Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2022-02-15 CVE-2022-25174 OS Command Injection vulnerability in Jenkins Pipeline:Shared Groovy Libraries
Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier uses the same checkout directories for distinct SCMs for Pipeline libraries, allowing attackers with Item/Configure permission to invoke arbitrary OS commands on the controller through crafted SCM contents.
network
low complexity
jenkins CWE-78
8.8
2022-02-15 CVE-2022-25175 OS Command Injection vulnerability in Jenkins Pipeline: Multibranch
Jenkins Pipeline: Multibranch Plugin 706.vd43c65dec013 and earlier uses the same checkout directories for distinct SCMs for the readTrusted step, allowing attackers with Item/Configure permission to invoke arbitrary OS commands on the controller through crafted SCM contents.
network
low complexity
jenkins CWE-78
8.8
2022-02-14 CVE-2022-23389 OS Command Injection vulnerability in Publiccms 4.0
PublicCMS v4.0 was discovered to contain a remote code execution (RCE) vulnerability via the cmdarray parameter.
network
low complexity
publiccms CWE-78
critical
9.8
2022-02-11 CVE-2022-0557 OS Command Injection vulnerability in Microweber
OS Command Injection in Packagist microweber/microweber prior to 1.2.11.
network
low complexity
microweber CWE-78
7.2
2022-02-10 CVE-2022-20708 OS Command Injection vulnerability in Cisco products
Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and run unsigned software Cause denial of service (DoS) For more information about these vulnerabilities, see the Details section of this advisory.
low complexity
cisco CWE-78
8.0
2022-02-09 CVE-2021-26616 OS Command Injection vulnerability in Secuwiz Secuwayssl U 2.0.0.4/2.0.0.8
An OS command injection was found in SecuwaySSL, when special characters injection on execute command with runCommand arguments.
network
low complexity
secuwiz CWE-78
critical
9.8
2022-02-06 CVE-2022-24552 OS Command Injection vulnerability in Starwindsoftware NAS and SAN
A flaw was found in the REST API in StarWind Stack.
network
low complexity
starwindsoftware CWE-78
critical
9.8
2022-02-04 CVE-2022-0365 OS Command Injection vulnerability in Riconmobile S9922L Firmware and S9922Xl Firmware
The affected product is vulnerable to an authenticated OS command injection, which may allow an attacker to inject and execute arbitrary shell commands as the Admin (root) user.
network
low complexity
riconmobile CWE-78
critical
9.8
2022-02-04 CVE-2022-23611 OS Command Injection vulnerability in Itunesrpc-Remastered Project Itunesrpc-Remastered
iTunesRPC-Remastered is a Discord Rich Presence for iTunes on Windows utility.
network
low complexity
itunesrpc-remastered-project CWE-78
critical
9.8
2022-02-04 CVE-2021-29393 OS Command Injection vulnerability in Globalnorthstar Northstar Club Management 6.3
Remote Code Execution in cominput.jsp and comoutput.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to inject and execute arbitrary system commands via the unsanitized user-controlled "command" and "commandvalues" parameters.
network
low complexity
globalnorthstar CWE-78
critical
9.8