Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2022-02-16 CVE-2022-22945 OS Command Injection vulnerability in VMWare Cloud Foundation and NSX Data Center
VMware NSX Edge contains a CLI shell injection vulnerability.
local
low complexity
vmware CWE-78
7.8
2022-02-15 CVE-2022-25173 OS Command Injection vulnerability in Jenkins Pipeline: Groovy
Jenkins Pipeline: Groovy Plugin 2648.va9433432b33c and earlier uses the same checkout directories for distinct SCMs when reading the script file (typically Jenkinsfile) for Pipelines, allowing attackers with Item/Configure permission to invoke arbitrary OS commands on the controller through crafted SCM contents.
network
low complexity
jenkins CWE-78
8.8
2022-02-15 CVE-2022-25174 OS Command Injection vulnerability in Jenkins Pipeline:Shared Groovy Libraries
Jenkins Pipeline: Shared Groovy Libraries Plugin 552.vd9cc05b8a2e1 and earlier uses the same checkout directories for distinct SCMs for Pipeline libraries, allowing attackers with Item/Configure permission to invoke arbitrary OS commands on the controller through crafted SCM contents.
network
low complexity
jenkins CWE-78
8.8
2022-02-15 CVE-2022-25175 OS Command Injection vulnerability in Jenkins Pipeline: Multibranch
Jenkins Pipeline: Multibranch Plugin 706.vd43c65dec013 and earlier uses the same checkout directories for distinct SCMs for the readTrusted step, allowing attackers with Item/Configure permission to invoke arbitrary OS commands on the controller through crafted SCM contents.
network
low complexity
jenkins CWE-78
8.8
2022-02-14 CVE-2022-23389 OS Command Injection vulnerability in Publiccms 4.0
PublicCMS v4.0 was discovered to contain a remote code execution (RCE) vulnerability via the cmdarray parameter.
network
low complexity
publiccms CWE-78
critical
9.8
2022-02-11 CVE-2022-0557 OS Command Injection vulnerability in Microweber
OS Command Injection in Packagist microweber/microweber prior to 1.2.11.
network
low complexity
microweber CWE-78
7.2
2022-02-10 CVE-2022-20708 OS Command Injection vulnerability in Cisco products
Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and run unsigned software Cause denial of service (DoS) For more information about these vulnerabilities, see the Details section of this advisory.
low complexity
cisco CWE-78
8.0
2022-02-09 CVE-2021-26616 OS Command Injection vulnerability in Secuwiz Secuwayssl U 2.0.0.4/2.0.0.8
An OS command injection was found in SecuwaySSL, when special characters injection on execute command with runCommand arguments.
network
low complexity
secuwiz CWE-78
critical
9.8
2022-02-06 CVE-2022-24552 OS Command Injection vulnerability in Starwindsoftware NAS and SAN
A flaw was found in the REST API in StarWind Stack.
network
low complexity
starwindsoftware CWE-78
critical
9.8
2022-02-04 CVE-2022-0365 OS Command Injection vulnerability in Riconmobile S9922L Firmware and S9922Xl Firmware
The affected product is vulnerable to an authenticated OS command injection, which may allow an attacker to inject and execute arbitrary shell commands as the Admin (root) user.
network
low complexity
riconmobile CWE-78
critical
9.8