Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2021-11-22 CVE-2021-23732 OS Command Injection vulnerability in Quobject Docker-Cli-Js
This affects all versions of package docker-cli-js.
network
high complexity
quobject CWE-78
critical
9.0
2021-11-19 CVE-2021-41280 OS Command Injection vulnerability in Sharetribe
Sharetribe Go is a source available marketplace software.
network
low complexity
sharetribe CWE-78
critical
9.8
2021-11-12 CVE-2021-3723 OS Command Injection vulnerability in IBM System X3550 M3 Firmware and System X3650 M3 Firmware
A command injection vulnerability was reported in the Integrated Management Module (IMM) of legacy IBM System x 3550 M3 and IBM System x 3650 M3 servers that could allow the execution of operating system commands over an authenticated SSH or Telnet session.
network
low complexity
ibm CWE-78
8.8
2021-11-12 CVE-2021-41254 OS Command Injection vulnerability in Fluxcd Kustomize-Controller
kustomize-controller is a Kubernetes operator, specialized in running continuous delivery pipelines for infrastructure and workloads defined with Kubernetes manifests and assembled with Kustomize.
network
low complexity
fluxcd CWE-78
8.8
2021-11-12 CVE-2021-3934 OS Command Injection vulnerability in Planetargon OH MY ZSH
ohmyzsh is vulnerable to Improper Neutralization of Special Elements used in an OS Command
network
high complexity
planetargon CWE-78
7.5
2021-11-10 CVE-2021-3058 OS Command Injection vulnerability in Paloaltonetworks Pan-Os
An OS command injection vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administrator with permissions to use XML API the ability to execute arbitrary OS commands to escalate privileges.
network
low complexity
paloaltonetworks CWE-78
7.2
2021-11-10 CVE-2021-3059 OS Command Injection vulnerability in Paloaltonetworks Pan-Os
An OS command injection vulnerability in the Palo Alto Networks PAN-OS management interface exists when performing dynamic updates.
network
high complexity
paloaltonetworks CWE-78
8.1
2021-11-10 CVE-2021-3060 OS Command Injection vulnerability in Paloaltonetworks Pan-Os
An OS command injection vulnerability in the Simple Certificate Enrollment Protocol (SCEP) feature of PAN-OS software allows an unauthenticated network-based attacker with specific knowledge of the firewall configuration to execute arbitrary code with root user privileges.
network
high complexity
paloaltonetworks CWE-78
8.1
2021-11-10 CVE-2021-3061 OS Command Injection vulnerability in Paloaltonetworks Pan-Os
An OS command injection vulnerability in the Palo Alto Networks PAN-OS command line interface (CLI) enables an authenticated administrator with access to the CLI to execute arbitrary OS commands to escalate privileges.
network
low complexity
paloaltonetworks CWE-78
7.2
2021-11-10 CVE-2021-39474 OS Command Injection vulnerability in Ubeeinteractive Ubc1319 Firmware 1319010201R009
Vulnerability in the product Docsis 3.0 UBC1319BA00 Router supported affected version 1319010201r009.
network
low complexity
ubeeinteractive CWE-78
7.2