Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2021-09-29 CVE-2021-35028 OS Command Injection vulnerability in Zyxel Zywall Vpn2S Firmware 1.12(Abln.0)C0
A command injection vulnerability in the CGI program of the Zyxel VPN2S firmware version 1.12 could allow an authenticated, local user to execute arbitrary OS commands.
local
low complexity
zyxel CWE-78
7.8
2021-09-27 CVE-2021-20035 OS Command Injection vulnerability in Sonicwall products
Improper neutralization of special elements in the SMA100 management interface allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user which potentially leads to DoS.
network
low complexity
sonicwall CWE-78
6.5
2021-09-27 CVE-2021-31605 OS Command Injection vulnerability in Openvpn-Monitor Project Openvpn-Monitor
furlongm openvpn-monitor through 1.1.3 allows %0a command injection via the OpenVPN management interface socket.
network
low complexity
openvpn-monitor-project CWE-78
7.5
2021-09-23 CVE-2021-34725 OS Command Injection vulnerability in Cisco IOS XE Sd-Wan
A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands to be executed with root-level privileges on the underlying operating system.
local
low complexity
cisco CWE-78
6.7
2021-09-23 CVE-2021-34726 OS Command Injection vulnerability in Cisco Sd-Wan
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands to be executed with root-level privileges on the underlying operating system of an affected device.
local
low complexity
cisco CWE-78
6.7
2021-09-23 CVE-2021-34729 OS Command Injection vulnerability in Cisco IOS XE and IOS XE Sd-Wan
A vulnerability in the CLI of Cisco IOS XE SD-WAN Software and Cisco IOS XE Software could allow an authenticated, local attacker to execute arbitrary commands with elevated privileges on an affected device.
local
low complexity
cisco CWE-78
6.7
2021-09-22 CVE-2021-37925 OS Command Injection vulnerability in Zohocorp Manageengine Admanager Plus
Zoho ManageEngine ADManager Plus version 7110 and prior has a Post-Auth OS command injection vulnerability.
network
low complexity
zohocorp CWE-78
critical
9.8
2021-09-22 CVE-2021-36260 OS Command Injection vulnerability in Hikvision products
A command injection vulnerability in the web server of some Hikvision product.
network
low complexity
hikvision CWE-78
critical
9.8
2021-09-17 CVE-2021-41315 OS Command Injection vulnerability in Device42 Remote Collector
The Device42 Remote Collector before 17.05.01 does not sanitize user input in its SNMP Connectivity utility.
network
low complexity
device42 CWE-78
8.8
2021-09-14 CVE-2021-23025 OS Command Injection vulnerability in F5 products
On version 15.1.x before 15.1.0.5, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.5, and all versions of 12.1.x and 11.6.x, an authenticated remote command execution vulnerability exists in the BIG-IP Configuration utility.
network
low complexity
f5 CWE-78
8.8