Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2021-09-08 CVE-2021-36182 OS Command Injection vulnerability in Fortinet Fortiweb
A Improper neutralization of special elements used in a command ('Command Injection') in Fortinet FortiWeb version 6.3.13 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests
network
low complexity
fortinet CWE-78
8.8
2021-09-07 CVE-2021-39279 OS Command Injection vulnerability in Moxa products
Certain MOXA devices allow Authenticated Command Injection via /forms/web_importTFTP.
network
low complexity
moxa CWE-78
8.8
2021-08-31 CVE-2021-27556 OS Command Injection vulnerability in Easycorp Zentao 12.5.3
The Cron job tab in EasyCorp ZenTao 12.5.3 allows remote attackers (who have admin access) to execute arbitrary code by setting the type parameter to System.
network
low complexity
easycorp CWE-78
7.2
2021-08-30 CVE-2021-35062 OS Command Injection vulnerability in Testzentrum-Odw Testerfassung 202103
A Shell Metacharacter Injection vulnerability in result.php in DRK Odenwaldkreis Testerfassung March-2021 allow an attacker with a valid token of a COVID-19 test result to execute shell commands with the permissions of the web server.
network
high complexity
testzentrum-odw CWE-78
8.1
2021-08-30 CVE-2021-33055 OS Command Injection vulnerability in Zohocorp Manageengine Adselfservice Plus
Zoho ManageEngine ADSelfService Plus through 6102 allows unauthenticated remote code execution in non-English editions.
network
low complexity
zohocorp CWE-78
critical
9.8
2021-08-26 CVE-2021-27944 OS Command Injection vulnerability in Vizio E50X-E1 Firmware and P65-F1 Firmware
Several high privileged APIs on the Vizio P65-F1 6.0.31.4-2 and E50x-E1 10.0.31.4-2 Smart TVs do not enforce access controls, allowing an unauthenticated threat actor to access privileged functionality, leading to OS command execution.
network
low complexity
vizio CWE-78
critical
9.8
2021-08-25 CVE-2021-1584 OS Command Injection vulnerability in Cisco Nx-Os 14.2(7F)
A vulnerability in Cisco Nexus 9000 Series Fabric Switches in Application Centric Infrastructure (ACI) mode could allow an authenticated, local attacker to elevate privileges on an affected device.
local
low complexity
cisco CWE-78
6.7
2021-08-25 CVE-2021-39159 OS Command Injection vulnerability in Jupyter Binderhub
BinderHub is a kubernetes-based cloud service that allows users to share reproducible interactive computing environments from code repositories.
network
low complexity
jupyter CWE-78
critical
9.8
2021-08-25 CVE-2021-39160 OS Command Injection vulnerability in Jupyterhub Nbgitpuller 0.10.0/0.10.1/0.9.0
nbgitpuller is a Jupyter server extension to sync a git repository one-way to a local path.
network
low complexity
jupyterhub CWE-78
8.8
2021-08-24 CVE-2021-38306 OS Command Injection vulnerability in LG N1T1 Firmware
Network Attached Storage on LG N1T1*** 10124 devices allows an unauthenticated attacker to gain root access via OS command injection in the en/ajp/plugins/access.ssh/checkInstall.php destServer parameter.
network
low complexity
lg CWE-78
critical
9.8