Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2021-03-05 CVE-2021-26962 OS Command Injection vulnerability in Arubanetworks Airwave
A remote authenticated arbitrary command execution vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0.
network
low complexity
arubanetworks CWE-78
7.2
2021-03-02 CVE-2021-27886 OS Command Injection vulnerability in Docker Dashboard Project Docker Dashboard
rakibtg Docker Dashboard before 2021-02-28 allows command injection in backend/utilities/terminal.js via shell metacharacters in the command parameter of an API request.
network
low complexity
docker-dashboard-project CWE-78
critical
9.8
2021-03-01 CVE-2021-3342 OS Command Injection vulnerability in Eprints 3.4.2
EPrints 3.4.2 allows remote attackers to read arbitrary files and possibly execute commands via crafted LaTeX input to a cgi/latex2png?latex= URI.
network
low complexity
eprints CWE-78
critical
9.8
2021-03-01 CVE-2021-26704 OS Command Injection vulnerability in Eprints 3.4.2
EPrints 3.4.2 allows remote attackers to execute arbitrary commands via crafted input to the verb parameter in a cgi/toolbox/toolbox URI.
network
low complexity
eprints CWE-78
8.8
2021-03-01 CVE-2021-26476 OS Command Injection vulnerability in Eprints 3.4.2
EPrints 3.4.2 allows remote attackers to execute OS commands via crafted LaTeX input to a cgi/cal?year= URI.
network
low complexity
eprints CWE-78
critical
9.8
2021-02-27 CVE-2019-25022 OS Command Injection vulnerability in Scytl Secure Vote 2.1
An issue was discovered in Scytl sVote 2.1.
network
low complexity
scytl CWE-78
critical
9.8
2021-02-24 CVE-2021-20658 OS Command Injection vulnerability in Contec Sv-Cpt-Mc310 Firmware 6.0/6.00
SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to execute arbitrary OS commands with the web server privilege via unspecified vectors.
network
low complexity
contec CWE-78
critical
9.8
2021-02-23 CVE-2021-26680 OS Command Injection vulnerability in Arubanetworks Clearpass Policy Manager
A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1.
network
low complexity
arubanetworks CWE-78
7.2
2021-02-23 CVE-2021-26679 OS Command Injection vulnerability in Arubanetworks Clearpass Policy Manager
A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1.
network
low complexity
arubanetworks CWE-78
7.2
2021-02-23 CVE-2021-26684 OS Command Injection vulnerability in Arubanetworks Clearpass Policy Manager
A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1.
network
low complexity
arubanetworks CWE-78
7.2