Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2021-06-01 CVE-2021-24312 OS Command Injection vulnerability in Automattic WP Super Cache
The parameters $cache_path, $wp_cache_debug_ip, $wp_super_cache_front_page_text, $cache_scheduled_time, $cached_direct_pages used in the settings of WP Super Cache WordPress plugin before 1.7.3 result in RCE because they allow input of '$' and '\n'.
network
low complexity
automattic CWE-78
7.2
2021-06-01 CVE-2021-3515 OS Command Injection vulnerability in 2Ndquadrant Pglogical
A shell injection flaw was found in pglogical in versions before 2.3.4 and before 3.6.26.
local
low complexity
2ndquadrant CWE-78
6.7
2021-05-27 CVE-2021-20026 OS Command Injection vulnerability in Sonicwall Network Security Manager 2.2.0
A vulnerability in the SonicWall NSM On-Prem product allows an authenticated attacker to perform OS command injection using a crafted HTTP request.
network
low complexity
sonicwall CWE-78
8.8
2021-05-25 CVE-2021-30187 OS Command Injection vulnerability in Codesys Runtime Toolkit 2.4.7.54
CODESYS V2 runtime system SP before 2.4.7.55 has Improper Neutralization of Special Elements used in an OS Command.
local
low complexity
codesys CWE-78
5.3
2021-05-24 CVE-2021-33525 OS Command Injection vulnerability in Eyesofnetwork
EyesOfNetwork eonweb through 5.3-11 allows Remote Command Execution (by authenticated users) via shell metacharacters in the nagios_path parameter to lilac/export.php, as demonstrated by %26%26+curl to insert an "&& curl" substring for the shell.
network
low complexity
eyesofnetwork CWE-78
8.8
2021-05-24 CVE-2021-29300 OS Command Injection vulnerability in Ronomon Opened
The @ronomon/opened library before 1.5.2 is vulnerable to a command injection vulnerability which would allow a remote attacker to execute commands on the system if the library was used with untrusted input.
network
low complexity
ronomon CWE-78
critical
9.8
2021-05-24 CVE-2021-20557 OS Command Injection vulnerability in IBM Security Guardium 11.2
IBM Security Guardium 11.2 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request.
network
low complexity
ibm CWE-78
7.2
2021-05-21 CVE-2021-33514 OS Command Injection vulnerability in Netgear products
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker via the vulnerable /sqfs/lib/libsal.so.0.0 library used by a CGI application, as demonstrated by setup.cgi?token=';$HTTP_USER_AGENT;' with an OS command in the User-Agent field.
network
low complexity
netgear CWE-78
critical
9.8
2021-05-20 CVE-2021-20719 OS Command Injection vulnerability in Nippon-Antenna Rfntps Firmware System01000004/Web01000004
RFNTPS firmware versions System_01000004 and earlier, and Web_01000004 and earlier allow an attacker on the same network segment to execute arbitrary OS commands with a root privilege via unspecified vectors.
low complexity
nippon-antenna CWE-78
6.8
2021-05-18 CVE-2021-31324 OS Command Injection vulnerability in Control-Webpanel Webpanel
The unprivileged user portal part of CentOS Web Panel is affected by a Command Injection vulnerability leading to root Remote Code Execution.
network
low complexity
control-webpanel CWE-78
critical
9.8