Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2021-01-13 CVE-2020-5685 OS Command Injection vulnerability in NEC Univerge Sv8500 Firmware and Univerge Sv9500 Firmware
UNIVERGE SV9500 series from V1 to V7and SV8500 series from S6 to S8 allows an attacker to execute arbitrary OS commands or cause a denial-of-service (DoS) condition by sending a specially crafted request to a specific URL.
network
low complexity
nec CWE-78
critical
9.8
2021-01-12 CVE-2020-35459 OS Command Injection vulnerability in multiple products
An issue was discovered in ClusterLabs crmsh through 4.2.1.
local
low complexity
clusterlabs debian CWE-78
7.8
2021-01-12 CVE-2020-35458 OS Command Injection vulnerability in Clusterlabs Hawk 2.2.012/2.3.012
An issue was discovered in ClusterLabs Hawk 2.x through 2.3.0-x.
network
low complexity
clusterlabs CWE-78
critical
9.8
2021-01-09 CVE-2020-5146 OS Command Injection vulnerability in Sonicwall SMA 100 Firmware
A vulnerability in SonicWall SMA100 appliance allow an authenticated management-user to perform OS command injection using HTTP POST parameters.
network
low complexity
sonicwall CWE-78
7.2
2021-01-07 CVE-2021-3029 OS Command Injection vulnerability in Evolucare ECS Imaging 6.21.5
EVOLUCARE ECSIMAGING (aka ECS Imaging) through 6.21.5 has an OS Command Injection vulnerability via shell metacharacters and an IFS manipulation.
network
low complexity
evolucare CWE-78
critical
9.8
2021-01-07 CVE-2020-26085 OS Command Injection vulnerability in Cisco Jabber
Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system (OS) with elevated privileges or gain access to sensitive information.
network
low complexity
cisco CWE-78
critical
9.9
2021-01-06 CVE-2020-36178 OS Command Injection vulnerability in Tp-Link Tl-Wr840N Firmware 6Eu0.9.14.16
oal_ipt_addBridgeIsolationRules on TP-Link TL-WR840N 6_EU_0.9.1_4.16 devices allows OS command injection because a raw string entered from the web interface (an IP address field) is used directly for a call to the system library function (for iptables).
network
low complexity
tp-link CWE-78
critical
9.8
2020-12-31 CVE-2020-35851 OS Command Injection vulnerability in Hgiga Msr45 Isherlock-User and Ssr45 Isherlock-User
HGiga MailSherlock does not validate specific parameters properly.
network
low complexity
hgiga CWE-78
critical
9.8
2020-12-31 CVE-2020-19664 OS Command Injection vulnerability in Draytek Vigor2960 Firmware 1.3.1
DrayTek Vigor2960 1.5.1 allows remote command execution via shell metacharacters in a toLogin2FA action to mainfunction.cgi.
network
low complexity
draytek CWE-78
8.8
2020-12-31 CVE-2020-17363 OS Command Injection vulnerability in Usvn
USVN (aka User-friendly SVN) before 1.0.9 allows remote code execution via shell metacharacters in the number_start or number_end parameter to LastHundredRequest (aka lasthundredrequestAction) in the Timeline module.
network
low complexity
usvn CWE-78
critical
9.9