Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2021-03-01 CVE-2021-26476 OS Command Injection vulnerability in Eprints 3.4.2
EPrints 3.4.2 allows remote attackers to execute OS commands via crafted LaTeX input to a cgi/cal?year= URI.
network
low complexity
eprints CWE-78
critical
9.8
2021-02-27 CVE-2019-25022 OS Command Injection vulnerability in Scytl Secure Vote 2.1
An issue was discovered in Scytl sVote 2.1.
network
low complexity
scytl CWE-78
critical
9.8
2021-02-24 CVE-2021-20658 OS Command Injection vulnerability in Contec Sv-Cpt-Mc310 Firmware 6.0/6.00
SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to execute arbitrary OS commands with the web server privilege via unspecified vectors.
network
low complexity
contec CWE-78
critical
9.8
2021-02-23 CVE-2021-26680 OS Command Injection vulnerability in Arubanetworks Clearpass Policy Manager
A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1.
network
low complexity
arubanetworks CWE-78
7.2
2021-02-23 CVE-2021-26679 OS Command Injection vulnerability in Arubanetworks Clearpass Policy Manager
A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1.
network
low complexity
arubanetworks CWE-78
7.2
2021-02-23 CVE-2021-26684 OS Command Injection vulnerability in Arubanetworks Clearpass Policy Manager
A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1.
network
low complexity
arubanetworks CWE-78
7.2
2021-02-23 CVE-2021-26683 OS Command Injection vulnerability in Arubanetworks Clearpass Policy Manager
A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1.
network
low complexity
arubanetworks CWE-78
7.2
2021-02-23 CVE-2021-26681 OS Command Injection vulnerability in Arubanetworks Clearpass Policy Manager
A remote authenticated command Injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1.
network
low complexity
arubanetworks CWE-78
7.2
2021-02-23 CVE-2020-28429 OS Command Injection vulnerability in Geojson2Kml Project Geojson2Kml
All versions of package geojson2kml are vulnerable to Command Injection via the index.js file.
network
low complexity
geojson2kml-project CWE-78
critical
9.8
2021-02-22 CVE-2021-26724 OS Command Injection vulnerability in Nozominetworks Central Management Control and Guardian
OS Command Injection vulnerability when changing date settings or hostname using web GUI of Nozomi Networks Guardian and CMC allows authenticated administrators to perform remote code execution.
network
low complexity
nozominetworks CWE-78
7.2