Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2020-07-29 CVE-2020-7698 OS Command Injection vulnerability in Gerapy
This affects the package Gerapy from 0 and before 0.9.3.
network
low complexity
gerapy CWE-78
critical
9.8
2020-07-24 CVE-2020-15778 OS Command Injection vulnerability in multiple products
scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument.
local
low complexity
openbsd netapp broadcom CWE-78
7.8
2020-07-24 CVE-2020-15922 OS Command Injection vulnerability in Midasolutions Eframework 2.8.0/2.8.9/2.9.0
There is an OS Command Injection in Mida eFramework 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) privileges.
network
low complexity
midasolutions CWE-78
critical
9.8
2020-07-24 CVE-2020-15920 OS Command Injection vulnerability in Midasolutions Eframework 2.8.0/2.8.9/2.9.0
There is an OS Command Injection in Mida eFramework through 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) privileges.
network
low complexity
midasolutions CWE-78
critical
9.8
2020-07-23 CVE-2020-15477 OS Command Injection vulnerability in Raspberrytorte Raspberrytortoise 20121028
The WebControl in RaspberryTortoise through 2012-10-28 is vulnerable to remote code execution via shell metacharacters in a URI.
network
low complexity
raspberrytorte CWE-78
critical
9.8
2020-07-23 CVE-2020-15916 OS Command Injection vulnerability in Tenda Ac15 Firmware 15.03.05.19
goform/AdvSetLanip endpoint on Tenda AC15 AC1900 15.03.05.19 devices allows remote attackers to execute arbitrary system commands via shell metacharacters in the lanIp POST parameter.
network
low complexity
tenda CWE-78
critical
9.8
2020-07-22 CVE-2020-15893 OS Command Injection vulnerability in Dlink Dir-816L Firmware 2.06/2.06.B09
An issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02.
network
low complexity
dlink CWE-78
critical
9.8
2020-07-22 CVE-2020-12774 OS Command Injection vulnerability in Dlink Dsl-7740C Firmware V6.Tr069.20180723
D-Link DSL-7740C does not properly validate user input, which allows an authenticated LAN user to inject arbitrary command.
local
low complexity
dlink CWE-78
6.7
2020-07-20 CVE-2020-15123 OS Command Injection vulnerability in Codecov
In codecov (npm package) before version 3.7.1 the upload method has a command injection vulnerability.
network
low complexity
codecov CWE-78
critical
9.3
2020-07-20 CVE-2020-15121 OS Command Injection vulnerability in multiple products
In radare2 before version 4.5.0, malformed PDB file names in the PDB server path cause shell injection.
network
low complexity
radare fedoraproject CWE-78
critical
9.6