Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2020-07-06 CVE-2020-5352 OS Command Injection vulnerability in Dell EMC Data Protection Advisor 18.1/6.4/6.5
Dell EMC Data Protection Advisor 6.4, 6.5 and 18.1 contain an OS command injection vulnerability.
network
low complexity
dell CWE-78
critical
9.0
2020-07-02 CVE-2020-8188 OS Command Injection vulnerability in UI Unifi Protect Firmware
We have recently released new version of UniFi Protect firmware v1.13.3 and v1.14.10 for Unifi Cloud Key Gen2 Plus and UniFi Dream Machine Pro/UNVR respectively that fixes vulnerabilities found on Protect firmware v1.13.2, v1.14.9 and prior according to the description below:View only users can run certain custom commands which allows them to assign themselves unauthorized roles and escalate their privileges.
network
low complexity
ui CWE-78
6.5
2020-07-01 CVE-2020-7688 OS Command Injection vulnerability in Mversion Project Mversion
The issue occurs because tagName user input is formatted inside the exec function is executed without any checks.
local
low complexity
mversion-project CWE-78
4.6
2020-06-30 CVE-2020-14947 OS Command Injection vulnerability in Factorfx Open Computer Software Inventory Next Generation 2.7
OCS Inventory NG 2.7 allows Remote Command Execution via shell metacharacters to require/commandLine/CommandLine.php because mib_file in plugins/main_sections/ms_config/ms_snmp_config.php is mishandled in get_mib_oid.
network
low complexity
factorfx CWE-78
8.8
2020-06-30 CVE-2020-15415 OS Command Injection vulnerability in Draytek products
On DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote command execution via shell metacharacters in a filename when the text/x-python-script content type is used, a different issue than CVE-2020-14472.
network
low complexity
draytek CWE-78
7.5
2020-06-29 CVE-2020-14414 OS Command Injection vulnerability in Nedi 1.9C
NeDi 1.9C is vulnerable to Remote Command Execution.
network
low complexity
nedi CWE-78
critical
9.0
2020-06-29 CVE-2020-14412 OS Command Injection vulnerability in Nedi 1.9C
NeDi 1.9C is vulnerable to Remote Command Execution.
network
low complexity
nedi CWE-78
critical
9.0
2020-06-26 CVE-2020-9583 OS Command Injection vulnerability in Magento
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability.
network
low complexity
magento CWE-78
7.5
2020-06-26 CVE-2020-9582 OS Command Injection vulnerability in Magento
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability.
network
low complexity
magento CWE-78
7.5
2020-06-26 CVE-2020-9578 OS Command Injection vulnerability in Magento
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability.
network
low complexity
magento CWE-78
7.5