Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2020-08-05 CVE-2020-13404 OS Command Injection vulnerability in Quadra-Informatique Atos/Sips
The ATOS/Sips (aka Atos-Magento) community module 3.0.0 to 3.0.5 for Magento allows command injection.
network
low complexity
quadra-informatique CWE-78
8.8
2020-08-05 CVE-2020-13151 OS Command Injection vulnerability in Aerospike Server
Aerospike Community Edition 4.9.0.5 allows for unauthenticated submission and execution of user-defined functions (UDFs), written in Lua, as part of a database query.
network
low complexity
aerospike CWE-78
critical
9.8
2020-08-04 CVE-2020-15467 OS Command Injection vulnerability in Cohesive Vns3
The administrative interface of Cohesive Networks vns3:vpn appliances before version 4.11.1 is vulnerable to authenticated remote code execution leading to server compromise.
network
low complexity
cohesive CWE-78
8.8
2020-07-31 CVE-2020-3377 OS Command Injection vulnerability in Cisco Data Center Network Manager
A vulnerability in the Device Manager application of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to inject arbitrary commands on the affected device.
network
low complexity
cisco CWE-78
8.8
2020-07-30 CVE-2020-12620 OS Command Injection vulnerability in Pi-Hole
Pi-hole 4.4 allows a user able to write to /etc/pihole/dns-servers.conf to escalate privileges through command injection (shell metacharacters after an IP address).
local
low complexity
pi-hole CWE-78
7.8
2020-07-29 CVE-2020-5760 OS Command Injection vulnerability in Grandstream products
Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to an OS command injection vulnerability.
local
low complexity
grandstream CWE-78
7.8
2020-07-29 CVE-2020-7698 OS Command Injection vulnerability in Gerapy
This affects the package Gerapy from 0 and before 0.9.3.
network
low complexity
gerapy CWE-78
critical
9.8
2020-07-24 CVE-2020-15778 OS Command Injection vulnerability in multiple products
scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument.
local
low complexity
openbsd netapp broadcom CWE-78
7.8
2020-07-24 CVE-2020-15922 OS Command Injection vulnerability in Midasolutions Eframework 2.8.0/2.8.9/2.9.0
There is an OS Command Injection in Mida eFramework 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) privileges.
network
low complexity
midasolutions CWE-78
critical
9.8
2020-07-24 CVE-2020-15920 OS Command Injection vulnerability in Midasolutions Eframework 2.8.0/2.8.9/2.9.0
There is an OS Command Injection in Mida eFramework through 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) privileges.
network
low complexity
midasolutions CWE-78
critical
9.8