Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2019-10-07 CVE-2019-17269 OS Command Injection vulnerability in Intelliantech Remote Access 3.18
Intellian Remote Access 3.18 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the Ping Test field.
network
low complexity
intelliantech CWE-78
critical
10.0
2019-10-02 CVE-2019-15036 OS Command Injection vulnerability in Jetbrains Teamcity 2018.2.4
An issue was discovered in JetBrains TeamCity 2018.2.4.
network
low complexity
jetbrains CWE-78
critical
9.0
2019-10-02 CVE-2019-12699 OS Command Injection vulnerability in Cisco products
Multiple vulnerabilities in the CLI of Cisco FXOS Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute commands on the underlying operating system (OS) with root privileges.
local
low complexity
cisco CWE-78
7.8
2019-10-02 CVE-2019-12690 OS Command Injection vulnerability in Cisco Firepower Management Center
A vulnerability in the web UI of the Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to inject arbitrary commands that are executed with the privileges of the root user of the underlying operating system.
network
low complexity
cisco CWE-78
critical
9.0
2019-09-27 CVE-2019-16920 OS Command Injection vulnerability in Dlink products
Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565.
network
low complexity
dlink CWE-78
critical
9.8
2019-09-26 CVE-2019-12091 OS Command Injection vulnerability in Netskope 57/60
The Netskope client service, v57 before 57.2.0.219 and v60 before 60.2.0.214, running with NT\SYSTEM privilege, accepts network connections from localhost.
local
low complexity
netskope CWE-78
7.2
2019-09-25 CVE-2019-12717 OS Command Injection vulnerability in Cisco Nx-Os
A vulnerability in a CLI command related to the virtualization manager (VMAN) in Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying Linux operating system with root privileges.
local
low complexity
cisco CWE-78
7.2
2019-09-25 CVE-2019-12709 OS Command Injection vulnerability in Cisco IOS XR
A vulnerability in a CLI command related to the virtualization manager (VMAN) in Cisco IOS XR Software for Cisco ASR 9000 Series Aggregation Services Routers could allow an authenticated, local attacker to execute arbitrary commands on the underlying Linux operating system with root privileges.
local
low complexity
cisco CWE-78
7.2
2019-09-25 CVE-2019-12661 OS Command Injection vulnerability in Cisco IOS XE
A vulnerability in a Virtualization Manager (VMAN) related CLI command of Cisco IOS XE Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying Linux operating system with a privilege level of root.
local
low complexity
cisco CWE-78
7.2
2019-09-25 CVE-2019-12651 OS Command Injection vulnerability in Cisco products
Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands with elevated privileges on the affected device.
network
low complexity
cisco CWE-78
critical
9.0