Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2019-09-23 CVE-2019-16718 OS Command Injection vulnerability in Radare Radare2
In radare2 before 3.9.0, a command injection vulnerability exists in bin_symbols() in libr/core/cbin.c.
network
radare CWE-78
6.8
2019-09-19 CVE-2019-15000 OS Command Injection vulnerability in Atlassian Bitbucket
The commit diff rest endpoint in Bitbucket Server and Data Center before 5.16.10 (the fixed version for 5.16.x ), from 6.0.0 before 6.0.10 (the fixed version for 6.0.x), from 6.1.0 before 6.1.8 (the fixed version for 6.1.x), from 6.2.0 before 6.2.6 (the fixed version for 6.2.x), from 6.3.0 before 6.3.5 (the fixed version for 6.3.x), from 6.4.0 before 6.4.3 (the fixed version for 6.4.x), and from 6.5.0 before 6.5.2 (the fixed version for 6.5.x) allows remote attackers who have permission to access a repository, if public access is enabled for a project or repository then attackers are able to exploit this issue anonymously, to read the contents of arbitrary files on the system and execute commands via injecting additional arguments into git commands.
network
atlassian CWE-78
6.8
2019-09-16 CVE-2019-16057 OS Command Injection vulnerability in Dlink Dns-320 Firmware
The login_mgr.cgi script in D-Link DNS-320 through 2.05.B10 is vulnerable to remote command injection.
network
low complexity
dlink CWE-78
critical
10.0
2019-09-13 CVE-2019-5485 OS Command Injection vulnerability in Gitlabhook Project Gitlabhook 0.0.17
NPM package gitlabhook version 0.0.17 is vulnerable to a Command Injection vulnerability.
network
low complexity
gitlabhook-project CWE-78
critical
10.0
2019-09-13 CVE-2019-5315 OS Command Injection vulnerability in Arubanetworks Arubaos
A command injection vulnerability is present in the web management interface of ArubaOS that permits an authenticated user to execute arbitrary commands on the underlying operating system.
network
low complexity
arubanetworks CWE-78
critical
9.0
2019-09-13 CVE-2019-16293 OS Command Injection vulnerability in Opmantek Open-Audit
The Create Discoveries feature of Open-AudIT before 3.2.0 allows an authenticated attacker to execute arbitrary OS commands via a crafted value for a URL field.
network
low complexity
opmantek CWE-78
6.5
2019-09-12 CVE-2019-10392 OS Command Injection vulnerability in Jenkins GIT Client
Jenkins Git Client Plugin 2.8.4 and earlier and 3.0.0-rc did not properly restrict values passed as URL argument to an invocation of 'git ls-remote', resulting in OS command injection.
network
low complexity
jenkins CWE-78
8.8
2019-09-09 CVE-2019-10669 OS Command Injection vulnerability in Librenms
An issue was discovered in LibreNMS through 1.47.
network
low complexity
librenms CWE-78
6.5
2019-09-06 CVE-2019-10891 OS Command Injection vulnerability in Dlink Dir-806 Firmware
An issue was discovered in D-Link DIR-806 devices.
network
low complexity
dlink CWE-78
critical
10.0
2019-09-05 CVE-2019-15029 OS Command Injection vulnerability in Fusionpbx 4.4.8
FusionPBX 4.4.8 allows an attacker to execute arbitrary system commands by submitting a malicious command to the service_edit.php file (which will insert the malicious command into the database).
network
low complexity
fusionpbx CWE-78
critical
9.0