Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2018-08-15 CVE-2018-15155 OS Command Injection vulnerability in Open-Emr Openemr
OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary commands by making a crafted request to interface/fax/fax_dispatch.php after modifying the "hylafax_enscript" global variable in interface/super/edit_globals.php.
network
low complexity
open-emr CWE-78
8.8
2018-08-15 CVE-2018-15154 OS Command Injection vulnerability in Open-Emr Openemr
OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary commands by making a crafted request to interface/billing/sl_eob_search.php after modifying the "print_command" global variable in interface/super/edit_globals.php.
network
low complexity
open-emr CWE-78
8.8
2018-08-15 CVE-2018-15153 OS Command Injection vulnerability in Open-Emr Openemr
OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary commands by making a crafted request to interface/main/daemon_frame.php after modifying the "hylafax_server" global variable in interface/super/edit_globals.php.
network
low complexity
open-emr CWE-78
8.8
2018-08-14 CVE-2018-3937 OS Command Injection vulnerability in Sony products
An exploitable command injection vulnerability exists in the measurementBitrateExec functionality of Sony IPELA E Series Network Camera G5 firmware 1.87.00.
network
low complexity
sony CWE-78
7.2
2018-08-04 CVE-2018-14933 OS Command Injection vulnerability in Nuuo Nvrmini Firmware 2016
upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir parameter for a writeuploaddir command.
network
low complexity
nuuo CWE-78
critical
9.8
2018-08-04 CVE-2018-14417 OS Command Injection vulnerability in Softnas Cloud
A command injection vulnerability was found in the web administration console in SoftNAS Cloud before 4.0.3.
network
low complexity
softnas CWE-78
critical
9.8
2018-08-04 CVE-2018-12483 OS Command Injection vulnerability in Ocsinventory-Ng Ocsinventory NG 2.4.1
OCS Inventory 2.4.1 is prone to a remote command-execution vulnerability.
network
low complexity
ocsinventory-ng CWE-78
8.8
2018-07-26 CVE-2018-10900 OS Command Injection vulnerability in multiple products
Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privilege escalation attack.
local
low complexity
gnome debian CWE-78
7.8
2018-07-24 CVE-2018-10905 OS Command Injection vulnerability in Redhat Cloudforms and Cloudforms Management Engine
CloudForms Management Engine (cfme) is vulnerable to an improper security setting in the dRuby component of CloudForms.
local
low complexity
redhat CWE-78
7.8
2018-07-18 CVE-2018-0349 OS Command Injection vulnerability in Cisco products
A vulnerability in the Cisco SD-WAN Solution could allow an authenticated, remote attacker to overwrite arbitrary files on the underlying operating system of an affected device.
network
low complexity
cisco CWE-78
critical
9.8