Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2019-03-21 CVE-2019-5414 OS Command Injection vulnerability in Kill-Port Project Kill-Port
If an attacker can control the port, which in itself is a very sensitive value, they can inject arbitrary OS commands due to the usage of the exec function in a third-party module kill-port < 1.3.2.
network
high complexity
kill-port-project CWE-78
8.1
2019-03-21 CVE-2018-20323 OS Command Injection vulnerability in Mailcleaner 2018.08
www/soap/application/MCSoap/Logs.php in MailCleaner Community Edition 2018.08 allows remote attackers to execute arbitrary OS commands.
network
low complexity
mailcleaner CWE-78
8.8
2019-03-21 CVE-2018-20218 OS Command Injection vulnerability in Teracue products
An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below.
network
low complexity
teracue CWE-78
critical
9.8
2019-03-14 CVE-2019-9785 OS Command Injection vulnerability in Gitnoteapp Gitnote 3.1.0
gitnote 3.1.0 allows remote attackers to execute arbitrary code via a crafted Markdown file, as demonstrated by a javascript:window.parent.top.require('child_process').execFile substring in the onerror attribute of an IMG element.
local
low complexity
gitnoteapp CWE-78
7.8
2019-03-11 CVE-2018-1998 OS Command Injection vulnerability in IBM Websphere MQ
IBM WebSphere MQ 8.0.0.0 through 9.1.1 could allow a local user to inject code that could be executed with root privileges.
local
low complexity
ibm CWE-78
7.8
2019-03-11 CVE-2019-1614 OS Command Injection vulnerability in Cisco Nx-Os
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, remote attacker to execute arbitrary commands with root privileges.
network
low complexity
cisco CWE-78
8.8
2019-03-11 CVE-2019-1612 OS Command Injection vulnerability in Cisco Nx-Os
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device.
local
low complexity
cisco CWE-78
6.7
2019-03-07 CVE-2019-9121 OS Command Injection vulnerability in Motorola C1 Firmware and M2 Firmware
An issue was discovered on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively.
network
low complexity
motorola CWE-78
critical
9.8
2019-03-07 CVE-2019-9120 OS Command Injection vulnerability in Motorola C1 Firmware and M2 Firmware
An issue was discovered on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively.
network
low complexity
motorola CWE-78
critical
9.8
2019-03-07 CVE-2019-9119 OS Command Injection vulnerability in Motorola C1 Firmware and M2 Firmware
An issue was discovered on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively.
network
low complexity
motorola CWE-78
critical
9.8