Vulnerabilities > Improper Neutralization of Special Elements used in a Command ('Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2024-07-08 CVE-2024-25639 Command Injection vulnerability in Khoj
Khoj is an application that creates personal AI agents.
network
high complexity
khoj CWE-77
7.5
2024-06-25 CVE-2024-4884 Command Injection vulnerability in Progress Whatsup Gold
In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold.  The Apm.UI.Areas.APM.Controllers.CommunityController allows execution of commands with iisapppool\nmconsole privileges.
network
low complexity
progress CWE-77
critical
9.8
2024-06-25 CVE-2024-4639 Command Injection vulnerability in Moxa products
OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to a lack of neutralized inputs in IPSec configuration.
network
low complexity
moxa CWE-77
8.8
2024-06-25 CVE-2024-4638 Command Injection vulnerability in Moxa products
OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to a lack of neutralized inputs in the web key upload function.
network
low complexity
moxa CWE-77
8.8
2024-06-09 CVE-2024-37569 Command Injection vulnerability in Mitel 6869I SIP Firmware
An issue was discovered on Mitel 6869i through 4.5.0.41 and 5.x through 5.0.0.1018 devices.
network
low complexity
mitel CWE-77
8.8
2024-06-09 CVE-2024-37570 Command Injection vulnerability in Mitel 6869I SIP Firmware 4.5.0.41
On Mitel 6869i 4.5.0.41 devices, the Manual Firmware Update (upgrade.html) page does not perform sanitization on the username and path parameters (sent by an authenticated user) before appending flags to the busybox ftpget command.
network
low complexity
mitel CWE-77
8.8
2024-06-06 CVE-2024-30368 Command Injection vulnerability in A10Networks Advanced Core Operating System
A10 Thunder ADC CsrRequestView Command Injection Remote Code Execution Vulnerability.
network
low complexity
a10networks CWE-77
8.8
2024-06-04 CVE-2024-36604 Command Injection vulnerability in Tenda O3 Firmware 1.0.0.12(3880)
Tenda O3V2 v1.0.0.12(3880) was discovered to contain a Blind Command Injection via stpEn parameter in the SetStp function.
network
low complexity
tenda CWE-77
critical
9.8
2024-04-12 CVE-2024-3400 Command Injection vulnerability in Paloaltonetworks Pan-Os
A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall. Cloud NGFW, Panorama appliances, and Prisma Access are not impacted by this vulnerability.
network
low complexity
paloaltonetworks CWE-77
critical
10.0
2024-03-31 CVE-2023-41724 Command Injection vulnerability in Ivanti Standalone Sentry
A command injection vulnerability in Ivanti Sentry prior to 9.19.0 allows unauthenticated threat actor to execute arbitrary commands on the underlying operating system of the appliance within the same physical or logical network.
low complexity
ivanti CWE-77
8.8