Vulnerabilities > Improper Neutralization of Special Elements used in a Command ('Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2023-12-29 CVE-2023-52137 Command Injection vulnerability in Tj-Actions Verify-Changed-Files
The [`tj-actions/verify-changed-files`](https://github.com/tj-actions/verify-changed-files) action allows for command injection in changed filenames, allowing an attacker to execute arbitrary code and potentially leak secrets.
network
low complexity
tj-actions CWE-77
8.8
2023-12-27 CVE-2023-51664 Command Injection vulnerability in Tj-Actions Changed-Files
tj-actions/changed-files is a Github action to retrieve all files and directories.
network
low complexity
tj-actions CWE-77
critical
9.8
2023-12-25 CVE-2023-49226 Command Injection vulnerability in Peplink Balance TWO Firmware 8.1.0
An issue was discovered in Peplink Balance Two before 8.4.0.
network
low complexity
peplink CWE-77
7.2
2023-12-22 CVE-2023-51016 Command Injection vulnerability in Totolink Ex1800T Firmware 9.1.0Cu.2112B20220316
TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the setRebootScheCfg interface of the cstecgi .cgi.
network
low complexity
totolink CWE-77
critical
9.8
2023-12-22 CVE-2023-51707 Command Injection vulnerability in Arraynetworks Arrayos AG
MotionPro in Array ArrayOS AG before 9.4.0.505 on AG and vxAG allows remote command execution via crafted packets.
network
low complexity
arraynetworks CWE-77
critical
9.8
2023-12-20 CVE-2023-50983 Command Injection vulnerability in Tenda I29 Firmware 1.0.0.2/1.0.0.5
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerability via the sysScheduleRebootSet function.
network
low complexity
tenda CWE-77
critical
9.8
2023-12-20 CVE-2023-50989 Command Injection vulnerability in Tenda I29 Firmware 1.0.0.2/1.0.0.5
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerability via the pingSet function.
network
low complexity
tenda CWE-77
critical
9.8
2023-12-18 CVE-2023-39509 Command Injection vulnerability in Bosch Cpp13 Firmware and Cpp14 Firmware
A command injection vulnerability exists in Bosch IP cameras that allows an authenticated user with administrative rights to run arbitrary commands on the OS of the camera.
network
low complexity
bosch CWE-77
7.2
2023-12-15 CVE-2023-50089 Command Injection vulnerability in Netgear Wnr2000 Firmware 1.0.0.70
A Command Injection vulnerability exists in NETGEAR WNR2000v4 version 1.0.0.70.
network
low complexity
netgear CWE-77
critical
9.8
2023-12-15 CVE-2023-50917 Command Injection vulnerability in Mjdm Majordomo
MajorDoMo (aka Major Domestic Module) before 0662e5e allows command execution via thumb.php shell metacharacters.
network
low complexity
mjdm CWE-77
critical
9.8