Vulnerabilities > Improper Neutralization of Special Elements used in a Command ('Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2024-01-24 CVE-2023-52040 Command Injection vulnerability in Totolink X6000R Firmware 9.4.0Cu.852B20230719
An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_41284C function.
network
low complexity
totolink CWE-77
critical
9.8
2024-01-24 CVE-2023-51887 Command Injection vulnerability in Ctan Mathtex
Command Injection vulnerability in Mathtex v.1.05 and before allows a remote attacker to execute arbitrary code via crafted string in application URL.
network
low complexity
ctan CWE-77
critical
9.8
2024-01-24 CVE-2024-22651 Command Injection vulnerability in Dlink Dir-815 Firmware 1.0.1/1.01Ssb08.Bin/1.04
There is a command injection vulnerability in the ssdpcgi_main function of cgibin binary in D-Link DIR-815 router firmware v1.04.
network
low complexity
dlink CWE-77
critical
9.8
2024-01-23 CVE-2023-50274 Command Injection vulnerability in HP Oneview
HPE OneView may allow command injection with local privilege escalation.
local
low complexity
hp CWE-77
7.8
2024-01-23 CVE-2024-22663 Command Injection vulnerability in Totolink A3700R Firmware 9.1.2U.616520211012
TOTOLINK_A3700R_V9.1.2u.6165_20211012has a command Injection vulnerability via setOpModeCfg
network
low complexity
totolink CWE-77
critical
9.8
2024-01-22 CVE-2023-24135 Command Injection vulnerability in Jensenofscandinavia Eagle 1200Ac Firmware 15.03.06.33En
Jensen of Scandinavia Eagle 1200AC V15.03.06.33_en was discovered to contain a command injection vulnerability in the function formWriteFacMac.
local
low complexity
jensenofscandinavia CWE-77
7.8
2024-01-17 CVE-2024-20287 Command Injection vulnerability in Cisco Wap371 Firmware
A vulnerability in the web-based management interface of the Cisco WAP371 Wireless-AC/N Dual Radio Access Point (AP) with Single Point Setup could allow an authenticated, remote attacker to perform command injection attacks against an affected device.
network
low complexity
cisco CWE-77
7.2
2024-01-16 CVE-2024-0507 Command Injection vulnerability in Github Enterprise Server
An attacker with access to a Management Console user account with the editor role could escalate privileges through a command injection vulnerability in the Management Console.
network
low complexity
github CWE-77
8.8
2024-01-16 CVE-2023-4797 Command Injection vulnerability in Tribulant Newsletters
The Newsletters WordPress plugin before 4.9.3 does not properly escape user-controlled parameters when they are appended to SQL queries and shell commands, which could enable an administrator to run arbitrary commands on the server.
network
low complexity
tribulant CWE-77
7.2
2024-01-12 CVE-2024-21887 Command Injection vulnerability in Ivanti Connect Secure and Policy Secure
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.
network
low complexity
ivanti CWE-77
critical
9.1