Vulnerabilities > Improper Neutralization of Special Elements used in a Command ('Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2024-01-11 CVE-2023-6634 Command Injection vulnerability in Thimpress Learnpress
The LearnPress plugin for WordPress is vulnerable to Command Injection in all versions up to, and including, 4.2.5.7 via the get_content function.
network
low complexity
thimpress CWE-77
critical
9.8
2024-01-10 CVE-2023-51126 Command Injection vulnerability in Flir AX8 Firmware
Command injection vulnerability in /usr/www/res.php in FLIR AX8 up to 1.46.16 allows attackers to run arbitrary commands via the value parameter.
network
low complexity
flir CWE-77
critical
9.8
2024-01-10 CVE-2023-51972 Command Injection vulnerability in Tenda Ax1803 Firmware 1.0.0.1
Tenda AX1803 v1.0.0.1 was discovered to contain a command injection vulnerability via the function fromAdvSetLanIp.
network
low complexity
tenda CWE-77
critical
9.8
2024-01-09 CVE-2023-49237 Command Injection vulnerability in Trendnet Tv-Ip1314Pi Firmware 5.5.3
An issue was discovered on TRENDnet TV-IP1314PI 5.5.3 200714 devices.
network
low complexity
trendnet CWE-77
critical
9.8
2024-01-09 CVE-2024-21663 Command Injection vulnerability in Demon1A Discord-Recon
Discord-Recon is a Discord bot created to automate bug bounty recon, automated scans and information gathering via a discord server.
network
low complexity
demon1a CWE-77
8.8
2023-12-29 CVE-2023-52137 Command Injection vulnerability in Tj-Actions Verify-Changed-Files
The [`tj-actions/verify-changed-files`](https://github.com/tj-actions/verify-changed-files) action allows for command injection in changed filenames, allowing an attacker to execute arbitrary code and potentially leak secrets.
network
low complexity
tj-actions CWE-77
8.8
2023-12-27 CVE-2023-51664 Command Injection vulnerability in Tj-Actions Changed-Files
tj-actions/changed-files is a Github action to retrieve all files and directories.
network
low complexity
tj-actions CWE-77
critical
9.8
2023-12-25 CVE-2023-49226 Command Injection vulnerability in Peplink Balance TWO Firmware 8.1.0
An issue was discovered in Peplink Balance Two before 8.4.0.
network
low complexity
peplink CWE-77
7.2
2023-12-22 CVE-2023-51016 Command Injection vulnerability in Totolink Ex1800T Firmware 9.1.0Cu.2112B20220316
TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the setRebootScheCfg interface of the cstecgi .cgi.
network
low complexity
totolink CWE-77
critical
9.8
2023-12-22 CVE-2023-51707 Command Injection vulnerability in Arraynetworks Arrayos AG
MotionPro in Array ArrayOS AG before 9.4.0.505 on AG and vxAG allows remote command execution via crafted packets.
network
low complexity
arraynetworks CWE-77
critical
9.8