Vulnerabilities > Improper Neutralization of Special Elements used in a Command ('Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2023-06-12 CVE-2023-35033 Command Injection vulnerability in Atos products
Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8, Assistant V10 R0, Manager V10 R1 before V10 R1.42.0 and V10 R1.34.8, and Manager V10 R0 allow command injection by authenticated users, aka OSFOURK-23556.
network
low complexity
atos CWE-77
8.8
2023-06-12 CVE-2023-35035 Command Injection vulnerability in Atos products
Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8, Assistant V10 R0, Manager V10 R1 before V10 R1.42.0 and V10 R1.34.8, and Manager V10 R0 allow command injection by authenticated users, aka OSFOURK-23557.
network
low complexity
atos CWE-77
8.8
2023-06-11 CVE-2023-25911 Command Injection vulnerability in Danfoss Ak-Em100 Firmware
The Danfoss AK-EM100 web applications allow for an authenticated user to perform OS command injection through the web application parameters.
network
low complexity
danfoss CWE-77
critical
9.8
2023-06-08 CVE-2023-34230 Command Injection vulnerability in Snowflake Connector
snowflake-connector-net, the Snowflake Connector for .NET, is vulnerable to command injection prior to version 2.0.18 via SSO URL authentication.
network
low complexity
snowflake CWE-77
8.8
2023-06-08 CVE-2023-34232 Command Injection vulnerability in Snowflake Connector
snowflake-connector-nodejs, a NodeJS driver for Snowflake, is vulnerable to command injection via single sign on (SSO) browser URL authentication in versions prior to 1.6.21.
network
low complexity
snowflake CWE-77
8.8
2023-06-08 CVE-2023-34233 Command Injection vulnerability in Snowflake Connector
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations.
network
low complexity
snowflake CWE-77
8.8
2023-06-08 CVE-2023-34231 Command Injection vulnerability in Snowflake Gosnowflake
gosnowflake is th Snowflake Golang driver.
network
low complexity
snowflake CWE-77
8.8
2023-06-07 CVE-2023-33556 Command Injection vulnerability in Totolink A7100Ru Firmware 7.4Cu.2313B20191024
TOTOLink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the staticGw parameter at /setting/setWanIeCfg.
network
low complexity
totolink CWE-77
critical
9.8
2023-06-07 CVE-2023-20887 Command Injection vulnerability in VMWare Aria Operations for Networks
Aria Operations for Networks contains a command injection vulnerability.
network
low complexity
vmware CWE-77
critical
9.8
2023-06-07 CVE-2023-20889 Command Injection vulnerability in VMWare Vrealize Network Insight
Aria Operations for Networks contains an information disclosure vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in information disclosure.
network
low complexity
vmware CWE-77
7.5