Vulnerabilities > Improper Neutralization of Special Elements used in a Command ('Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2024-10-02 CVE-2024-20432 Command Injection vulnerability in Cisco Nexus Dashboard Fabric Controller
A vulnerability in the REST API and web UI of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, low-privileged, remote attacker to perform a command injection attack against an affected device.   This vulnerability is due to improper user authorization and insufficient validation of command arguments.
network
low complexity
cisco CWE-77
8.8
2024-10-02 CVE-2024-20492 Command Injection vulnerability in Cisco Telepresence Video Communication Server
A vulnerability in the restricted shell of Cisco Expressway Series could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root.
local
low complexity
cisco CWE-77
6.7
2024-09-26 CVE-2024-8405 Command Injection vulnerability in Papercut NG
An arbitrary file creation vulnerability exists in PaperCut NG/MF that only affects Windows servers with Web Print enabled.
local
low complexity
papercut CWE-77
5.5
2024-09-25 CVE-2024-7575 Command Injection vulnerability in Telerik UI for WPF
In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a command injection attack is possible through improper neutralization of hyperlink elements.
network
low complexity
telerik CWE-77
critical
9.8
2024-09-25 CVE-2024-7679 Command Injection vulnerability in Telerik UI for WPF
In Progress Telerik UI for WinForms versions prior to 2024 Q3 (2024.3.924), a command injection attack is possible through improper neutralization of hyperlink elements.
local
low complexity
telerik CWE-77
7.8
2024-09-25 CVE-2024-43693 Command Injection vulnerability in Doverfuelingsolutions products
A specially crafted POST request to the ProGauge MAGLINK LX CONSOLE UTILITY sub-menu can allow a remote attacker to inject arbitrary commands.
network
low complexity
doverfuelingsolutions CWE-77
critical
9.8
2024-09-25 CVE-2024-45066 Command Injection vulnerability in Doverfuelingsolutions products
A specially crafted POST request to the ProGauge MAGLINK LX CONSOLE IP sub-menu can allow a remote attacker to inject arbitrary commands.
network
low complexity
doverfuelingsolutions CWE-77
critical
9.8
2024-09-23 CVE-2024-0005 Command Injection vulnerability in Purestorage Purity//Fa
A condition exists in FlashArray and FlashBlade Purity whereby a malicious user could execute arbitrary commands remotely through a specifically crafted SNMP configuration.
network
low complexity
purestorage CWE-77
8.8
2024-09-13 CVE-2024-42025 Command Injection vulnerability in UI Unifi Network Application
A Command Injection vulnerability found in a Self-Hosted UniFi Network Servers (Linux) with UniFi Network Application (Version 8.3.32 and earlier) allows a malicious actor with unifi user shell access to escalate privileges to root on the host device.
local
low complexity
ui CWE-77
7.8
2024-09-13 CVE-2024-46048 Command Injection vulnerability in Tenda Fh451 Firmware 1.0.0.9
Tenda FH451 v1.0.0.9 has a command injection vulnerability in the formexeCommand function i
network
low complexity
tenda CWE-77
critical
9.8