Vulnerabilities > Improper Neutralization of Special Elements used in a Command ('Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2023-03-13 CVE-2023-0628 Command Injection vulnerability in Docker Desktop
Docker Desktop before 4.17.0 allows an attacker to execute an arbitrary command inside a Dev Environments container during initialization by tricking a user to open a crafted malicious docker-desktop:// URL.
local
low complexity
docker CWE-77
7.8
2023-03-06 CVE-2023-0093 Command Injection vulnerability in Okta Advanced Server Access
Okta Advanced Server Access Client versions 1.13.1 through 1.65.0 are vulnerable to command injection due to the third party library webbrowser.
network
low complexity
okta CWE-77
8.8
2023-03-05 CVE-2021-4329 Command Injection vulnerability in Json-Logic-Js Project Json-Logic-Js 2.0.0
A vulnerability, which was classified as critical, has been found in json-logic-js 2.0.0.
network
low complexity
json-logic-js-project CWE-77
critical
9.8
2023-03-01 CVE-2023-1097 Command Injection vulnerability in Baicells Eg7035-M11 Firmware Bceodu1.0.8
Baicells EG7035-M11 devices with firmware through BCE-ODU-1.0.8 are vulnerable to improper code exploitation via HTTP GET command injections.
network
low complexity
baicells CWE-77
critical
9.8
2023-03-01 CVE-2021-3855 Command Injection vulnerability in Liman Port MYS 1.7.0
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Liman Central Management System Liman MYS (HTTP/Controllers, CronMail, Jobs modules) allows Command Injection.This issue affects Liman Central Management System: from 1.7.0 before 1.8.3-462.
network
low complexity
liman CWE-77
8.8
2023-03-01 CVE-2023-22747 Command Injection vulnerability in Arubanetworks Arubaos and Sd-Wan
There are multiple command injection vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks access point management protocol) UDP port (8211).
network
low complexity
arubanetworks CWE-77
critical
9.8
2023-03-01 CVE-2023-22748 Command Injection vulnerability in Arubanetworks Arubaos and Sd-Wan
There are multiple command injection vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks access point management protocol) UDP port (8211).
network
low complexity
arubanetworks CWE-77
critical
9.8
2023-03-01 CVE-2023-22749 Command Injection vulnerability in Arubanetworks Arubaos and Sd-Wan
There are multiple command injection vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks access point management protocol) UDP port (8211).
network
low complexity
arubanetworks CWE-77
critical
9.8
2023-03-01 CVE-2023-22750 Command Injection vulnerability in Arubanetworks Arubaos and Sd-Wan
There are multiple command injection vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks access point management protocol) UDP port (8211).
network
low complexity
arubanetworks CWE-77
critical
9.8
2023-03-01 CVE-2023-22758 Command Injection vulnerability in Arubanetworks Arubaos and Sd-Wan
Authenticated remote command injection vulnerabilities exist in the ArubaOS web-based management interface.
network
low complexity
arubanetworks CWE-77
7.2