Vulnerabilities > Improper Neutralization of Special Elements used in a Command ('Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2023-02-02 CVE-2023-0640 Command Injection vulnerability in Trendnet Tew-652Brp Firmware 3.04B01
A vulnerability was found in TRENDnet TEW-652BRP 3.04b01.
network
low complexity
trendnet CWE-77
critical
9.8
2023-02-01 CVE-2023-22657 Command Injection vulnerability in F5 F5Os-A and F5Os-C
On F5OS-A beginning in version 1.2.0 to before 1.3.0 and F5OS-C beginning in version 1.3.0 to before 1.5.0, processing F5OS tenant file names may allow for command injection.
local
low complexity
f5 CWE-77
7.8
2023-02-01 CVE-2023-0611 Command Injection vulnerability in Trendnet Tew-652Brp Firmware 3.04B01
A vulnerability, which was classified as critical, has been found in TRENDnet TEW-652BRP 3.04B01.
network
low complexity
trendnet CWE-77
8.8
2023-02-01 CVE-2022-45095 Command Injection vulnerability in Dell EMC Powerscale Onefs
Dell PowerScale OneFS, 8.2.x-9.4.x, contain a command injection vulnerability.
local
low complexity
dell CWE-77
6.7
2023-01-30 CVE-2023-24612 Command Injection vulnerability in Pdfbook Project Pdfbook 2.0.5
The PdfBook extension through 2.0.5 before b07b6a64 for MediaWiki allows command injection via an option.
network
low complexity
pdfbook-project CWE-77
critical
9.8
2023-01-27 CVE-2021-41144 Command Injection vulnerability in Openmage Magento
OpenMage LTS is an e-commerce platform.
network
low complexity
openmage CWE-77
8.8
2023-01-27 CVE-2021-39217 Command Injection vulnerability in Openmage Magento
OpenMage LTS is an e-commerce platform.
network
low complexity
openmage CWE-77
7.2
2023-01-21 CVE-2023-22884 Command Injection vulnerability in Apache Airflow
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow, Apache Software Foundation Apache Airflow MySQL Provider.This issue affects Apache Airflow: before 2.5.1; Apache Airflow MySQL Provider: before 4.0.0.
network
low complexity
apache CWE-77
critical
9.8
2023-01-20 CVE-2020-22662 Command Injection vulnerability in Ruckuswireless products
In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10.5.1.0.199, SmartCell Gateway 200 (SCG200) before 3.6.2.0.795, SmartZone 100 (SZ-100) before 3.6.2.0.795, SmartZone 300 (SZ300) before 3.6.2.0.795, Virtual SmartZone (vSZ) before 3.6.2.0.795, ZoneDirector 1100 9.10.2.0.130, ZoneDirector 1200 10.2.1.0.218, ZoneDirector 3000 10.2.1.0.218, ZoneDirector 5000 10.0.1.0.151, a vulnerability allows attackers to change and set unauthorized "illegal region code" by remote code Execution command injection which leads to run illegal frequency with maxi output power.
network
low complexity
ruckuswireless CWE-77
7.5
2023-01-16 CVE-2023-0315 Command Injection vulnerability in Froxlor
Command Injection in GitHub repository froxlor/froxlor prior to 2.0.8.
network
low complexity
froxlor CWE-77
8.8