Vulnerabilities > Improper Neutralization of Special Elements used in a Command ('Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2023-01-14 CVE-2022-41955 Command Injection vulnerability in Autolabproject Autolab
Autolab is a course management service, initially developed by a team of students at Carnegie Mellon University, that enables instructors to offer autograded programming assignments to their students over the Web.
network
low complexity
autolabproject CWE-77
8.8
2023-01-14 CVE-2023-22496 Command Injection vulnerability in Netdata
Netdata is an open source option for real-time infrastructure monitoring and troubleshooting.
network
low complexity
netdata CWE-77
critical
9.8
2023-01-13 CVE-2022-4616 Command Injection vulnerability in Deltaww Dx-3021L9 Firmware
The webserver in Delta DX-3021 versions prior to 1.24 is vulnerable to command injection through the network diagnosis page.
network
low complexity
deltaww CWE-77
critical
9.1
2023-01-11 CVE-2020-36650 Command Injection vulnerability in GRY Project GRY
A vulnerability, which was classified as critical, was found in IonicaBizau node-gry up to 5.x.
low complexity
gry-project CWE-77
8.0
2023-01-10 CVE-2022-45094 Command Injection vulnerability in Siemens Sinec INS 1.0
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 1).
network
low complexity
siemens CWE-77
8.8
2023-01-06 CVE-2022-39073 Command Injection vulnerability in ZTE Mf286R Firmware Nordicmf286Rb06
There is a command injection vulnerability in ZTE MF286R, Due to insufficient validation of the input parameters, an attacker could use the vulnerability to execute arbitrary commands.
network
low complexity
zte CWE-77
critical
9.8
2023-01-06 CVE-2020-36642 Command Injection vulnerability in Jobe Project Jobe
A vulnerability was found in trampgeek jobe up to 1.6.x and classified as critical.
network
low complexity
jobe-project CWE-77
critical
9.8
2023-01-06 CVE-2023-22671 Command Injection vulnerability in NSA Ghidra
Ghidra/RuntimeScripts/Linux/support/launch.sh in NSA Ghidra through 10.2.2 passes user-provided input into eval, leading to command injection when calling analyzeHeadless with untrusted input.
network
low complexity
nsa CWE-77
critical
9.8
2023-01-05 CVE-2021-4304 Command Injection vulnerability in Ulcc-Core Project Ulcc-Core
A vulnerability was found in eprintsug ulcc-core.
network
low complexity
ulcc-core-project CWE-77
critical
9.8
2023-01-03 CVE-2022-32664 Command Injection vulnerability in Mediatek Linkit Software Development KIT 4.6.1
In Config Manager, there is a possible command injection due to improper input validation.
network
low complexity
mediatek CWE-77
8.8