Vulnerabilities > Improper Neutralization of Special Elements used in a Command ('Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2022-07-06 CVE-2022-28935 Command Injection vulnerability in Totolink products
Totolink A830R V5.9c.4729_B20191112, Totolink A3100R V4.1.2cu.5050_B20200504, Totolink A950RG V4.1.2cu.5161_B20200903, Totolink A800R V4.1.2cu.5137_B20200730, Totolink A3000RU V5.9c.5185_B20201128, Totolink A810R V4.1.2cu.5182_B20201026 were discovered to contain a command injection vulnerability.
network
low complexity
totolink CWE-77
7.2
2022-06-27 CVE-2022-28171 Command Injection vulnerability in Hikvision products
The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability.
network
low complexity
hikvision CWE-77
critical
9.8
2022-06-17 CVE-2022-31874 Command Injection vulnerability in Asus Rt-N53 Firmware 3.0.0.4.376.3754
ASUS RT-N53 3.0.0.4.376.3754 has a command injection vulnerability in the SystemCmd parameter of the apply.cgi interface.
network
low complexity
asus CWE-77
critical
9.8
2022-06-15 CVE-2022-32154 Command Injection vulnerability in Splunk
Dashboards in Splunk Enterprise versions before 9.0 might let an attacker inject risky search commands into a form token when the token is used in a query in a cross-origin request.
network
low complexity
splunk CWE-77
8.1
2022-06-14 CVE-2022-32262 Command Injection vulnerability in Siemens Sinema Remote Connect Server
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1).
network
low complexity
siemens CWE-77
critical
9.8
2022-06-07 CVE-2019-9972 Command Injection vulnerability in multiple products
PhoneSystem Terminal in 3CX Phone System (Debian based installation) 16.0.0.1570 allows an authenticated attacker to run arbitrary commands with the phonesystem user privileges because of "<space><space> followed by <shift><enter>" mishandling.
network
low complexity
3cx debian CWE-77
8.8
2022-06-07 CVE-2020-36529 Command Injection vulnerability in IBM Sevone Network Performance Management
A vulnerability classified as critical has been found in SevOne Network Management System up to 5.7.2.22.
network
low complexity
ibm CWE-77
8.8
2022-06-02 CVE-2022-29712 Command Injection vulnerability in Librenms 22.3.0
LibreNMS v22.3.0 was discovered to contain multiple command injection vulnerabilities via the service_ip, hostname, and service_param parameters.
network
low complexity
librenms CWE-77
critical
9.8
2022-05-25 CVE-2022-30321 Command Injection vulnerability in Hashicorp Go-Getter
go-getter up to 1.5.11 and 2.0.2 allowed arbitrary host access via go-getter path traversal, symlink processing, and command injection flaws.
network
low complexity
hashicorp CWE-77
8.6
2022-05-20 CVE-2022-28618 Command Injection vulnerability in HPE Nimbleos
A command injection security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Storage All Flash Arrays and HPE Nimble Storage Secondary Flash Arrays that could allow an attacker to execute arbitrary commands on a Nimble appliance.
network
low complexity
hpe CWE-77
critical
9.8