Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2024-06-24 CVE-2024-37091 OS Command Injection vulnerability in Stylemixthemes Consulting Elementor Widgets
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in StylemixThemes Consulting Elementor Widgets, StylemixThemes Masterstudy Elementor Widgets allows OS Command Injection.This issue affects Consulting Elementor Widgets: from n/a through 1.3.0; Masterstudy Elementor Widgets: from n/a through 1.2.2.
network
low complexity
stylemixthemes CWE-78
8.8
2024-06-24 CVE-2024-3121 OS Command Injection vulnerability in Lollms 5.9.0
A remote code execution vulnerability exists in the create_conda_env function of the parisneo/lollms repository, version 5.9.0.
local
low complexity
lollms CWE-78
3.3
2024-06-09 CVE-2024-4577 OS Command Injection vulnerability in multiple products
In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use "Best-Fit" behavior to replace characters in command line given to Win32 API functions.
network
low complexity
php fedoraproject CWE-78
critical
9.8
2024-05-16 CVE-2024-30314 OS Command Injection vulnerability in Adobe Dreamweaver
Dreamweaver Desktop versions 21.3 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could lead in arbitrary code execution by an attacker.
local
low complexity
adobe CWE-78
7.8
2024-05-03 CVE-2023-51625 OS Command Injection vulnerability in Dlink Dcs-8300Lhv2 Firmware
D-Link DCS-8300LHV2 ONVIF SetSystemDateAndTime Command Injection Remote Code Execution Vulnerability.
low complexity
dlink CWE-78
8.0
2024-04-24 CVE-2024-20358 OS Command Injection vulnerability in Cisco Adaptive Security Appliance Software
A vulnerability in the Cisco Adaptive Security Appliance (ASA) restore functionality that is available in Cisco ASA Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system with root-level privileges.
local
low complexity
cisco CWE-78
6.7
2024-02-23 CVE-2024-1683 OS Command Injection vulnerability in Tenable Identity Exposure
A DLL injection vulnerability exists where an authenticated, low-privileged local attacker could modify application files on the TIE Secure Relay host, which could allow for overriding of the configuration and running of new Secure Relay services.
local
low complexity
tenable CWE-78
7.3
2024-02-22 CVE-2023-51450 OS Command Injection vulnerability in Basercms
baserCMS is a website development framework.
network
high complexity
basercms CWE-78
8.1
2024-02-21 CVE-2024-1212 OS Command Injection vulnerability in Progress Loadmaster
Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.
network
low complexity
progress CWE-78
critical
9.8
2024-02-17 CVE-2024-25468 OS Command Injection vulnerability in Totolink X5000R Firmware 9.1.0U.6369B20230113
An issue in TOTOLINK X5000R V.9.1.0u.6369_B20230113 allows a remote attacker to cause a denial of service via the host_time parameter of the NTPSyncWithHost component.
network
low complexity
totolink CWE-78
7.5