Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2019-10-31 CVE-2019-18424 OS Command Injection vulnerability in multiple products
An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has access to a physical device.
6.8
2019-10-28 CVE-2019-14931 OS Command Injection vulnerability in multiple products
An issue was discovered on Mitsubishi Electric Europe B.V.
network
low complexity
mitsubishielectric inea CWE-78
critical
9.8
2019-10-28 CVE-2019-16663 OS Command Injection vulnerability in Rconfig 3.9.2
An issue was discovered in rConfig 3.9.2.
network
low complexity
rconfig CWE-78
8.8
2019-10-28 CVE-2019-16662 OS Command Injection vulnerability in Rconfig 3.9.2
An issue was discovered in rConfig 3.9.2.
network
low complexity
rconfig CWE-78
critical
9.8
2019-10-25 CVE-2019-5129 OS Command Injection vulnerability in Youphptube Encoder 2.3
A command injection have been found in YouPHPTube Encoder.
network
low complexity
youphptube CWE-78
critical
9.8
2019-10-25 CVE-2019-5128 OS Command Injection vulnerability in Youphptube Encoder 2.3
A command injection have been found in YouPHPTube Encoder.
network
low complexity
youphptube CWE-78
critical
9.8
2019-10-25 CVE-2019-5127 OS Command Injection vulnerability in Youphptube Encoder 2.3
A command injection have been found in YouPHPTube Encoder.
network
low complexity
youphptube CWE-78
critical
9.8
2019-10-24 CVE-2019-13653 OS Command Injection vulnerability in Tp-Link M7350 Firmware 1.0.16
TP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow triggerPort OS Command Injection (issue 5 of 5).
network
low complexity
tp-link CWE-78
critical
9.8
2019-10-24 CVE-2019-13652 OS Command Injection vulnerability in Tp-Link M7350 Firmware 1.0.16
TP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow serviceName OS Command Injection (issue 4 of 5).
network
low complexity
tp-link CWE-78
critical
9.8
2019-10-24 CVE-2019-13651 OS Command Injection vulnerability in Tp-Link M7350 Firmware 1.0.16
TP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow portMappingProtocol OS Command Injection (issue 3 of 5).
network
low complexity
tp-link CWE-78
critical
9.8