Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2019-10-31 CVE-2019-15710 OS Command Injection vulnerability in Fortiguard Fortiextender Firmware 4.1.1
An OS command injection vulnerability in FortiExtender 4.1.0 to 4.1.1, 4.0.0 and below under CLI admin console may allow unauthorized administrators to run arbitrary system level commands via specially crafted "execute date" commands.
network
low complexity
fortiguard CWE-78
7.2
2019-10-31 CVE-2013-2024 OS Command Injection vulnerability in multiple products
OS command injection vulnerability in the "qs" procedure from the "utils" module in Chicken before 4.9.0.
network
low complexity
call-cc debian CWE-78
8.8
2019-10-31 CVE-2019-18424 OS Command Injection vulnerability in multiple products
An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has access to a physical device.
6.8
2019-10-28 CVE-2019-14931 OS Command Injection vulnerability in multiple products
An issue was discovered on Mitsubishi Electric Europe B.V.
network
low complexity
mitsubishielectric inea CWE-78
critical
9.8
2019-10-28 CVE-2019-16663 OS Command Injection vulnerability in Rconfig 3.9.2
An issue was discovered in rConfig 3.9.2.
network
low complexity
rconfig CWE-78
8.8
2019-10-28 CVE-2019-16662 OS Command Injection vulnerability in Rconfig 3.9.2
An issue was discovered in rConfig 3.9.2.
network
low complexity
rconfig CWE-78
critical
9.8
2019-10-25 CVE-2019-5129 OS Command Injection vulnerability in Youphptube Encoder 2.3
A command injection have been found in YouPHPTube Encoder.
network
low complexity
youphptube CWE-78
critical
9.8
2019-10-25 CVE-2019-5128 OS Command Injection vulnerability in Youphptube Encoder 2.3
A command injection have been found in YouPHPTube Encoder.
network
low complexity
youphptube CWE-78
critical
9.8
2019-10-25 CVE-2019-5127 OS Command Injection vulnerability in Youphptube Encoder 2.3
A command injection have been found in YouPHPTube Encoder.
network
low complexity
youphptube CWE-78
critical
9.8
2019-10-24 CVE-2019-13653 OS Command Injection vulnerability in Tp-Link M7350 Firmware 1.0.16
TP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow triggerPort OS Command Injection (issue 5 of 5).
network
low complexity
tp-link CWE-78
critical
9.8