Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2024-01-08 CVE-2024-0298 OS Command Injection vulnerability in Totolink N200Re Firmware 9.3.5U.6139B20201216
A vulnerability was found in Totolink N200RE 9.3.5u.6139_B20201216.
network
low complexity
totolink CWE-78
critical
9.8
2024-01-08 CVE-2024-0292 OS Command Injection vulnerability in Totolink Lr1200Gb Firmware 9.1.0U.6619B20230130
A vulnerability classified as critical has been found in Totolink LR1200GB 9.1.0u.6619_B20230130.
network
low complexity
totolink CWE-78
critical
9.8
2024-01-05 CVE-2023-41289 OS Command Injection vulnerability in Qnap Qcalagent 1.1.6/1.1.7
An OS command injection vulnerability has been reported to affect QcalAgent.
network
low complexity
qnap CWE-78
8.8
2024-01-03 CVE-2023-52310 OS Command Injection vulnerability in Paddlepaddle
PaddlePaddle before 2.6.0 has a command injection in get_online_pass_interval.
network
low complexity
paddlepaddle CWE-78
critical
9.8
2024-01-03 CVE-2023-52311 OS Command Injection vulnerability in Paddlepaddle
PaddlePaddle before 2.6.0 has a command injection in _wget_download.
network
low complexity
paddlepaddle CWE-78
critical
9.8
2024-01-03 CVE-2023-52314 OS Command Injection vulnerability in Paddlepaddle
PaddlePaddle before 2.6.0 has a command injection in convert_shape_compare.
network
low complexity
paddlepaddle CWE-78
critical
9.8
2024-01-01 CVE-2023-50094 OS Command Injection vulnerability in Yogeshojha Rengine
reNgine before 2.1.2 allows OS Command Injection if an adversary has a valid session ID.
network
low complexity
yogeshojha CWE-78
8.8
2023-12-30 CVE-2023-50651 OS Command Injection vulnerability in Totolink X6000R Firmware 9.4.0Cu.852B20230719
TOTOLINK X6000R v9.4.0cu.852_B20230719 was discovered to contain a remote command execution (RCE) vulnerability via the component /cgi-bin/cstecgi.cgi.
network
low complexity
totolink CWE-78
critical
9.8
2023-12-28 CVE-2023-50445 OS Command Injection vulnerability in Gl-Inet products
Shell Injection vulnerability GL.iNet A1300 v4.4.6, AX1800 v4.4.6, AXT1800 v4.4.6, MT3000 v4.4.6, MT2500 v4.4.6, MT6000 v4.5.0, MT1300 v4.3.7, MT300N-V2 v4.3.7, AR750S v4.3.7, AR750 v4.3.7, AR300M v4.3.7, and B1300 v4.3.7., allows local attackers to execute arbitrary code via the get_system_log and get_crash_log functions of the logread module, as well as the upgrade_online function of the upgrade module.
local
low complexity
gl-inet CWE-78
7.8
2023-12-26 CVE-2023-51094 OS Command Injection vulnerability in Tenda M3 Firmware 1.0.0.12(4856)
Tenda M3 V1.0.0.12(4856) was discovered to contain a Command Execution vulnerability via the function TendaTelnet.
network
low complexity
tenda CWE-78
critical
9.8