VUMETRIC
CYBER PORTAL
Dashboard
Security News
Latest Vulnerabilities
Browse Vulnerabilities
by Vendors
by Products
by Categories
Weekly Reports
Vulnerabilities
> Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Exclude new CVEs:
DATE
CVE
VULNERABILITY TITLE
RISK
2025-03-11
CVE-2024-12010
A post-authentication command injection vulnerability in the ”zyUtilMailSend” function of the Zyxel AX7501-B1 firmware version V5.17(ABPC.5.3)C0 and earlier could allow an authenticated attacker with administrator privileges to execute operating system (OS) commands on a vulnerable device.
network
low complexity
CWE-78
7.2
7.2
2025-03-07
CVE-2025-2094
OS Command Injection vulnerability in Totolink Ex1800T Firmware 9.1.0Cu.2112B20220316
A vulnerability was found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316.
network
low complexity
totolink
CWE-78
critical
9.8
9.8
2025-03-07
CVE-2025-2095
OS Command Injection vulnerability in Totolink Ex1800T Firmware 9.1.0Cu.2112B20220316
A vulnerability classified as critical has been found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316.
network
low complexity
totolink
CWE-78
critical
9.8
9.8
2025-03-07
CVE-2025-2096
OS Command Injection vulnerability in Totolink Ex1800T Firmware 9.1.0Cu.2112B20220316
A vulnerability classified as critical was found in TOTOLINK EX1800T 9.1.0cu.2112_B20220316.
network
low complexity
totolink
CWE-78
critical
9.8
9.8
2025-03-05
CVE-2025-1316
OS Command Injection vulnerability in Edimax Ic-7100 Firmware
Edimax IC-7100 does not properly neutralize requests.
network
low complexity
edimax
CWE-78
critical
9.8
9.8
2025-03-02
CVE-2025-1829
OS Command Injection vulnerability in Totolink X18 Firmware 9.1.0Cu.2024B20220329
A vulnerability was found in TOTOLINK X18 9.1.0cu.2024_B20220329.
network
low complexity
totolink
CWE-78
8.8
8.8
2025-02-26
CVE-2025-20161
A vulnerability in the software upgrade process of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an authenticated, local attacker with valid Administrator credentials to execute a command injection attack on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of specific elements within a software image.
local
low complexity
CWE-78
5.1
5.1
2025-02-14
CVE-2024-55904
IBM DevOps Deploy 8.0 through 8.0.1.4, 8.1 through 8.1.0.0 / IBM UrbanCode Deploy 7.0 through 7.0.5.25, 7.1 through 7.1.2.21, 7.2 through 7.2.3.14, and 7.3 through 7.3.2.9 could allow a remote privileged authenticated attacker to execute arbitrary commands on the system by sending specially crafted input containing special elements.
network
low complexity
CWE-78
7.2
7.2
2025-02-13
CVE-2025-25067
OS Command Injection vulnerability in Myscada Mypro
mySCADA myPRO Manager is vulnerable to an OS command injection which could allow a remote attacker to execute arbitrary OS commands.
network
low complexity
myscada
CWE-78
critical
9.8
9.8
2025-02-11
CVE-2024-47908
OS Command Injection vulnerability in Ivanti Cloud Services Appliance
OS command injection in the admin web console of Ivanti CSA before version 5.0.5 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
network
low complexity
ivanti
CWE-78
7.2
7.2
«
Previous
1
2
3
(current)
4
5
...
297
298
»
Next