Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-11-30 | CVE-2023-37928 | OS Command Injection vulnerability in Zyxel Nas326 Firmware and Nas542 Firmware A post-authentication command injection vulnerability in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an authenticated attacker to execute some operating system (OS) commands by sending a crafted URL to a vulnerable device. | 8.8 |
2023-11-30 | CVE-2023-4473 | OS Command Injection vulnerability in Zyxel Nas326 Firmware and Nas542 Firmware A command injection vulnerability in the web server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted URL to a vulnerable device. | 9.8 |
2023-11-30 | CVE-2023-4474 | OS Command Injection vulnerability in Zyxel Nas326 Firmware and Nas542 Firmware The improper neutralization of special elements in the WSGI server of the Zyxel NAS326 firmware version V5.21(AAZF.14)C0 and NAS542 firmware version V5.21(ABAG.11)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands by sending a crafted URL to a vulnerable device. | 9.8 |
2023-11-30 | CVE-2023-3741 | OS Command Injection vulnerability in NEC products An OS Command injection vulnerability in NEC Platforms DT900 and DT900S Series all versions allows an attacker to execute any command on the device. | 9.8 |
2023-11-29 | CVE-2023-23325 | OS Command Injection vulnerability in Zumtobel Netlink CCD Firmware 3.80 Zumtobel Netlink CCD Onboard 3.74 - Firmware 3.80 was discovered to contain a command injection vulnerability via the NetHostname parameter. | 9.8 |
2023-11-28 | CVE-2023-6201 | OS Command Injection vulnerability in Univera Panorama Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Univera Computer System Panorama allows Command Injection.This issue affects Panorama: before 8.0. | 8.8 |
2023-11-28 | CVE-2023-4221 | OS Command Injection vulnerability in Chamilo LMS Command injection in `main/lp/openoffice_presentation.class.php` in Chamilo LMS <= v1.11.24 allows users permitted to upload Learning Paths to obtain remote code execution via improper neutralisation of special characters. | 8.8 |
2023-11-28 | CVE-2023-4222 | OS Command Injection vulnerability in Chamilo LMS Command injection in `main/lp/openoffice_text_document.class.php` in Chamilo LMS <= v1.11.24 allows users permitted to upload Learning Paths to obtain remote code execution via improper neutralisation of special characters. | 8.8 |
2023-11-28 | CVE-2023-3368 | OS Command Injection vulnerability in Chamilo Command injection in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to obtain remote code execution via improper neutralisation of special characters. | 9.8 |
2023-11-27 | CVE-2023-6309 | OS Command Injection vulnerability in Moses-Smt Mosesdecoder A vulnerability, which was classified as critical, was found in moses-smt mosesdecoder up to 4.0. | 9.8 |