Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2024-11-01 CVE-2024-51244 OS Command Injection vulnerability in Draytek Vigor3900 Firmware 1.5.1.3
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doIPSec function.
network
low complexity
draytek CWE-78
8.8
2024-11-01 CVE-2024-51245 OS Command Injection vulnerability in Draytek Vigor3900 Firmware 1.5.1.3
In DrayTek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the rename_table function.
network
low complexity
draytek CWE-78
8.8
2024-11-01 CVE-2024-51247 OS Command Injection vulnerability in Draytek Vigor3900 Firmware 1.5.1.3
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doPPPo function.
network
low complexity
draytek CWE-78
8.8
2024-11-01 CVE-2024-51248 OS Command Injection vulnerability in Draytek Vigor3900 Firmware 1.5.1.3
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the modifyrow function.
network
low complexity
draytek CWE-78
8.8
2024-10-29 CVE-2024-51378 OS Command Injection vulnerability in Cyberpanel
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or /ftp/getresetstatus by bypassing secMiddleware (which is only for a POST request) and using shell metacharacters in the statusfile property, as exploited in the wild in October 2024 by PSAUX.
network
low complexity
cyberpanel CWE-78
critical
9.8
2024-10-25 CVE-2024-37845 OS Command Injection vulnerability in Radixiot Mango
MangoOS before 5.2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the Active Process Command feature.
network
low complexity
radixiot CWE-78
7.2
2024-10-23 CVE-2024-48963 OS Command Injection vulnerability in Snyk CLI
The package Snyk CLI before 1.1294.0 is vulnerable to Code Injection when scanning an untrusted PHP project.
network
low complexity
snyk CWE-78
critical
9.8
2024-10-23 CVE-2024-20424 OS Command Injection vulnerability in Cisco Secure Firewall Management Center
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system as root. This vulnerability is due to insufficient input validation of certain HTTP requests.
network
low complexity
cisco CWE-78
critical
9.9
2024-10-23 CVE-2024-47901 OS Command Injection vulnerability in Siemens products
A vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fire Subscriber (All versions < V7.2.12 only if the IP interface is enabled (which is not the default configuration)).
network
low complexity
siemens CWE-78
critical
9.8
2024-10-21 CVE-2024-10202 OS Command Injection vulnerability in Wellchoose Administrative Management System
Administrative Management System from Wellchoose has an OS Command Injection vulnerability, allowing remote attackers with regular privileges to inject and execute arbitrary OS commands.
network
low complexity
wellchoose CWE-78
8.8