Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2024-11-08 CVE-2024-45765 OS Command Injection vulnerability in Dell Enterprise Sonic Distribution
Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability.
network
low complexity
dell CWE-78
7.2
2024-11-06 CVE-2024-10919 OS Command Injection vulnerability in Didi Super-Jacoco 1.0
A vulnerability has been found in didi Super-Jacoco 1.0 and classified as critical.
network
low complexity
didi CWE-78
critical
9.8
2024-11-06 CVE-2024-10915 OS Command Injection vulnerability in Dlink products
A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028.
network
low complexity
dlink CWE-78
critical
9.8
2024-11-05 CVE-2023-29120 OS Command Injection vulnerability in Enelx Waybox PRO Firmware
Waybox Enel X web management application could be used to execute arbitrary OS commands and provide administrator’s privileges over the Waybox system.
low complexity
enelx CWE-78
8.8
2024-11-04 CVE-2024-51661 OS Command Injection vulnerability in Davidlingren Media Library Assistant
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in David Lingren Media Library Assistant allows Command Injection.This issue affects Media Library Assistant: from n/a through 3.19.
network
low complexity
davidlingren CWE-78
7.2
2024-11-01 CVE-2024-51252 OS Command Injection vulnerability in Draytek Vigor3900 Firmware 1.5.1.3
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the restore function.
network
low complexity
draytek CWE-78
critical
9.8
2024-11-01 CVE-2024-51244 OS Command Injection vulnerability in Draytek Vigor3900 Firmware 1.5.1.3
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doIPSec function.
network
low complexity
draytek CWE-78
8.8
2024-11-01 CVE-2024-51245 OS Command Injection vulnerability in Draytek Vigor3900 Firmware 1.5.1.3
In DrayTek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the rename_table function.
network
low complexity
draytek CWE-78
8.8
2024-11-01 CVE-2024-51247 OS Command Injection vulnerability in Draytek Vigor3900 Firmware 1.5.1.3
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doPPPo function.
network
low complexity
draytek CWE-78
8.8
2024-11-01 CVE-2024-51248 OS Command Injection vulnerability in Draytek Vigor3900 Firmware 1.5.1.3
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the modifyrow function.
network
low complexity
draytek CWE-78
8.8