Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-04-25 | CVE-2023-25313 | OS Command Injection vulnerability in Wwbn Avideo OS injection vulnerability in World Wide Broadcast Network AVideo version before 12.4, allows attackers to execute arbitrary code via the video link field to the Embed a video link feature. | 9.8 |
2023-04-24 | CVE-2023-27991 | OS Command Injection vulnerability in Zyxel products The post-authentication command injection vulnerability in the CLI command of Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, USG20(W)-VPN firmware versions 4.16 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow an authenticated attacker to execute some OS commands remotely. | 8.8 |
2023-04-22 | CVE-2023-25507 | OS Command Injection vulnerability in Nvidia BMC NVIDIA DGX-1 BMC contains a vulnerability in the SPX REST API, where an attacker with the appropriate level of authorization can inject arbitrary shell commands, which may lead to code execution, denial of service, information disclosure, and data tampering. | 8.8 |
2023-04-20 | CVE-2023-2131 | OS Command Injection vulnerability in Inea ME RTU Firmware Versions of INEA ME RTU firmware prior to 3.36 are vulnerable to OS command injection, which could allow an attacker to remotely execute arbitrary code. | 9.8 |
2023-04-19 | CVE-2023-25759 | OS Command Injection vulnerability in Uniguest Tripleplay 3.4.0 OS Command Injection in TripleData Reporting Engine in Tripleplay Platform releases prior to Caveman 3.4.0 allows authenticated users to run unprivileged OS level commands via a crafted request payload. | 5.4 |
2023-04-16 | CVE-2022-38841 | OS Command Injection vulnerability in Linksys E8450 Firmware 1.1.00 Linksys AX3200 1.1.00 is vulnerable to OS command injection by authenticated users via shell metacharacters to the diagnostics traceroute page. | 8.8 |
2023-04-14 | CVE-2023-29804 | OS Command Injection vulnerability in Iodata Wfs-Sr03K Firmware and Wfs-Sr03W Firmware WFS-SR03 v1.0.3 was discovered to contain a command injection vulnerability via the sys_smb_pwdmod function. | 8.8 |
2023-04-14 | CVE-2023-29805 | OS Command Injection vulnerability in Iodata Wfs-Sr03K Firmware and Wfs-Sr03W Firmware WFS-SR03 v1.0.3 was discovered to contain a command injection vulnerability via the pro_stor_canceltrans_handler_part_19 function. | 9.8 |
2023-04-12 | CVE-2023-27216 | OS Command Injection vulnerability in Dlink Dsl-3782 Firmware 1.03 An issue found in D-Link DSL-3782 v.1.03 allows remote authenticated users to execute arbitrary code as root via the network settings page. | 8.8 |
2023-04-12 | CVE-2023-27826 | OS Command Injection vulnerability in Seowonintech Swc-5100W Firmware 1.11.0.1/1.9.9.4 SeowonIntech SWC 5100W WIMAX Bootloader 1.18.19.0, HW 0.0.7.0, and FW 1.11.0.1, 1.9.9.4 are vulnerable to OS Command Injection. | 8.8 |