Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2023-05-18 CVE-2023-20164 OS Command Injection vulnerability in Cisco Identity Services Engine
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform command injection attacks on the underlying operating system and elevate privileges to root.
network
low complexity
cisco CWE-78
7.2
2023-05-17 CVE-2023-24805 OS Command Injection vulnerability in multiple products
cups-filters contains backends, filters, and other software required to get the cups printing service working on operating systems other than macos.
network
low complexity
linuxfoundation fedoraproject debian CWE-78
8.8
2023-05-12 CVE-2020-13378 OS Command Injection vulnerability in Loadbalancer Enterprise VA MAX 8.3.3/8.3.8
Loadbalancer.org Enterprise VA MAX through 8.3.8 has an OS Command Injection vulnerability that allows a remote authenticated attacker to execute arbitrary code.
network
low complexity
loadbalancer CWE-78
8.8
2023-05-10 CVE-2022-29841 OS Command Injection vulnerability in Westerndigital MY Cloud OS
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that was caused by a command that read files from a privileged location and created a system command without sanitizing the read data.
network
low complexity
westerndigital CWE-78
critical
9.8
2023-05-10 CVE-2023-32568 OS Command Injection vulnerability in Veritas Infoscale Operations Manager
An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2.800 and 8.x before 8.0.410.
network
low complexity
veritas CWE-78
7.2
2023-05-09 CVE-2023-27407 OS Command Injection vulnerability in Siemens Scalance Lpe9403 Firmware 2.0
A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1).
network
low complexity
siemens CWE-78
critical
9.9
2023-05-05 CVE-2023-30053 OS Command Injection vulnerability in Totolink A7100Ru Firmware 7.4Cu.2313B20191024
TOTOLINK A7100RU V7.4cu.2313_B20191024 is vulnerable to Command Injection.
network
low complexity
totolink CWE-78
critical
9.8
2023-05-05 CVE-2023-30054 OS Command Injection vulnerability in Totolink A7100Ru Firmware 7.4Cu.2313B20191024
TOTOLINK A7100RU V7.4cu.2313_B20191024 has a Command Injection vulnerability.
network
low complexity
totolink CWE-78
critical
9.8
2023-05-05 CVE-2023-30013 OS Command Injection vulnerability in Totolink X5000R Firmware 9.1.0U.6118B20201102/9.1.0U.6369B20230113
TOTOLINK X5000R V9.1.0u.6118_B20201102 and V9.1.0u.6369_B20230113 contain a command insertion vulnerability in setting/setTracerouteCfg.
network
low complexity
totolink CWE-78
critical
9.8
2023-05-03 CVE-2023-27999 OS Command Injection vulnerability in Fortinet Fortiadc 7.1.0/7.1.1/7.2.0
An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiADC 7.2.0, 7.1.0 through 7.1.1 may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments to existing commands.
local
low complexity
fortinet CWE-78
7.8