Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2023-05-18 CVE-2023-20164 OS Command Injection vulnerability in Cisco Identity Services Engine
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform command injection attacks on the underlying operating system and elevate privileges to root.
network
low complexity
cisco CWE-78
7.2
2023-05-17 CVE-2023-24805 OS Command Injection vulnerability in multiple products
cups-filters contains backends, filters, and other software required to get the cups printing service working on operating systems other than macos.
network
low complexity
linuxfoundation fedoraproject debian CWE-78
8.8
2023-05-15 CVE-2023-1698 OS Command Injection vulnerability in Wago products
In multiple products of WAGO a vulnerability allows an unauthenticated, remote attacker to create new users and change the device configuration which can result in unintended behaviour, Denial of Service and full system compromise.
network
low complexity
wago CWE-78
critical
9.8
2023-05-12 CVE-2020-13378 OS Command Injection vulnerability in Loadbalancer Enterprise VA MAX 8.3.3/8.3.8
Loadbalancer.org Enterprise VA MAX through 8.3.8 has an OS Command Injection vulnerability that allows a remote authenticated attacker to execute arbitrary code.
network
low complexity
loadbalancer CWE-78
8.8
2023-05-10 CVE-2022-29841 OS Command Injection vulnerability in Westerndigital MY Cloud OS
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that was caused by a command that read files from a privileged location and created a system command without sanitizing the read data.
network
low complexity
westerndigital CWE-78
critical
9.8
2023-05-10 CVE-2023-32568 OS Command Injection vulnerability in Veritas Infoscale Operations Manager
An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2.800 and 8.x before 8.0.410.
network
low complexity
veritas CWE-78
7.2
2023-05-09 CVE-2023-27407 OS Command Injection vulnerability in Siemens Scalance Lpe9403 Firmware 2.0
A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1).
network
low complexity
siemens CWE-78
critical
9.9
2023-05-07 CVE-2023-2564 OS Command Injection vulnerability in Scanservjs Project Scanservjs
OS Command Injection in GitHub repository sbs20/scanservjs prior to v2.27.0.
network
low complexity
scanservjs-project CWE-78
critical
10.0
2023-05-05 CVE-2023-30053 OS Command Injection vulnerability in Totolink A7100Ru Firmware 7.4Cu.2313B20191024
TOTOLINK A7100RU V7.4cu.2313_B20191024 is vulnerable to Command Injection.
network
low complexity
totolink CWE-78
critical
9.8
2023-05-05 CVE-2023-30054 OS Command Injection vulnerability in Totolink A7100Ru Firmware 7.4Cu.2313B20191024
TOTOLINK A7100RU V7.4cu.2313_B20191024 has a Command Injection vulnerability.
network
low complexity
totolink CWE-78
critical
9.8