Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2023-04-27 CVE-2023-28384 OS Command Injection vulnerability in Myscada Mypro
mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands.
network
low complexity
myscada CWE-78
8.8
2023-04-27 CVE-2023-28400 OS Command Injection vulnerability in Myscada Mypro
mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands.
network
low complexity
myscada CWE-78
8.8
2023-04-27 CVE-2023-28716 OS Command Injection vulnerability in Myscada Mypro
mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands.
network
low complexity
myscada CWE-78
8.8
2023-04-27 CVE-2023-29150 OS Command Injection vulnerability in Myscada Mypro
mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands.
network
low complexity
myscada CWE-78
8.8
2023-04-27 CVE-2023-29169 OS Command Injection vulnerability in Myscada Mypro
mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands.
network
low complexity
myscada CWE-78
8.8
2023-04-25 CVE-2023-25313 OS Command Injection vulnerability in Wwbn Avideo
OS injection vulnerability in World Wide Broadcast Network AVideo version before 12.4, allows attackers to execute arbitrary code via the video link field to the Embed a video link feature.
network
low complexity
wwbn CWE-78
critical
9.8
2023-04-25 CVE-2023-28771 OS Command Injection vulnerability in Zyxel products
Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG FLEX series firmware versions 4.60 through 5.35, and ATP series firmware versions 4.60 through 5.35, which could allow an unauthenticated attacker to execute some OS commands remotely by sending crafted packets to an affected device.
network
low complexity
zyxel CWE-78
critical
9.8
2023-04-24 CVE-2023-30628 OS Command Injection vulnerability in Kiwitcms Kiwi Tcms
Kiwi TCMS is an open source test management system.
network
low complexity
kiwitcms CWE-78
8.8
2023-04-24 CVE-2023-27991 OS Command Injection vulnerability in Zyxel products
The post-authentication command injection vulnerability in the CLI command of Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, USG20(W)-VPN firmware versions 4.16 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow an authenticated attacker to execute some OS commands remotely.
network
low complexity
zyxel CWE-78
8.8
2023-04-22 CVE-2023-25507 OS Command Injection vulnerability in Nvidia BMC
NVIDIA DGX-1 BMC contains a vulnerability in the SPX REST API, where an attacker with the appropriate level of authorization can inject arbitrary shell commands, which may lead to code execution, denial of service, information disclosure, and data tampering.
network
low complexity
nvidia CWE-78
8.8