Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2023-04-21 CVE-2023-30621 OS Command Injection vulnerability in Gipsy Project Gipsy 1.0/1.1/1.3
Gipsy is a multi-purpose discord bot which aim to be as modular and user-friendly as possible.
network
low complexity
gipsy-project CWE-78
critical
9.8
2023-04-20 CVE-2023-2131 OS Command Injection vulnerability in Inea ME RTU Firmware
Versions of INEA ME RTU firmware prior to 3.36 are vulnerable to OS command injection, which could allow an attacker to remotely execute arbitrary code.
network
low complexity
inea CWE-78
critical
9.8
2023-04-19 CVE-2023-25759 OS Command Injection vulnerability in Uniguest Tripleplay 3.4.0
OS Command Injection in TripleData Reporting Engine in Tripleplay Platform releases prior to Caveman 3.4.0 allows authenticated users to run unprivileged OS level commands via a crafted request payload.
network
low complexity
uniguest CWE-78
5.4
2023-04-18 CVE-2023-25554 OS Command Injection vulnerability in Schneider-Electric Struxureware Data Center Expert
A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that allows a local privilege escalation on the appliance when a maliciously crafted Operating System command is entered on the device. Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)
local
low complexity
schneider-electric CWE-78
7.8
2023-04-18 CVE-2023-25555 OS Command Injection vulnerability in Schneider-Electric Struxureware Data Center Expert
A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could allow a user that knows the credentials to execute unprivileged shell commands on the appliance over SSH.
network
high complexity
schneider-electric CWE-78
8.1
2023-04-18 CVE-2023-29412 OS Command Injection vulnerability in Schneider-Electric products
CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause remote code execution when manipulating internal methods through Java RMI interface.
network
low complexity
schneider-electric CWE-78
critical
9.8
2023-04-17 CVE-2023-28983 OS Command Injection vulnerability in Juniper Junos OS Evolved 21.4
An OS Command Injection vulnerability in gRPC Network Operations Interface (gNOI) server module of Juniper Networks Junos OS Evolved allows an authenticated, low privileged, network based attacker to inject shell commands and execute code.
network
low complexity
juniper CWE-78
8.8
2023-04-16 CVE-2022-38841 OS Command Injection vulnerability in Linksys E8450 Firmware 1.1.00
Linksys AX3200 1.1.00 is vulnerable to OS command injection by authenticated users via shell metacharacters to the diagnostics traceroute page.
network
low complexity
linksys CWE-78
8.8
2023-04-15 CVE-2023-2091 OS Command Injection vulnerability in Kylinos Youker-Assistant
A vulnerability classified as critical was found in KylinSoft youker-assistant on KylinOS.
local
low complexity
kylinos CWE-78
7.8
2023-04-14 CVE-2023-29804 OS Command Injection vulnerability in Iodata Wfs-Sr03K Firmware and Wfs-Sr03W Firmware
WFS-SR03 v1.0.3 was discovered to contain a command injection vulnerability via the sys_smb_pwdmod function.
network
low complexity
iodata CWE-78
8.8