Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2022-10-25 CVE-2022-32765 OS Command Injection vulnerability in Robustel R1510 Firmware 3.1.16/3.3.0
An OS command injection vulnerability exists in the sysupgrade command injection functionality of Robustel R1510 3.1.16 and 3.3.0.
network
low complexity
robustel CWE-78
critical
9.8
2022-10-25 CVE-2022-33206 OS Command Injection vulnerability in Goabode Iota All-In-One Security KIT Firmware 6.9X/6.9Z
Four OS command injection vulnerabilities exists in the web interface /action/wirelessConnect functionality of Abode Systems, Inc.
network
low complexity
goabode CWE-78
critical
9.9
2022-10-25 CVE-2022-35132 OS Command Injection vulnerability in Webmin Usermin
Usermin through 1.850 allows a remote authenticated user to execute OS commands via command injection in a filename for the GPG module.
network
low complexity
webmin CWE-78
8.8
2022-10-25 CVE-2022-39321 OS Command Injection vulnerability in Github Runner
GitHub Actions Runner is the application that runs a job from a GitHub Actions workflow.
network
low complexity
github CWE-78
critical
9.9
2022-10-25 CVE-2022-39327 OS Command Injection vulnerability in Microsoft Azure Command-Line Interface
Azure CLI is the command-line interface for Microsoft Azure.
network
low complexity
microsoft CWE-78
critical
9.8
2022-10-21 CVE-2022-34437 OS Command Injection vulnerability in Dell EMC Powerscale Onefs
Dell PowerScale OneFS, versions 8.2.2-9.3.0, contain an OS command injection vulnerability.
local
low complexity
dell CWE-78
6.7
2022-10-19 CVE-2022-43184 OS Command Injection vulnerability in Dlink Dir-878 Firmware 1.30B08
D-Link DIR878 1.30B08 Hotfix_04 was discovered to contain a command injection vulnerability via the component /bin/proc.cgi.
network
low complexity
dlink CWE-78
critical
9.8
2022-10-18 CVE-2022-33872 OS Command Injection vulnerability in Fortinet Fortitester
An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in Telnet login components of FortiTester 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an unauthenticated remote attacker to execute arbitrary command in the underlying shell.
network
low complexity
fortinet CWE-78
critical
9.8
2022-10-18 CVE-2022-33873 OS Command Injection vulnerability in Fortinet Fortitester
An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in Console login components of FortiTester 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an unauthenticated attacker to execute arbitrary command in the underlying shell.
network
low complexity
fortinet CWE-78
critical
9.8
2022-10-18 CVE-2022-33874 OS Command Injection vulnerability in Fortinet Fortitester
An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in SSH login components of FortiTester 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow an unauthenticated remote attacker to execute arbitrary command in the underlying shell.
network
low complexity
fortinet CWE-78
critical
9.8