Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2024-10-01 CVE-2024-47608 OS Command Injection vulnerability in Definetlynotai Logicytics
Logicytics is designed to harvest and collect data for forensic analysis.
network
low complexity
definetlynotai CWE-78
critical
9.8
2024-09-28 CVE-2024-23924 OS Command Injection vulnerability in Alpsalpine Ilx-F509 Firmware 6.0.000
Alpine Halo9 UPDM_wemCmdCreatSHA256Hash Command Injection Remote Code Execution Vulnerability.
low complexity
alpsalpine CWE-78
6.8
2024-09-28 CVE-2024-23961 OS Command Injection vulnerability in Alpsalpine Ilx-F509 Firmware 6.0.000
Alpine Halo9 UPDM_wemCmdUpdFSpeDecomp Command Injection Remote Code Execution Vulnerability.
low complexity
alpsalpine CWE-78
6.8
2024-09-26 CVE-2024-46628 OS Command Injection vulnerability in Tendacn G3 Firmware 15.03.05.05
Tenda G3 Router firmware v15.03.05.05 was discovered to contain a remote code execution (RCE) vulnerability via the usbPartitionName parameter in the formSetUSBPartitionUmount function.
network
low complexity
tendacn CWE-78
critical
9.8
2024-09-19 CVE-2024-9004 OS Command Injection vulnerability in Dlink Dar-7000 Firmware
A vulnerability classified as critical has been found in D-Link DAR-7000 up to 20240912.
network
low complexity
dlink CWE-78
critical
9.8
2024-09-19 CVE-2024-9001 OS Command Injection vulnerability in Totolink T10 Firmware 4.1.8Cu.5207
A vulnerability was found in TOTOLINK T10 4.1.8cu.5207.
network
low complexity
totolink CWE-78
8.8
2024-09-17 CVE-2024-8957 OS Command Injection vulnerability in Ptzoptics Pt30X-Ndi-Xx-G2 Firmware and Pt30X-Sdi Firmware
PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an OS command injection issue.
network
low complexity
ptzoptics CWE-78
critical
9.8
2024-09-17 CVE-2024-45682 OS Command Injection vulnerability in Millbeck Proroute H685T-W Firmware 3.2.334
There is a command injection vulnerability that may allow an attacker to inject malicious input on the device's operating system.
network
low complexity
millbeck CWE-78
critical
9.8
2024-09-15 CVE-2024-8869 OS Command Injection vulnerability in Totolink A720R Firmware 4.1.5
A vulnerability classified as critical has been found in TOTOLINK A720R 4.1.5.
network
high complexity
totolink CWE-78
8.1
2024-09-11 CVE-2024-20398 OS Command Injection vulnerability in Cisco IOS XR
A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to obtain read/write file system access on the underlying operating system of an affected device. This vulnerability is due to insufficient validation of user arguments that are passed to specific CLI commands.
local
low complexity
cisco CWE-78
7.8