Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2022-06-30 CVE-2022-33314 OS Command Injection vulnerability in Robustel R1510 Firmware 3.3.0
Multiple command injection vulnerabilities exist in the web_server action endpoints functionalities of Robustel R1510 3.3.0.
network
low complexity
robustel CWE-78
critical
9.8
2022-06-30 CVE-2022-33325 OS Command Injection vulnerability in Robustel R1510 Firmware 3.3.0
Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0.
network
low complexity
robustel CWE-78
critical
9.8
2022-06-30 CVE-2022-33326 OS Command Injection vulnerability in Robustel R1510 Firmware 3.3.0
Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0.
network
low complexity
robustel CWE-78
critical
9.8
2022-06-30 CVE-2022-33327 OS Command Injection vulnerability in Robustel R1510 Firmware 3.3.0
Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0.
network
low complexity
robustel CWE-78
critical
9.8
2022-06-30 CVE-2022-33328 OS Command Injection vulnerability in Robustel R1510 Firmware 3.3.0
Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0.
network
low complexity
robustel CWE-78
critical
9.8
2022-06-30 CVE-2022-33329 OS Command Injection vulnerability in Robustel R1510 Firmware 3.3.0
Multiple command injection vulnerabilities exist in the web_server ajax endpoints functionalities of Robustel R1510 3.3.0.
network
low complexity
robustel CWE-78
critical
9.8
2022-06-28 CVE-2022-31885 OS Command Injection vulnerability in Marvalglobal Marval MSM 14.19.0.12476
Marval MSM v14.19.0.12476 is vulnerable to OS Command Injection due to the insecure handling of VBScripts.
network
low complexity
marvalglobal CWE-78
critical
9.8
2022-06-27 CVE-2022-32092 OS Command Injection vulnerability in Dlink Dir-645 Firmware 1.03
D-Link DIR-645 v1.03 was discovered to contain a command injection vulnerability via the QUERY_STRING parameter at __ajax_explorer.sgi.
network
low complexity
dlink CWE-78
critical
9.8
2022-06-24 CVE-2022-31767 OS Command Injection vulnerability in IBM Cics TX 11.1
IBM CICS TX Standard and Advanced 11.1 could allow a remote attacker to execute arbitrary commands on the system by sending a specially crafted request.
network
low complexity
ibm CWE-78
critical
9.8
2022-06-23 CVE-2022-32534 OS Command Injection vulnerability in Bosch Pra-Es8P2S Firmware 1.01.05
The Bosch Ethernet switch PRA-ES8P2S with software version 1.01.05 and earlier was found to be vulnerable to command injection through its diagnostics web interface.
network
low complexity
bosch CWE-78
critical
9.8