← Back
CWE-77

3,618 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

JSON object

Loading...

CVEs (3,618)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Escanav
1Escan Anti Virus
Jun 17, 2026
Jan 29, 2025
9.2 CRITICAL· v4
8.1 HIGH· v3
7.6 HIGH· v2
A vulnerability was found in MicroWorld eScan Antivirus 7.0.32 on Linux. It has been rated as critical. This issue affects some unknown processing of the file rtscanner of the component Quarantine Handler. The manipulati...Show more
A vulnerability was found in MicroWorld eScan Antivirus 7.0.32 on Linux. It has been rated as critical. This issue affects some unknown processing of the file rtscanner of the component Quarantine Handler. The manipulation leads to os command injection. The attack may be initiated remotely. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Apple
4Ipados
Iphone OsMacos+1 more
Jun 17, 2026
Jan 27, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
A privacy issue was addressed with improved handling of files. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 18.3, macOS Sequoia 15.3. Copying a URL from Web Inspector may lead to command injection.
-
-
Jun 17, 2026
Jan 27, 2025
10.0 CRITICAL· v4
10.0 CRITICAL· v3
N/A· v2
Network access can be used to execute arbitrary code with elevated privileges. This issue affects FLXEON 9.3.4 and older.
1Edimax
1Br 6476ac Firmware
Jul 5, 2026
Jan 27, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 suffers from Command Injection issues in /bin/goahead. Specifically, these issues can be triggered through /goform/tracerouteDiagnosis, /goform/pingDiagnosis, and /go...Show more
Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 suffers from Command Injection issues in /bin/goahead. Specifically, these issues can be triggered through /goform/tracerouteDiagnosis, /goform/pingDiagnosis, and /goform/fromSysToolPingCmd Each of these issues allows an attacker with access to the web interface to inject and execute arbitrary shell commands, with "root" privileges.Show less
1Trendnet
1Tew 632brp Firmware
Jun 17, 2026
Jan 27, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TRENDnet TEW-632BRP v1.010B31 devices have an OS command injection vulnerability in the CGl interface "ntp_sync.cgi",which allows remote attackers to execute arbitrary commands via parameter "ntp_server" passed to the "n...Show more
TRENDnet TEW-632BRP v1.010B31 devices have an OS command injection vulnerability in the CGl interface "ntp_sync.cgi",which allows remote attackers to execute arbitrary commands via parameter "ntp_server" passed to the "ntp_sync.cgi" binary through a POST request.Show less
1Ecovacs
12Deebot T30 Omni Firmware
Deebot T30s FirmwareDeebot X2 Combo Firmware+9 more
Jun 17, 2026
Jan 23, 2025
5.8 MEDIUM· v4
9.6 CRITICAL· v3
N/A· v2
ECOVACS robot lawnmowers and vacuums are vulnerable to command injection via SetNetPin() over an unauthenticated BLE connection.
1Apache
1Ambari
Jun 17, 2026
Jan 21, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
A code injection vulnerability exists in the Ambari Alert Definition feature, allowing authenticated users to inject and execute arbitrary shell commands. The vulnerability arises when defining alert scripts, where th...Show more
A code injection vulnerability exists in the Ambari Alert Definition feature, allowing authenticated users to inject and execute arbitrary shell commands. The vulnerability arises when defining alert scripts, where the script filename field is executed using `sh -c`. An attacker with authenticated access can exploit this vulnerability to inject malicious commands, leading to remote code execution on the server. The issue has been fixed in the latest versions of Ambari.Show less
1Linksys
1E8450 Firmware
Jun 17, 2026
Jan 21, 2025
N/A· v4
8.2 HIGH· v3
N/A· v2
Linksys E8450 v1.2.00.360516 was discovered to contain a command injection vulnerability via userEmail.
1Linksys
1E8450 Firmware
Jun 17, 2026
Jan 21, 2025
N/A· v4
8.0 HIGH· v3
N/A· v2
Linksys E8450 v1.2.00.360516 was discovered to contain a command injection vulnerability via wizard_status.
1Eng
1Spagobi
Jun 17, 2026
Jan 21, 2025
N/A· v4
9.1 CRITICAL· v3
N/A· v2
The script input feature of SpagoBI 3.5.1 allows arbitrary code execution.
1Totolink
1A810r Firmware
Jun 17, 2026
Jan 21, 2025
N/A· v4
8.1 HIGH· v3
N/A· v2
TOTOLINK A810R V4.1.2cu.5032_B20200407 was found to contain a command insertion vulnerability in downloadFile.cgi main function. This vulnerability allows an attacker to execute arbitrary commands by sending HTTP request...Show more
TOTOLINK A810R V4.1.2cu.5032_B20200407 was found to contain a command insertion vulnerability in downloadFile.cgi main function. This vulnerability allows an attacker to execute arbitrary commands by sending HTTP request.Show less
1Ibm
1Sterling Secure Proxy
Jun 17, 2026
Jan 19, 2025
N/A· v4
9.1 CRITICAL· v3
N/A· v2
IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow a privileged user to inject commands into the underlying operating system due to improper validation of a specified type of i...Show more
IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow a privileged user to inject commands into the underlying operating system due to improper validation of a specified type of input.Show less
-
-
Jun 17, 2026
Jan 17, 2025
2.0 LOW· v4
3.5 LOW· v3
N/A· v2
Multiple bash files were present in the application's private directory. Bash files can be used on their own, by an attacker that has already full access to the mobile platform to compromise the translations for the a...Show more
Multiple bash files were present in the application's private directory. Bash files can be used on their own, by an attacker that has already full access to the mobile platform to compromise the translations for the application.Show less
1Tenda
3Ac10 Firmware
Ac18 FirmwareAc8 Firmware
Jun 17, 2026
Jan 17, 2025
8.6 HIGH· v4
7.2 HIGH· v3
8.3 HIGH· v2
A vulnerability, which was classified as critical, has been found in Tenda AC8, AC10 and AC18 16.03.10.20. Affected by this issue is some unknown functionality of the file /goform/telnet of the component HTTP Request Han...Show more
A vulnerability, which was classified as critical, has been found in Tenda AC8, AC10 and AC18 16.03.10.20. Affected by this issue is some unknown functionality of the file /goform/telnet of the component HTTP Request Handler. The manipulation leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.Show less
-
-
Jun 17, 2026
Jan 16, 2025
N/A· v4
8.7 HIGH· v3
N/A· v2
A JNDI injection issue was discovered in Cloudera JDBC Connector for Hive before 2.6.26 and JDBC Connector for Impala before 2.6.35. Attackers can inject malicious parameters into the JDBC URL, triggering JNDI injection...Show more
A JNDI injection issue was discovered in Cloudera JDBC Connector for Hive before 2.6.26 and JDBC Connector for Impala before 2.6.35. Attackers can inject malicious parameters into the JDBC URL, triggering JNDI injection during the process when the JDBC Driver uses this URL to connect to the database. This could lead to remote code execution. JNDI injection is possible via the JDBC connection property krbJAASFile for the Java Authentication and Authorization Service (JAAS). Using untrusted parameters in the krbJAASFile and/or remote host can trigger JNDI injection in the JDBC URL through the krbJAASFile.Show less
1Tenda
1Ac18 Firmware
Jun 17, 2026
Jan 16, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Tenda AC18 V15.03.05.19 was discovered to contain a command injection vulnerability via the usbName parameter in the formSetSambaConf function.
1Edimax
1Re11s Firmware
Jul 5, 2026
Jan 16, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
RE11S v1.11 was discovered to contain a command injection vulnerability via the component /goform/formAccept.
-
-
Jun 17, 2026
Jan 14, 2025
N/A· v4
7.2 HIGH· v3
N/A· v2
Authenticated command injection vulnerability in the command line interface of a network management service. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands as a privil...Show more
Authenticated command injection vulnerability in the command line interface of a network management service. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system.Show less
1Wavlink
1Wl Wn533a8 Firmware
Jun 17, 2026
Jan 14, 2025
N/A· v4
7.2 HIGH· v3
N/A· v2
Multiple OS command injection vulnerabilities exist in the adm.cgi sch_reboot() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to a arbitrary code execution. An attacker can...Show more
Multiple OS command injection vulnerabilities exist in the adm.cgi sch_reboot() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to a arbitrary code execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A command injection vulnerability exists in the `restart_week` POST parameter.Show less
1Wavlink
1Wl Wn533a8 Firmware
Jun 17, 2026
Jan 14, 2025
N/A· v4
7.2 HIGH· v3
N/A· v2
Multiple OS command injection vulnerabilities exist in the adm.cgi sch_reboot() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to a arbitrary code execution. An attacker can...Show more
Multiple OS command injection vulnerabilities exist in the adm.cgi sch_reboot() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to a arbitrary code execution. An attacker can make an authenticated HTTP request to trigger these vulnerabilities.A command injection vulnerability exists in the `restart_min` POST parameter.Show less