← Back
CWE-77

3,620 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

JSON object

Loading...

CVEs (3,620)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Jun 17, 2026
Dec 20, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
A command injection is possible through the user interface, allowing arbitrary command execution as the root user. oMG2000 running MGOS 3.15.1 or earlier is affected.  MG90 running MGOS 4.2.1 or earlier is affected.
1Huawei
1Cv81 Wdm Firmware
Jun 17, 2026
Dec 20, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
There is a command injection vulnerability in Huawei terminal printer product. Successful exploitation could result in the highest privileges of the printer. (Vulnerability ID: HWPSIRT-2022-51773) This vulnerability has...Show more
There is a command injection vulnerability in Huawei terminal printer product. Successful exploitation could result in the highest privileges of the printer. (Vulnerability ID: HWPSIRT-2022-51773) This vulnerability has been assigned a Common Vulnerabilities and Exposures (CVE) ID: CVE-2022-32203.Show less
-
-
Jun 17, 2026
Dec 19, 2024
N/A· v4
8.0 HIGH· v3
N/A· v2
In a specific scenario a LDAP user can abuse the authentication process using injection attack in OpenText Privileged Access Manager that allows authentication bypass. This issue affects Privileged Access Manager version...Show more
In a specific scenario a LDAP user can abuse the authentication process using injection attack in OpenText Privileged Access Manager that allows authentication bypass. This issue affects Privileged Access Manager version 23.3(4.4); 24.3(4.5)Show less
1Qnap
1Qufirewall
Jun 17, 2026
Dec 19, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute arbitrary...Show more
A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute arbitrary commands. We have already fixed the vulnerability in the following versions: QuFirewall 2.3.3 ( 2023/03/27 ) and later and laterShow less
1Seacms
1Seacms
Jun 17, 2026
Dec 18, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SeaCMS <=13.0 is vulnerable to command execution in phome.php via the function Ebak_RepPathFiletext().
-
-
Jun 17, 2026
Dec 18, 2024
8.7 HIGH· v4
8.8 HIGH· v3
N/A· v2
In ThreatQuotient ThreatQ before 5.29.3, authenticated users are able to execute arbitrary commands by sending a crafted request to an API endpoint.
-
-
Jun 17, 2026
Dec 17, 2024
N/A· v4
7.3 HIGH· v3
N/A· v2
Databricks JDBC Driver 2.x before 2.6.40 could potentially allow remote code execution (RCE) by triggering a JNDI injection via a JDBC URL parameter. The vulnerability is rooted in the improper handling of the krbJAASFil...Show more
Databricks JDBC Driver 2.x before 2.6.40 could potentially allow remote code execution (RCE) by triggering a JNDI injection via a JDBC URL parameter. The vulnerability is rooted in the improper handling of the krbJAASFile parameter. An attacker could potentially exploit this vulnerability to achieve Remote Code Execution in the context of the driver by tricking a victim into using a crafted connection URL that uses the property krbJAASFile.Show less
1Beyondtrust
2Privileged Remote Access
Remote Support
Jun 17, 2026
Dec 17, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that are run as a site user.
1Logpoint
1Siem
Jun 17, 2026
Dec 16, 2024
N/A· v4
5.9 MEDIUM· v3
N/A· v2
An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while querying Search Template Dashboard. These are executed, leading to Server-Side Template Injection.
1Logpoint
1Siem
Jun 17, 2026
Dec 16, 2024
N/A· v4
7.1 HIGH· v3
N/A· v2
An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads in Report Templates. These are executed when the backup process is initiated, leading to Remote Code Execution.
1Logpoint
1Siem
Jun 17, 2026
Dec 16, 2024
N/A· v4
5.9 MEDIUM· v3
N/A· v2
An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while creating Search Template Dashboard. These are executed, leading to Server-Side Template Injection.
1Logpoint
1Universal Normalizer
Jun 17, 2026
Dec 16, 2024
N/A· v4
7.1 HIGH· v3
N/A· v2
An issue was discovered in Logpoint UniversalNormalizer before 5.7.0. Authenticated users can inject payloads while creating Universal Normalizer. These are executed, leading to Remote Code Execution.
1Cleo
3Harmony
LexicomVltrader
Jun 17, 2026
Dec 13, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default se...Show more
In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitrary Bash or PowerShell commands on the host system by leveraging the default settings of the Autorun directory.Show less
1Dell
1Thinos
Jun 17, 2026
Dec 11, 2024
N/A· v4
8.4 HIGH· v3
N/A· v2
Dell ThinOS version 2408 contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnera...Show more
Dell ThinOS version 2408 contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Command executionShow less
1Ivanti
1Cloud Services Appliance
Jun 17, 2026
Dec 10, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
Command injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
1Ivanti
2Connect Secure
Policy Secure
Jun 17, 2026
Dec 10, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
Command injection in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to achieve remote code execution. (Not appl...Show more
Command injection in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to achieve remote code execution. (Not applicable to 9.1Rx)Show less
1Oringnet
1Iap 420+ Firmware
Jun 17, 2026
Dec 10, 2024
9.3 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
SNMP objects in NET-SNMP used in ORing IAP-420 allows Command Injection. This issue affects IAP-420: through 2.01e.
1Oringnet
1Iap 420+ Firmware
Jun 17, 2026
Dec 10, 2024
8.7 HIGH· v4
8.8 HIGH· v3
N/A· v2
Missing input validation in the ORing IAP-420 web-interface allows authenticated Command Injections on OS level.This issue affects IAP-420 version 2.01e and below.
-
-
Jun 17, 2026
Dec 10, 2024
N/A· v4
7.6 HIGH· v3
N/A· v2
An injection vulnerability in Barco ClickShare CX-30/20, C-5/10, and ClickShare Bar Pro and Core models, running firmware before 2.21.1, allows physically proximate attackers or local admins to the webUI to trigger OS-le...Show more
An injection vulnerability in Barco ClickShare CX-30/20, C-5/10, and ClickShare Bar Pro and Core models, running firmware before 2.21.1, allows physically proximate attackers or local admins to the webUI to trigger OS-level command execution as root.Show less
1Datax Web Project
1Datax Web
Jun 17, 2026
Dec 9, 2024
5.3 MEDIUM· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A vulnerability was found in WeiYe-Jing datax-web 2.1.1. It has been classified as critical. This affects an unknown part of the file /api/job/add/. The manipulation of the argument glueSource leads to os command injecti...Show more
A vulnerability was found in WeiYe-Jing datax-web 2.1.1. It has been classified as critical. This affects an unknown part of the file /api/job/add/. The manipulation of the argument glueSource leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.Show less