CWE-77
3,620 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
CVEs (3,620)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A vulnerability was found in JFinalCMS 1.0. It has been rated as critical. Affected by this issue is the function update of the file \src\main\java\com\cms\controller\admin\TemplateController.java of the component Templa...Show more |
1Qnap 1Hybrid Backup Sync Jun 17, 2026 Dec 6, 2024 9.5 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 An OS command injection vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If exploited, the vulnerability could allow remote attackers to execute commands. We have already fixed the vulnerability in th...Show more |
1Arubanetworks 1Clearpass Policy Manager Jun 17, 2026 Dec 3, 2024 N/A· v4 6.3 MEDIUM· v3 N/A· v2 A vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploit could allow an attacker to execute arb...Show more |
1Arubanetworks 1Clearpass Policy Manager Jun 17, 2026 Dec 3, 2024 N/A· v4 8.0 HIGH· v3 N/A· v2 An authenticated RCE vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation could allow an...Show more |
1Arubanetworks 1Clearpass Policy Manager Jun 17, 2026 Dec 3, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could allow an authenticated remote threat actor to conduct a remote code execution attack. Successful exploitation coul...Show more |
An issue in Beijing Digital China Yunke Information Technology Co.Ltd v.7.2.6.120 allows a remote attacker to execute arbitrary code via the code/function/dpi/web_auth/customizable.php file |
An issue in Razer Synapse 3 v.3.9.131.20813 and Synapse 3 App v.20240213 allows a local attacker to execute arbitrary code via the export parameter of the Chroma Effects function in the Profiles component. |
Command Injection vulnerability in NEC Corporation UNIVERGE IX from Ver9.2 to Ver10.10.21, for Ver10.8 up to Ver10.8.27, for Ver10.9 up to Ver10.9.14 and UNIVERGE IX-R/IX-V Ver1.2.15 and earlier allows a attacker to inje...Show more |
1Vmware 2Aria Operations Cloud FoundationJun 17, 2026 Nov 26, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative privileges can insert malicious commands into the properties file to escalate privileges to a root...Show more |
1Engeniustech 3Enh1350ext Firmware Ens500 Ac FirmwareEns620ext FirmwareJun 17, 2026 Nov 25, 2024 5.1 MEDIUM· v4 7.2 HIGH· v3 5.8 MEDIUM· v2 A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/network/diag_iperf. The manipul...Show more |
1Engeniustech 3Enh1350ext Firmware Ens500 Ac FirmwareEns620ext FirmwareJun 17, 2026 Nov 25, 2024 5.1 MEDIUM· v4 7.2 HIGH· v3 5.8 MEDIUM· v2 A vulnerability has been found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/network/ajax_getChan...Show more |
1Engeniustech 3Enh1350ext Firmware Ens500 Ac FirmwareEns620ext FirmwareJun 17, 2026 Nov 25, 2024 5.1 MEDIUM· v4 7.2 HIGH· v3 5.8 MEDIUM· v2 A vulnerability, which was classified as critical, was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. Affected is an unknown function of the file /admin/network/diag_nslookup. The manipulation of t...Show more |
1Engeniustech 3Enh1350ext Firmware Ens500 Ac FirmwareEns620ext FirmwareJun 17, 2026 Nov 25, 2024 5.1 MEDIUM· v4 7.2 HIGH· v3 5.8 MEDIUM· v2 A vulnerability, which was classified as critical, has been found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. This issue affects some unknown processing of the file /admin/network/diag_ping6. The mani...Show more |
1Engeniustech 3Enh1350ext Firmware Ens500 Ac FirmwareEns620ext FirmwareJun 17, 2026 Nov 25, 2024 5.1 MEDIUM· v4 7.2 HIGH· v3 5.8 MEDIUM· v2 A vulnerability classified as critical was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. This vulnerability affects unknown code of the file /admin/network/diag_pinginterface. The manipulation of...Show more |
1Engeniustech 3Enh1350ext Firmware Ens500 Ac FirmwareEns620ext FirmwareJun 17, 2026 Nov 25, 2024 5.1 MEDIUM· v4 7.2 HIGH· v3 5.8 MEDIUM· v2 A vulnerability classified as critical has been found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. This affects an unknown part of the file /admin/network/diag_traceroute6. The manipulation of the argu...Show more |
1Engeniustech 3Enh1350ext Firmware Ens500 Ac FirmwareEns620ext FirmwareJun 17, 2026 Nov 25, 2024 5.1 MEDIUM· v4 7.2 HIGH· v3 5.8 MEDIUM· v2 A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/network/diag_traceroute. Th...Show more |
1Engeniustech 3Enh1350ext Firmware Ens500 Ac FirmwareEns620ext FirmwareJun 17, 2026 Nov 25, 2024 5.1 MEDIUM· v4 7.2 HIGH· v3 5.8 MEDIUM· v2 A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/sn_package/sn_http...Show more |
1Engeniustech 3Enh1350ext Firmware Ens500 Ac FirmwareEns620ext FirmwareJun 17, 2026 Nov 25, 2024 5.1 MEDIUM· v4 7.2 HIGH· v3 5.8 MEDIUM· v2 A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. It has been classified as critical. Affected is an unknown function of the file /admin/network/wifi_schedule. The manipulation of...Show more |
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in hardy-barth cph2_echarge_firmware allows OS Command Injection.This issue affects cph2_echarge_firmware: through 2.0.4. |
virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287. |