← Back
CWE-77

3,620 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

JSON object

Loading...

CVEs (3,620)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Jun 17, 2026
Nov 22, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An LDAP injection vulnerability in the login page of Gladinet CentreStack v13.12.9934.54690 allows attackers to access sensitive data or execute arbitrary commands via a crafted payload injected into the username field.
1Qnap
1Qurouter
Jun 17, 2026
Nov 22, 2024
7.3 HIGH· v4
7.8 HIGH· v3
N/A· v2
An OS command injection vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow local network attackers to execute commands. We have already fixed the vulnerabilit...Show more
An OS command injection vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow local network attackers to execute commands. We have already fixed the vulnerability in the following versions: QuRouter 2.4.4.106 and laterShow less
1Qnap
1Qurouter
Jun 17, 2026
Nov 22, 2024
9.5 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
An OS command injection vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow remote attackers to execute commands. We have already fixed the vulnerability in th...Show more
An OS command injection vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow remote attackers to execute commands. We have already fixed the vulnerability in the following version: QuRouter 2.4.3.103 and laterShow less
1Qnap
1Notes Station 3
Jun 17, 2026
Nov 22, 2024
8.7 HIGH· v4
8.8 HIGH· v3
N/A· v2
An OS command injection vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote authenticated attackers to execute commands. We have already fixed the vulnerability...Show more
An OS command injection vulnerability has been reported to affect Notes Station 3. If exploited, the vulnerability could allow remote authenticated attackers to execute commands. We have already fixed the vulnerability in the following version: Notes Station 3 3.9.7 and laterShow less
1Microfocus
1Imanager
Jun 17, 2026
Nov 22, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Possible Command Injection in iManager GET parameter has been discovered in OpenText™ iManager 3.2.6.0000.
1Microfocus
1Imanager
Jun 17, 2026
Nov 22, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Possible Command injection Vulnerability in iManager has been discovered in OpenText™ iManager 3.2.4.0000.
1Microfocus
1Imanager
Jun 17, 2026
Nov 22, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Possible Elevation of Privilege Vulnerability in iManager has been discovered in OpenText™ iManager. This impacts all versions before 3.2.5
1Totolink
1Ex200 Firmware
Jun 17, 2026
Nov 21, 2024
N/A· v4
6.3 MEDIUM· v3
N/A· v2
TOTOLINK EX200 v4.0.3c.7646_B20201211 was found to contain a command insertion vulnerability in the setUssd function. This vulnerability allows an attacker to execute arbitrary commands via the "ussd" parameter.
1Tp Link
1Tl Ipc42c Firmware
Jun 17, 2026
Nov 21, 2024
N/A· v4
8.0 HIGH· v3
N/A· v2
TP-Link TL-IPC42C V4.0_20211227_1.0.16 is vulnerable to command injection due to the lack of malicious code verification on both the frontend and backend.
1Linksys
1E3000 Firmware
Jun 17, 2026
Nov 21, 2024
N/A· v4
8.0 HIGH· v3
N/A· v2
Linksys E3000 1.0.06.002_US is vulnerable to command injection via the diag_ping_start function.
-
-
Jun 17, 2026
Nov 21, 2024
N/A· v4
6.8 MEDIUM· v3
N/A· v2
An issue in alist-tvbox v1.7.1 allows a remote attacker to execute arbitrary code via the /atv-cli file.
1Pandorafms
1Pandora Fms
Jun 17, 2026
Nov 21, 2024
6.9 MEDIUM· v4
9.8 CRITICAL· v3
N/A· v2
Arbitrary commands execution on the server by exploiting a command injection vulnerability in the LDAP authentication mechanism. This issue affects Pandora FMS: from 700 through <=777.4
1Dlink
1Di 8200 Firmware
Jun 17, 2026
Nov 21, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
D-Link DI-8200 16.07.26A1 is vulnerable to remote command execution in the msp_info_htm function via the flag parameter and cmd parameter.
-
-
Jun 17, 2026
Nov 20, 2024
N/A· v4
9.1 CRITICAL· v3
N/A· v2
An issue in Kasda LinkSmart Router KW5515 v1.7 and before allows an authenticated remote attacker to execute arbitrary OS commands via cgi parameters.
1Dlink
1Di 8400 Firmware
Jun 17, 2026
Nov 20, 2024
N/A· v4
8.0 HIGH· v3
N/A· v2
D-LINK DI-8400 v16.07.26A1 was discovered to contain multiple remote command execution (RCE) vulnerabilities in the msp_info_htm function via the flag and cmd parameters.
-
-
Jun 17, 2026
Nov 20, 2024
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Multiple OS Command Injection vulnerabilities affecting Kasda LinkSmart Router KW6512 <= v1.3 enable an authenticated remote attacker to execute arbitrary OS commands via various cgi parameters.
1Trendmicro
1Deep Security Agent
Jun 17, 2026
Nov 19, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
A security agent manual scan command injection vulnerability in the Trend Micro Deep Security 20 Agent could allow an attacker to escalate privileges and execute arbitrary code on an affected machine. In certain circums...Show more
A security agent manual scan command injection vulnerability in the Trend Micro Deep Security 20 Agent could allow an attacker to escalate privileges and execute arbitrary code on an affected machine. In certain circumstances, attackers that have legitimate access to the domain may be able to remotely inject commands to other machines in the same domain. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability locally and must have domain user privileges to affect other machines.Show less
1Apache
1Hertzbeat
Jun 17, 2026
Nov 18, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache HertzBeat (incubating). This vulnerability can only be exploited by authorized attackers. This issue affects Ap...Show more
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache HertzBeat (incubating). This vulnerability can only be exploited by authorized attackers. This issue affects Apache HertzBeat (incubating): before 1.6.1. Users are recommended to upgrade to version 1.6.1, which fixes the issue.Show less
1Synology
2Beephotos
Photos
Jun 17, 2026
Nov 15, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Task Manager component in Synology BeePhotos before 1.0.2-10026 and 1.1.0-10053 and Synology Photos before 1.6.2...Show more
Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Task Manager component in Synology BeePhotos before 1.0.2-10026 and 1.1.0-10053 and Synology Photos before 1.6.2-0720 and 1.7.0-0795 allows remote attackers to execute arbitrary code via unspecified vectors.Show less
1Gogs
1Gogs
Jun 17, 2026
Nov 15, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A remote command execution vulnerability exists in gogs/gogs versions <=0.12.7 when deployed on a Windows server. The vulnerability arises due to improper validation of the `tree_path` parameter during file uploads. An a...Show more
A remote command execution vulnerability exists in gogs/gogs versions <=0.12.7 when deployed on a Windows server. The vulnerability arises due to improper validation of the `tree_path` parameter during file uploads. An attacker can set `tree_path=.git.` to upload a file into the .git directory, allowing them to write or rewrite the `.git/config` file. If the `core.sshCommand` is set, this can lead to remote command execution.Show less