← Back
CWE-77

3,620 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

JSON object

Loading...

CVEs (3,620)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Mi
1Ax9000 Firmware
Jun 17, 2026
Sep 23, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Xiaomi Router AX9000 has a post-authorization command injection vulnerability. This vulnerability is caused by the lack of validation of user input, and an attacker can exploit this vulnerability to execute arbitrary cod...Show more
Xiaomi Router AX9000 has a post-authorization command injection vulnerability. This vulnerability is caused by the lack of validation of user input, and an attacker can exploit this vulnerability to execute arbitrary code.Show less
1Dedecms
1Dedecms
Jun 17, 2026
Sep 22, 2024
5.1 MEDIUM· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
A vulnerability was found in DedeCMS up to 5.7.115. It has been rated as critical. This issue affects some unknown processing of the file /dede/article_string_mix.php. The manipulation leads to os command injection. The...Show more
A vulnerability was found in DedeCMS up to 5.7.115. It has been rated as critical. This issue affects some unknown processing of the file /dede/article_string_mix.php. The manipulation leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Millbeck
1Proroute H685t W Firmware
Jun 17, 2026
Sep 17, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
There is a command injection vulnerability that may allow an attacker to inject malicious input on the device's operating system.
1Ui
1Unifi Network Application
Jun 17, 2026
Sep 13, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
A Command Injection vulnerability found in a Self-Hosted UniFi Network Servers (Linux) with UniFi Network Application (Version 8.3.32 and earlier) allows a malicious actor with unifi user shell access to escalate privile...Show more
A Command Injection vulnerability found in a Self-Hosted UniFi Network Servers (Linux) with UniFi Network Application (Version 8.3.32 and earlier) allows a malicious actor with unifi user shell access to escalate privileges to root on the host device.Show less
1Tenda
1Fh451 Firmware
Jun 17, 2026
Sep 13, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Tenda FH451 v1.0.0.9 has a command injection vulnerability in the formexeCommand function i
1Gitlab
1Gitlab
Jun 17, 2026
Sep 12, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
An issue has been discovered in GitLab EE affecting all versions starting from 16.11 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. Due to incomplete input filtering, it was possible to inject...Show more
An issue has been discovered in GitLab EE affecting all versions starting from 16.11 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. Due to incomplete input filtering, it was possible to inject commands into a connected Cube server.Show less
1Rockwellautomation
1Factorytalk View
Jun 17, 2026
Sep 12, 2024
9.2 CRITICAL· v4
9.8 CRITICAL· v3
N/A· v2
CVE-2024-45824 IMPACT A remote code vulnerability exists in the affected products. The vulnerability occurs when chained with Path Traversal, Command Injection, and XSS Vulnerabilities and allows for full unauthentica...Show more
CVE-2024-45824 IMPACT A remote code vulnerability exists in the affected products. The vulnerability occurs when chained with Path Traversal, Command Injection, and XSS Vulnerabilities and allows for full unauthenticated remote code execution. The link in the mitigations section below contains patches to fix this issue.Show less
1Relyum
1Rely Pcie Firmware
Jul 5, 2026
Sep 11, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the time_date function.
1Relyum
1Rely Pcie Firmware
Jul 5, 2026
Sep 11, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the sys_conf function.
1Relyum
1Rely Pcie Firmware
Jul 5, 2026
Sep 11, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the sys_mgmt function.
1Relyum
1Rely Pcie Firmware
Jul 5, 2026
Sep 11, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a code injection vulnerability via the getParams function in phpinf.php.
1Comfast
1Cf Xr11 Firmware
Jun 17, 2026
Sep 11, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
COMFAST CF-XR11 V2.7.2 has a command injection vulnerability in function sub_424CB4. Attackers can send POST request messages to /usr/bin/webmgnt and inject commands into parameter iface.
1Microsoft
1Sharepoint Server
Jun 17, 2026
Sep 10, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
Microsoft SharePoint Server Remote Code Execution Vulnerability
1Microsoft
1Sharepoint Server
Jun 17, 2026
Sep 10, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
Microsoft SharePoint Server Remote Code Execution Vulnerability
1Tenda
1Ac15 Firmware
Jun 17, 2026
Sep 10, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Command Injection vulnerability in goform/SetIPTVCfg interface of Tenda AC15 V15.03.05.20 allows remote attackers to run arbitrary commands via crafted POST request.
1Fortinet
1Forticlient Enterprise Management Server
Jun 17, 2026
Sep 10, 2024
N/A· v4
7.3 HIGH· v3
N/A· v2
An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in Fortinet FortiClientEMS 7.2.0 through 7.2.4, 7.0.0 through 7.0.12 may allow an unauthenticated attacker to...Show more
An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in Fortinet FortiClientEMS 7.2.0 through 7.2.4, 7.0.0 through 7.0.12 may allow an unauthenticated attacker to execute limited and temporary operations on the underlying database via crafted requests.Show less
1Dell
1Wyse Thinos
Jun 17, 2026
Sep 10, 2024
N/A· v4
7.6 HIGH· v3
N/A· v2
Dell ThinOS versions 2402 and 2405, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with physical access could potentially exploi...Show more
Dell ThinOS versions 2402 and 2405, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Elevation of privileges.Show less
1Dlink
1Di 8300 Firmware
Jun 17, 2026
Sep 9, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the upgrade_filter_asp function.
-
-
Jun 17, 2026
Sep 9, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
D-Link DI-7003G v19.12.24A1, DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.04.18D1 are vulnerable to Remote Command Executio...Show more
D-Link DI-7003G v19.12.24A1, DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.04.18D1 are vulnerable to Remote Command Execution (RCE) via version_upgrade.asp.Show less
-
-
Jun 17, 2026
Sep 9, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
D-Link DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.04.18D1 are vulnerable to Remote Command Execution due to insufficient...Show more
D-Link DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.04.18D1 are vulnerable to Remote Command Execution due to insufficient parameter filtering in the CGI handling function of upgrade_filter.asp.Show less