CWE-77
3,620 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
CVEs (3,620)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on th...Show more |
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on th...Show more |
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on th...Show more |
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on th...Show more |
An issue in TRENDnet TEW-822DRE v.1.03B02 allows a local attacker to execute arbitrary code via the parameters ipv4_ping in the /boafrm/formSystemCheck. |
1Arubanetworks 1Clearpass Policy Manager Jun 17, 2026 Feb 27, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute ar...Show more |
1Arubanetworks 1Clearpass Policy Manager Jun 17, 2026 Feb 27, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute ar...Show more |
1Arubanetworks 1Clearpass Policy Manager Jun 17, 2026 Feb 27, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute ar...Show more |
1Arubanetworks 1Clearpass Policy Manager Jun 17, 2026 Feb 27, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute ar...Show more |
1Arubanetworks 1Clearpass Policy Manager Jun 17, 2026 Feb 27, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute ar...Show more |
An issue was discovered in Linksys Router E1700 version 1.0.04 (build 3), allows authenticated attackers to execute arbitrary code via the setDateTime function. |
3Debian FedoraprojectFontforge3Debian Linux FedoraFontforgeJun 17, 2026 Feb 26, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files. |
3Debian FedoraprojectFontforge3Debian Linux FedoraFontforgeJun 17, 2026 Feb 26, 2024 N/A· v4 4.2 MEDIUM· v3 N/A· v2 Splinefont in FontForge through 20230101 allows command injection via crafted filenames. |
In Indo-Sol PROFINET-INspektor NT through 2.4.0, a command injection vulnerability in the gedtupdater service of the firmware allows remote attackers to execute arbitrary system commands with root privileges via a crafte...Show more |
A vulnerability was found in Totolink X6000R AX3000 9.4.0cu.852_20230719. It has been rated as critical. This issue affects the function setWizardCfg of the file /cgi-bin/cstecgi.cgi of the component shttpd. The manipula...Show more |
Netis WF2780 v2.1.40144 was discovered to contain a command injection vulnerability via the wps_ap_ssid5g parameter |
Command Injection vulnerability in D-Link Dir 816 with firmware version DIR-816_A2_v1.10CNB04 allows attackers to run arbitrary commands via the urlAdd parameter. |
Command Injection vulnerability in D-Link Dir 882 with firmware version DIR882A1_FW130B06 allows attackers to run arbitrary commands via crafted POST request to /HNAP1/. |
Pymatgen (Python Materials Genomics) is an open-source Python library for materials analysis. A critical security vulnerability exists in the `JonesFaithfulTransformation.from_transformation_str()` method within the `pym...Show more |
An issue in idocv v.14.1.3_20231228 allows a remote attacker to execute arbitrary code and obtain sensitive information via a crafted script. |