← Back
CWE-77

3,620 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

JSON object

Loading...

CVEs (3,620)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Arubanetworks
1Arubaos
Jun 17, 2026
Mar 5, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on th...Show more
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system. Show less
1Arubanetworks
1Arubaos
Jun 17, 2026
Mar 5, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on th...Show more
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system. Show less
1Arubanetworks
1Arubaos
Jun 17, 2026
Mar 5, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on th...Show more
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system. Show less
1Arubanetworks
1Arubaos
Jun 17, 2026
Mar 5, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on th...Show more
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system. Show less
1Trendnet
1Tew 822dre Firmware
Jun 17, 2026
Feb 29, 2024
N/A· v4
6.8 MEDIUM· v3
N/A· v2
An issue in TRENDnet TEW-822DRE v.1.03B02 allows a local attacker to execute arbitrary code via the parameters ipv4_ping in the /boafrm/formSystemCheck.
1Arubanetworks
1Clearpass Policy Manager
Jun 17, 2026
Feb 27, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute ar...Show more
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise. Show less
1Arubanetworks
1Clearpass Policy Manager
Jun 17, 2026
Feb 27, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute ar...Show more
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise. Show less
1Arubanetworks
1Clearpass Policy Manager
Jun 17, 2026
Feb 27, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute ar...Show more
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise. Show less
1Arubanetworks
1Clearpass Policy Manager
Jun 17, 2026
Feb 27, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute ar...Show more
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise. Show less
1Arubanetworks
1Clearpass Policy Manager
Jun 17, 2026
Feb 27, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute ar...Show more
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise. Show less
1Linksys
1E1700 Firmware
Jun 17, 2026
Feb 27, 2024
N/A· v4
8.0 HIGH· v3
N/A· v2
An issue was discovered in Linksys Router E1700 version 1.0.04 (build 3), allows authenticated attackers to execute arbitrary code via the setDateTime function.
3Debian
FedoraprojectFontforge
3Debian Linux
FedoraFontforge
Jun 17, 2026
Feb 26, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files.
3Debian
FedoraprojectFontforge
3Debian Linux
FedoraFontforge
Jun 17, 2026
Feb 26, 2024
N/A· v4
4.2 MEDIUM· v3
N/A· v2
Splinefont in FontForge through 20230101 allows command injection via crafted filenames.
1Indu Sol
1Profinet Inspektor Nt
Jun 17, 2026
Feb 26, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In Indo-Sol PROFINET-INspektor NT through 2.4.0, a command injection vulnerability in the gedtupdater service of the firmware allows remote attackers to execute arbitrary system commands with root privileges via a crafte...Show more
In Indo-Sol PROFINET-INspektor NT through 2.4.0, a command injection vulnerability in the gedtupdater service of the firmware allows remote attackers to execute arbitrary system commands with root privileges via a crafted filename parameter in POST requests to the /api/updater/ctrl/start_update endpoint.Show less
1Totolink
1X6000r Firmware
Jun 17, 2026
Feb 23, 2024
N/A· v4
9.8 CRITICAL· v3
5.8 MEDIUM· v2
A vulnerability was found in Totolink X6000R AX3000 9.4.0cu.852_20230719. It has been rated as critical. This issue affects the function setWizardCfg of the file /cgi-bin/cstecgi.cgi of the component shttpd. The manipula...Show more
A vulnerability was found in Totolink X6000R AX3000 9.4.0cu.852_20230719. It has been rated as critical. This issue affects the function setWizardCfg of the file /cgi-bin/cstecgi.cgi of the component shttpd. The manipulation leads to command injection. The exploit has been disclosed to the public and may be used. The identifier VDB-254573 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.Show less
1Netis Systems
1Wf2780 Firmware
Jun 17, 2026
Feb 22, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Netis WF2780 v2.1.40144 was discovered to contain a command injection vulnerability via the wps_ap_ssid5g parameter
1Dlink
1Dir 816 Firmware
Jun 17, 2026
Feb 21, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Command Injection vulnerability in D-Link Dir 816 with firmware version DIR-816_A2_v1.10CNB04 allows attackers to run arbitrary commands via the urlAdd parameter.
1Dlink
1Dir 882 Firmware
Jun 17, 2026
Feb 21, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Command Injection vulnerability in D-Link Dir 882 with firmware version DIR882A1_FW130B06 allows attackers to run arbitrary commands via crafted POST request to /HNAP1/.
1Materialsvirtuallab
1Pymatgen
Jun 17, 2026
Feb 21, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Pymatgen (Python Materials Genomics) is an open-source Python library for materials analysis. A critical security vulnerability exists in the `JonesFaithfulTransformation.from_transformation_str()` method within the `pym...Show more
Pymatgen (Python Materials Genomics) is an open-source Python library for materials analysis. A critical security vulnerability exists in the `JonesFaithfulTransformation.from_transformation_str()` method within the `pymatgen` library prior to version 2024.2.20. This method insecurely utilizes `eval()` for processing input, enabling execution of arbitrary code when parsing untrusted input. Version 2024.2.20 fixes this issue.Show less
1Idocv
1Idocview
Jun 17, 2026
Feb 16, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue in idocv v.14.1.3_20231228 allows a remote attacker to execute arbitrary code and obtain sensitive information via a crafted script.