← Back
CWE-77

3,620 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

JSON object

Loading...

CVEs (3,620)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Pypa
1Pip
Jun 17, 2026
Oct 25, 2023
N/A· v4
3.3 LOW· v3
N/A· v2
When installing a package from a Mercurial VCS URL (ie "pip install hg+...") with pip prior to v23.3, the specified Mercurial revision could be used to inject arbitrary configuration options to the "hg clone" call (i...Show more
When installing a package from a Mercurial VCS URL (ie "pip install hg+...") with pip prior to v23.3, the specified Mercurial revision could be used to inject arbitrary configuration options to the "hg clone" call (ie "--config"). Controlling the Mercurial configuration can modify how and which repository is installed. This vulnerability does not affect users who aren't installing from Mercurial.Show less
1Totolink
1A3700r Firmware
Jun 17, 2026
Oct 25, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue in TOTOLINK A3700R v.9.1.2u.6165_20211012 allows a remote attacker to execute arbitrary code via the FileName parameter of the UploadFirmwareFile function.
1Tenda
1W18e Firmware
Jun 17, 2026
Oct 25, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Tenda W18E V16.01.0.8(1576) has a command injection vulnerability via the hostName parameter in the formSetNetCheckTools function.
1Arubanetworks
1Clearpass Policy Manager
Jun 17, 2026
Oct 25, 2023
N/A· v4
6.3 MEDIUM· v3
N/A· v2
A vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute a...Show more
A vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as a non-privileged user on the underlying operating system leading to partial system compromise.Show less
1Superwebmailer
1Superwebmailer
Jun 17, 2026
Oct 21, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
An issue was discovered in SuperWebMailer 9.00.0.01710. It allows Remote Code Execution via a crafted sendmail command line.
1Axis
1Axis Os
Jun 17, 2026
Oct 16, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
GoSecure on behalf of Genetec Inc. has found a flaw that allows for a remote code execution during the installation of ACAP applications on the Axis device. The application handling service in AXIS OS was vulnerable to c...Show more
GoSecure on behalf of Genetec Inc. has found a flaw that allows for a remote code execution during the installation of ACAP applications on the Axis device. The application handling service in AXIS OS was vulnerable to command injection allowing an attacker to run arbitrary code. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.Show less
1Totolink
1Cp300+ Firmware
Jun 17, 2026
Oct 16, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOLINK CP300+ V5.2cu.7594_B20200910 and before is vulnerable to command injection.
1Totolink
1Cp300+ Firmware
Jun 17, 2026
Oct 16, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOLINK CP300+ V5.2cu.7594_B20200910 and before is vulnerable to command injection.
1Nrhirani
1Node Qpdf
Jun 17, 2026
Oct 14, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
All versions of the package node-qpdf are vulnerable to Command Injection such that the package-exported method encrypt() fails to sanitize its parameter input, which later flows into a sensitive command execution API. A...Show more
All versions of the package node-qpdf are vulnerable to Command Injection such that the package-exported method encrypt() fails to sanitize its parameter input, which later flows into a sensitive command execution API. As a result, attackers may inject malicious commands once they can specify the input pdf file path.Show less
1Viessmann
1Vitogate 300 Firmware
Jun 17, 2026
Oct 14, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In Vitogate 300 2.1.3.0, /cgi-bin/vitogate.cgi allows an unauthenticated attacker to bypass authentication and execute arbitrary commands via shell metacharacters in the ipaddr params JSON data for the put method.
1Netis Systems
1N3mv2 Firmware
Jun 17, 2026
Oct 13, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the pin_host parameter in the WPS Settings.
1Netis Systems
1N3m Firmware
Jun 17, 2026
Oct 13, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the ddnsDomainName parameter in the Dynamic DNS settings.
1Yifanwireless
1Yf325 Firmware
Jun 17, 2026
Oct 11, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A command execution vulnerability exists in the validate.so diag_ping_start functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to command execution. An attacker can send a network re...Show more
A command execution vulnerability exists in the validate.so diag_ping_start functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to command execution. An attacker can send a network request to trigger this vulnerability.Show less
1Mi
1Xiaomi Router Ax3200 Firmware
Jun 17, 2026
Oct 11, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Xiaomi Xiaomi Router allows Command Injection.
1Mi
1Xiaomi Router Ax3200 Firmware
Jun 17, 2026
Oct 11, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Xiaomi Xiaomi Router allows Command Injection.
1Microsoft
1Azure Identity Sdk
Jun 17, 2026
Oct 10, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Azure Identity SDK Remote Code Execution Vulnerability
1Microsoft
1Azure Identity Sdk
Jun 17, 2026
Oct 10, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Azure Identity SDK Remote Code Execution Vulnerability
1Dlink
1Dap 1860 Firmware
Jun 17, 2026
Oct 10, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
A command injection in the parsing_xml_stasurvey function inside libcgifunc.so of the D-Link DAP-X1860 repeater 1.00 through 1.01b05-01 allows attackers (within range of the repeater) to run shell commands as root during...Show more
A command injection in the parsing_xml_stasurvey function inside libcgifunc.so of the D-Link DAP-X1860 repeater 1.00 through 1.01b05-01 allows attackers (within range of the repeater) to run shell commands as root during the setup process of the repeater, via a crafted SSID. Also, network names containing single quotes (in the range of the repeater) can result in a denial of service.Show less
1Dlink
1Dsl 3782 Firmware
Jun 17, 2026
Oct 10, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
An issue found in D-Link DSL-3782 v.1.03 and before allows remote authenticated users to execute arbitrary code as root via the Router IP Address fields of the network settings page.
1Easycorp
3Zentao
Zentao BizZentao Max
Jun 17, 2026
Oct 10, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
An issue in ZenTao Community Edition v.18.6 and before, ZenTao Biz v.8.6 and before, ZenTao Max v.4.7 and before allows an attacker to execute arbitrary code via a crafted script to the Office Conversion Settings functio...Show more
An issue in ZenTao Community Edition v.18.6 and before, ZenTao Biz v.8.6 and before, ZenTao Max v.4.7 and before allows an attacker to execute arbitrary code via a crafted script to the Office Conversion Settings function.Show less