CWE-77
3,618 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
CVEs (3,618)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Kratosdefense 1Spectralnet Narrowband Firmware Jun 17, 2026 Jun 12, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2 A remote command injection issues exists in the web server of the Kratos SpectralNet device with SpectralNet Narrowband (NB) before 1.7.5. As an admin user, an attacker can send a crafted password in order to execute Lin...Show more |
1Atos 2Unify Openscape 4000 Assistant Unify Openscape 4000 ManagerJun 17, 2026 Jun 12, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8, Assistant V10 R0, Manager V10 R1 before V10 R1.42.0 and V10 R1.34.8, and Manager V10 R0 allow command injection by authenticated users, aka O...Show more |
1Atos 2Unify Openscape 4000 Assistant Unify Openscape 4000 ManagerJun 17, 2026 Jun 12, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8, Assistant V10 R0, Manager V10 R1 before V10 R1.42.0 and V10 R1.34.8, and Manager V10 R0 allow command injection by authenticated users, aka O...Show more |
1Atos 2Unify Openscape 4000 Assistant Unify Openscape 4000 ManagerJun 17, 2026 Jun 12, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8 and Manager V10 R1 before V10 R1.42.0 and V10 R1.34.8 allow command injection by authenticated users, aka OSFOURK-23554. |
1Atos 2Unify Openscape 4000 Assistant Unify Openscape 4000 ManagerJun 17, 2026 Jun 12, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8, Assistant V10 R0, Manager V10 R1 before V10 R1.42.0 and V10 R1.34.8, and Manager V10 R0 allow command injection by authenticated users, aka O...Show more |
The Danfoss AK-EM100 web applications allow for an authenticated user to perform OS command injection through the web application parameters. |
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Versions prior to 3.0.2 are vulnerable to command injection v...Show more |
snowflake-connector-nodejs, a NodeJS driver for Snowflake, is vulnerable to command injection via single sign on (SSO) browser URL authentication in versions prior to 1.6.21. In order to exploit the potential for command...Show more |
snowflake-connector-net, the Snowflake Connector for .NET, is vulnerable to command injection prior to version 2.0.18 via SSO URL authentication. In order to exploit the potential for command injection, an attacker would...Show more |
gosnowflake is th Snowflake Golang driver. Prior to version 1.6.19, a command injection vulnerability exists in the Snowflake Golang driver via single sign-on (SSO) browser URL authentication. In order to exploit the pot...Show more |
TOTOLink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the staticGw parameter at /setting/setWanIeCfg. |
Aria Operations for Networks contains an information disclosure vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in i...Show more |
1Vmware 1Aria Operations For Networks Jun 17, 2026 Jun 7, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in remote...Show more |
1Tp Link 3Tl Wr740n Firmware Tl Wr841n FirmwareTl Wr940n FirmwareJun 17, 2026 Jun 7, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerability via the component /userRpm/WlanNetworkRpm . |
D-Link DIR-842V2 v1.0.3 was discovered to contain a command injection vulnerability via the iperf3 diagnostics function. |
An issue was discovered in Anyka Microelectronics AK3918EV300 MCU v18. A command injection vulnerability in the network configuration script within the MCU's operating system allows attackers to perform arbitrary command...Show more |
In Percona XtraBackup (PXB) through 2.2.24 and 3.x through 8.0.27-19, a crafted filename on the local file system could trigger unexpected command shell execution of arbitrary commands. |
The `Release PR Merged` workflow in the github repo taosdata/grafanaplugin is subject to a command injection vulnerability which allows for arbitrary code execution within the github action context due to the insecure us...Show more |
1Netgear 4D6220 Firmware D8500 FirmwareR6700 Firmware+1 moreJun 17, 2026 Jun 6, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Netgear D6220 with Firmware Version 1.0.0.80, D8500 with Firmware Version 1.0.3.60, R6700 with Firmware Version 1.0.2.26, and R6900 with Firmware Version 1.0.2.26 are vulnerable to Command Injection. If an attacker gains...Show more |
There is a command injection vulnerability in the Netgear R6250 router with Firmware Version 1.0.4.48. If an attacker gains web management privileges, they can inject commands into the post request parameters, thereby ga...Show more |