CWE-77
3,618 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
CVEs (3,618)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Ui 2Er X Sfp Firmware Er X FirmwareJul 9, 2026 Apr 28, 2023 7.3 HIGH· v4 8.8 HIGH· v3 8.3 HIGH· v2 A vulnerability was detected in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. The impacted element is an unknown function of the component Web Management Interface. The manipulation of the argument Name results in command...Show more |
1Ui 2Er X Sfp Firmware Er X FirmwareJul 9, 2026 Apr 28, 2023 7.3 HIGH· v4 8.8 HIGH· v3 8.3 HIGH· v2 A security vulnerability has been detected in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. The affected element is an unknown function of the component Web Management Interface. The manipulation of the argument dpi leads...Show more |
1Ui 2Er X Sfp Firmware Er X FirmwareJul 9, 2026 Apr 28, 2023 7.3 HIGH· v4 8.8 HIGH· v3 8.3 HIGH· v2 A weakness has been identified in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. Impacted is an unknown function of the component Web Management Interface. Executing a manipulation of the argument src can lead to command in...Show more |
1Ui 2Er X Sfp Firmware Er X FirmwareJul 9, 2026 Apr 28, 2023 7.3 HIGH· v4 8.8 HIGH· v3 8.3 HIGH· v2 A security flaw has been discovered in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. This issue affects some unknown processing of the component Web Management Interface. Performing a manipulation of the argument ecn-down...Show more |
1Ui 1Edgemax Edgerouter Firmware Jul 9, 2026 Apr 28, 2023 7.3 HIGH· v4 8.8 HIGH· v3 8.3 HIGH· v2 A vulnerability was identified in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. This vulnerability affects unknown code of the component Web Management Interface. Such manipulation of the argument ecn-up leads to command i...Show more |
IBM Cloud Pak for Data 4.5 and 4.6 could allow a privileged user to upload malicious files of dangerous types that can be automatically processed within the product's environment. IBM X-Force ID: 232034.
|
`embano1/wip` is a GitHub Action written in Bash. Prior to version 2, the `embano1/wip` action uses the `github.event.pull_request.title` parameter in an insecure way. The title parameter is used in a run statement - re...Show more |
2Dawnsparks Node Tesseract Project Huedawn Tesseract Project2Dawnsparks Node Tesseract Huedawn TesseractJun 17, 2026 Apr 24, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 huedawn-tesseract 0.3.3 and dawnsparks-node-tesseract 0.4.0 to 0.4.1 was discovered to contain a remote code execution (RCE) vulnerability via the child_process function. |
1Rails Routes To Json Project 1Rails Routes To Json Jun 17, 2026 Apr 24, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 rails-routes-to-json v1.0.0 was discovered to contain a remote code execution (RCE) vulnerability via the child_process function. |
1Broccoli Compass Project 1Broccoli Compass Jun 17, 2026 Apr 24, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 broccoli-compass v0.2.4 was discovered to contain a remote code execution (RCE) vulnerability via the child_process function. |
1Zyxel 11Usg Flex 100 Firmware Usg Flex 100w FirmwareUsg Flex 200 Firmware+8 moreJun 17, 2026 Apr 24, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 A post-authentication command injection vulnerability in the “account_operator.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 through 5.35, and VPN series firmware versions 4.30 through 5.35, which coul...Show more |
1Vmware 2Aria Operations For Logs Cloud FoundationJun 17, 2026 Apr 20, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2 VMware Aria Operations for Logs contains a command injection vulnerability. A malicious actor with administrative privileges in VMware Aria Operations for Logs can execute arbitrary commands as root. |
WBCE CMS 1.5.3 has a command execution vulnerability via admin/languages/install.php. |
Nanoleaf Desktop App before v1.3.1 was discovered to contain a command injection vulnerability which is exploited via a crafted HTTP request. |
Amanda 3.5.1 allows privilege escalation from the regular user backup to root. The SUID binary located at /lib/amanda/rundump will execute /usr/sbin/dump as root with controlled arguments from the attacker which may lead...Show more |
An issue was discovered in GitLab Community and Enterprise Edition before 11.11.8, 12 before 12.0.6, and 12.1 before 12.1.6. Gitaly allows injection of command-line flags. This sometimes leads to privilege escalation or...Show more |
Snowflake JDBC provides a JDBC type 4 driver that supports core functionality, allowing Java program to connect to Snowflake. Users of the Snowflake JDBC driver were vulnerable to a command injection vulnerability. An at...Show more |
TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the pid parameter in the disconnectVPN function. |
TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the ip parameter in the setDiagnosisCfg function. |
TOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain multiple command injection vulnerabilities via the rtLogEnabled and rtLogServer parameters in the setSyslogCfg function. |