CWE-77
3,618 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
CVEs (3,618)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the city parameter at setting/delStaticDhcpRules. |
TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the province parameter at setting/delStaticDhcpRules. |
NetModule NSRW web administration interface executes an OS command constructed with unsanitized user input. A successful exploit could allow an authenticated user to execute arbitrary commands with elevated privileges. T...Show more |
1Netgear 1Wndr3700 Firmware Jun 17, 2026 Feb 15, 2023 N/A· v4 9.8 CRITICAL· v3 5.8 MEDIUM· v2 A vulnerability has been found in Netgear WNDR3700v2 1.0.1.14 and classified as critical. This vulnerability affects unknown code of the component Web Interface. The manipulation leads to command injection. The attack ca...Show more |
Microsoft Dynamics Unified Service Desk Remote Code Execution Vulnerability |
1Microsoft 13Windows 10 Windows 10 1607Windows 10 1809+10 moreJun 17, 2026 Feb 14, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Windows MSHTML Platform Remote Code Execution Vulnerability |
In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘display.page.search.patterns.sensitivity’ search parameter lets a search bypass SPL safeguards for risky commands. The vulnerability requires a higher p...Show more |
A vulnerability classified as critical has been found in EasyNAS 1.1.0. Affected is the function system of the file /backup.pl. The manipulation leads to os command injection. It is possible to launch the attack remotely...Show more |
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the webWlanIdx parameter in the setWebWlanIdx function. |
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the admuser parameter in the setPasswordCfg function. |
TOTOLINK CA300-PoE V6.2c.884 was discovered to contain a command injection vulnerability via the admpass parameter in the setPasswordCfg function. |
1Microchip 1Syncserver S650 Firmware Jun 17, 2026 Feb 13, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Microchip Technology (Microsemi) SyncServer S650 was discovered to contain a command injection vulnerability. |
Command Injection in GitHub repository thorsten/phpmyfaq prior to 3.1.11.
|
A command injection vulnerability in the firmware_update command, in the device's restricted telnet interface, allows an authenticated attacker to execute arbitrary commands as root. |
1Baicells 4Neutrino 430 Firmware Nova430e FirmwareNova430l Firmware+1 moreJun 17, 2026 Feb 11, 2023 N/A· v4 10.0 CRITICAL· v3 N/A· v2 Baicells Nova 436Q, Nova 430E, Nova 430I, and Neutrino 430 LTE TDD eNodeB devices with firmware through QRTB 2.12.7 are vulnerable to remote shell code exploitation via HTTP command injections. Commands are executed usin...Show more |
1Dell 3Evasa Provider Virtual Appliance Solutions Enabler Virtual ApplianceUnisphere For Powermax Virtual ApplianceJun 17, 2026 Feb 11, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 9.2.3.x contain a command execution vulnerability. A low privileged remote attacker could potentially exploit this vulnerability, l...Show more |
A command injection vulnerability exists in Jitsi before commit 8aa7be58522f4264078d54752aae5483bfd854b2 when launching browsers on Windows which could allow an attacker to insert an arbitrary URL which opens up the oppo...Show more |
1Contec 1Solarview Compact Firmware Jun 17, 2026 Feb 6, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restrictions through downloader.php. |
1Mediatek 2En7528 Firmware En7580 FirmwareJun 17, 2026 Feb 6, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 In Config Manager, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege from a proximal attacker with no additional execution privileges needed. User i...Show more |
1Mediatek 2En7528 Firmware En7580 FirmwareJun 17, 2026 Feb 6, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 In Config Manager, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege from a proximal attacker with no additional execution privileges needed. User i...Show more |