CWE-77
3,618 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
CVEs (3,618)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. |
In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. |
In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. |
In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. |
1Mediatek 1Linkit Software Development Kit Jun 17, 2026 Jan 3, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 In Boa, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploit...Show more |
1Mediatek 1Linkit Software Development Kit Jun 17, 2026 Jan 3, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 In Config Manager, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege with User execution privileges needed. User interaction is needed for exploitat...Show more |
A vulnerability was found in Exciting Printer and classified as critical. This issue affects some unknown processing of the file lib/printer/jobs/prepare_page.rb of the component Argument Handler. The manipulation of the...Show more |
Diagnosis Controller miss parameter validation, so user may attacked by command injection via HTTP Request. |
D-Link DIR-846 A1_FW100A43 was discovered to contain a command injection vulnerability via the auto_upgrade_hour parameter in the SetAutoUpgradeInfo function. |
D-Link DIR-846 A1_FW100A43 was discovered to contain a command injection vulnerability via the lan(0)_dhcps_staticlist parameter in the SetIpMacBindSettings function. |
Activity Watch is a free and open-source automated time tracker. Versions prior to 0.11.0 allow an attacker to execute arbitrary commands on any macOS machine with ActivityWatch running. The attacker can exploit this vul...Show more |
During the plaintext phase of the STARTTLS connection setup, protocol commands could have been injected and evaluated within the encrypted session. This vulnerability affects Thunderbird < 78.7. |
1Apache 1Apache Airflow Providers Apache Hive Jun 17, 2026 Dec 20, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow Hive Provider.This issue affects Apache Airflow Hive Provider: before 5.0.0....Show more |
1Sharp 158Bp 30c25 Firmware Bp 30c25t FirmwareBp 30c25y Firmware+155 moreJun 17, 2026 Dec 16, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Command injection vulnerability in nw_interface.html in SHARP multifunction printers (MFPs)'s Digital Full-color Multifunctional System 202 or earlier, 120 or earlier, 600 or earlier, 121 or earlier, 500 or earlier, 402...Show more |
1Vmware 1Vrealize Network Insight Jun 17, 2026 Dec 14, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 vRealize Network Insight (vRNI) contains a command injection vulnerability present in the vRNI REST API. A malicious actor with network access to the vRNI REST API can execute commands without authentication. |
D-Link DIR-3040 device with firmware 120B03 was discovered to contain a command injection vulnerability via the SetTriggerLEDBlink function. |
1Atos 2Unify Openscape 4000 Assistant Unify Openscape 4000 ManagerJun 17, 2026 Dec 13, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A command injection vulnerability has been identified in Atos Unify OpenScape 4000 Assistant and Unify OpenScape 4000 Manager (8 before R2.22.18, 10 before 0.28.13, and 10 R1 before R1.34.4) that may allow an unauthentic...Show more |
1Flir 1Flir Ax8 Firmware Jun 17, 2026 Dec 8, 2022 5.5 MEDIUM· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability has been found in Teledyne FLIR AX8 up to 1.46.16. Affected by this issue is some unknown functionality of the file palette.php of the component Web Service Handler. The manipulation of the argument palet...Show more |
1F5 11Big Ip Access Policy Manager Big Ip Advanced Firewall ManagerBig Ip Analytics+8 moreJun 17, 2026 Dec 7, 2022 N/A· v4 8.7 HIGH· v3 N/A· v2 In all versions of BIG-IP, when running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode restrictions, utilizing an undisclosed iControl REST endpoint. A succ...Show more |
1Moxa 50Uc 2101 Lx Firmware Uc 2102 Lx FirmwareUc 2104 Lx Firmware+47 moreJun 17, 2026 Dec 2, 2022 N/A· v4 7.6 HIGH· v3 N/A· v2 Cradlepoint IBR600 NCOS versions 6.5.0.160bc2e and prior are vulnerable to shell escape, which enables local attackers with non-superuser credentials to gain full, unrestrictive shell access which may allow an attacke...Show more |