← Back
CWE-77

3,618 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

JSON object

Loading...

CVEs (3,618)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Solarwinds
1Orion Platform
Jun 17, 2026
Nov 29, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
SolarWinds Platform was susceptible to Command Injection. This vulnerability allows a remote adversary with complete control over the SolarWinds database to execute arbitrary commands.
1Belden
1Hirschmann Bat C2 Firmware
Jun 17, 2026
Nov 25, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
The web server of Hirschmann BAT-C2 before 09.13.01.00R04 allows authenticated command injection. This allows an authenticated attacker to pass commands to the shell of the system because the dir parameter of the FsCreat...Show more
The web server of Hirschmann BAT-C2 before 09.13.01.00R04 allows authenticated command injection. This allows an authenticated attacker to pass commands to the shell of the system because the dir parameter of the FsCreateDir Ajax function is not sufficiently sanitized. The vendor's ID is BSECV-2022-21.Show less
1Apache
1Dolphinscheduler
Jun 17, 2026
Nov 23, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Alarm instance management has command injection when there is a specific command configured. It is only for logged-in users. We recommend you upgrade to version 2.0.6 or higher
1Zohocorp
3Manageengine Servicedesk Plus
Manageengine Servicedesk Plus MspManageengine Supportcenter Plus
Jun 17, 2026
Nov 23, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to authenticated command injection. This can be exploited by high-privileged users.
1Optilinknetwork
1Op Xt71000n Firmware
Jun 17, 2026
Nov 23, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Unauthenticated remote code execution in OPTILINK OP-XT71000N, Hardware Version: V2.2 occurs when the attacker passes arbitrary commands with IP-ADDRESS using " | " to execute commands on " /diag_tracert_admin.asp " in t...Show more
Unauthenticated remote code execution in OPTILINK OP-XT71000N, Hardware Version: V2.2 occurs when the attacker passes arbitrary commands with IP-ADDRESS using " | " to execute commands on " /diag_tracert_admin.asp " in the "PingTest" parameter that leads to command execution.Show less
1Optilinknetwork
1Op Xt71000n Firmware
Jun 17, 2026
Nov 23, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
OPTILINK OP-XT71000N V2.2 is vulnerable to Remote Code Execution. The issue occurs when the attacker sends an arbitrary code on "/diag_ping_admin.asp" to "PingTest" interface that leads to COMMAND EXECUTION. An attacker...Show more
OPTILINK OP-XT71000N V2.2 is vulnerable to Remote Code Execution. The issue occurs when the attacker sends an arbitrary code on "/diag_ping_admin.asp" to "PingTest" interface that leads to COMMAND EXECUTION. An attacker can successfully trigger the COMMAND and can compromise full system.Show less
1Mitel
1Mivoice Connect
Jun 17, 2026
Nov 22, 2022
N/A· v4
6.8 MEDIUM· v3
N/A· v2
A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker with internal network access to conduct a command-injection attack, due to insuffic...Show more
A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker with internal network access to conduct a command-injection attack, due to insufficient restriction of URL parameters.Show less
1Ibm
1I Access Client Solutions
Jun 17, 2026
Nov 21, 2022
N/A· v4
6.7 MEDIUM· v3
N/A· v2
IBM i Access Family 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.0 could allow a local authenticated attacker to execute arbitrary code on the system, caused by DLL search order hijacking vulnerability. By placing a spe...Show more
IBM i Access Family 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.0 could allow a local authenticated attacker to execute arbitrary code on the system, caused by DLL search order hijacking vulnerability. By placing a specially crafted file in a compromised folder, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 236581.Show less
1Zohocorp
1Manageengine Admanager Plus
Jun 17, 2026
Nov 18, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Zoho ManageEngine ADManager Plus through 7151 allows authenticated admin users to execute the commands in proxy settings.
1Dlink
1Dsl 224 Firmware
Jun 17, 2026
Nov 17, 2022
N/A· v4
9.9 CRITICAL· v3
N/A· v2
DLINK - DSL-224 Post-auth RCE. DLINK router version 3.0.8 has an interface where you can configure NTP servers (Network Time Protocol) via jsonrpc API. It is possible to inject a command through this interface that will...Show more
DLINK - DSL-224 Post-auth RCE. DLINK router version 3.0.8 has an interface where you can configure NTP servers (Network Time Protocol) via jsonrpc API. It is possible to inject a command through this interface that will run with ROOT permissions on the router. Show less
1Contec
1Solarview Compact Firmware
Jun 17, 2026
Nov 17, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SolarView Compact 6.00 was discovered to contain a command injection vulnerability via network_test.php
1Atlassian
1Bitbucket
Jun 17, 2026
Nov 17, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control their username can exploit this issue to execute arbitrary code on the sy...Show more
There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control their username can exploit this issue to execute arbitrary code on the system. This vulnerability can be unauthenticated if the Bitbucket Server and Data Center instance has enabled “Allow public signup”.Show less
1Ibm
2Infosphere Information Server
Infosphere Information Server On Cloud
Jun 17, 2026
Nov 16, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
IBM InfoSphere DataStage 11.7 is vulnerable to a command injection vulnerability due to improper neutralization of special elements. IBM X-Force ID:  236687.
1Cisco
2Firepower Extensible Operating System
Firepower Threat Defense
Jun 17, 2026
Nov 15, 2022
N/A· v4
6.7 MEDIUM· v3
N/A· v2
A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software and Cisco FXOS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system as root....Show more
A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software and Cisco FXOS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system as root. This vulnerability is due to improper input validation for specific CLI commands. An attacker could exploit this vulnerability by injecting operating system commands into a legitimate command. A successful exploit could allow the attacker to escape the restricted command prompt and execute arbitrary commands on the underlying operating system. To successfully exploit this vulnerability, an attacker would need valid Administrator credentials.Show less
1Cisco
1Secure Firewall Management Center
Jun 17, 2026
Nov 15, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
A vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. T...Show more
A vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. The vulnerability is due to insufficient validation of user-supplied parameters for certain API endpoints. An attacker could exploit this vulnerability by sending crafted input to an affected API endpoint. A successful exploit could allow an attacker to execute arbitrary commands on the device with low system privileges. To successfully exploit this vulnerability, an attacker would need valid credentials for a user with Device permissions: by default, only Administrators, Security Approvers and Network Admins user accounts have these permissions.Show less
1Cisco
1Secure Firewall Management Center
Jun 17, 2026
Nov 15, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
A vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. T...Show more
A vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. The vulnerability is due to insufficient validation of user-supplied parameters for certain API endpoints. An attacker could exploit this vulnerability by sending crafted input to an affected API endpoint. A successful exploit could allow an attacker to execute arbitrary commands on the device with low system privileges. To successfully exploit this vulnerability, an attacker would need valid credentials for a user with Device permissions: by default, only Administrators, Security Approvers and Network Admins user accounts have these permissions.Show less
2Fedoraproject
Invisible Island
2Fedora
Xterm
Jun 17, 2026
Nov 10, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
xterm before 375 allows code execution via font ops, e.g., because an OSC 50 response may have Ctrl-g and therefore lead to command execution within the vi line-editing mode of Zsh. NOTE: font ops are not allowed in the...Show more
xterm before 375 allows code execution via font ops, e.g., because an OSC 50 response may have Ctrl-g and therefore lead to command execution within the vi line-editing mode of Zsh. NOTE: font ops are not allowed in the xterm default configurations of some Linux distributions.Show less
1Dlink
1Dir 823g Firmware
Jun 17, 2026
Nov 3, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
D-Link DIR-823G v1.0.2 was found to contain a command injection vulnerability in the function SetNetworkTomographySettings. This vulnerability allows attackers to execute arbitrary commands via a crafted packet.
1Opennebula
1Opennebula
Jun 17, 2026
Oct 28, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in OpenNebula OpenNebula core on Linux allows Remote Code Inclusion.
1Ip Com
1Ew9 Firmware
Jun 17, 2026
Oct 27, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
IP-COM EW9 V15.11.0.14(9732) was discovered to contain a command injection vulnerability in the formSetDebugCfg function.