CWE-77
3,618 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
CVEs (3,618)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
SolarWinds Platform was susceptible to Command Injection. This vulnerability allows a remote adversary with complete control over the SolarWinds database to execute arbitrary commands. |
The web server of Hirschmann BAT-C2 before 09.13.01.00R04 allows authenticated command injection. This allows an authenticated attacker to pass commands to the shell of the system because the dir parameter of the FsCreat...Show more |
Alarm instance management has command injection when there is a specific command configured. It is only for logged-in users. We recommend you upgrade to version 2.0.6 or higher |
1Zohocorp 3Manageengine Servicedesk Plus Manageengine Servicedesk Plus MspManageengine Supportcenter PlusJun 17, 2026 Nov 23, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to authenticated command injection. This can be exploited by high-privileged users. |
1Optilinknetwork 1Op Xt71000n Firmware Jun 17, 2026 Nov 23, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Unauthenticated remote code execution in OPTILINK OP-XT71000N, Hardware Version: V2.2 occurs when the attacker passes arbitrary commands with IP-ADDRESS using " | " to execute commands on " /diag_tracert_admin.asp " in t...Show more |
1Optilinknetwork 1Op Xt71000n Firmware Jun 17, 2026 Nov 23, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 OPTILINK OP-XT71000N V2.2 is vulnerable to Remote Code Execution. The issue occurs when the attacker sends an arbitrary code on "/diag_ping_admin.asp" to "PingTest" interface that leads to COMMAND EXECUTION. An attacker...Show more |
A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker with internal network access to conduct a command-injection attack, due to insuffic...Show more |
IBM i Access Family 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.0 could allow a local authenticated attacker to execute arbitrary code on the system, caused by DLL search order hijacking vulnerability. By placing a spe...Show more |
1Zohocorp 1Manageengine Admanager Plus Jun 17, 2026 Nov 18, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Zoho ManageEngine ADManager Plus through 7151 allows authenticated admin users to execute the commands in proxy settings. |
DLINK - DSL-224 Post-auth RCE. DLINK router version 3.0.8 has an interface where you can configure NTP servers (Network Time Protocol) via jsonrpc API. It is possible to inject a command through this interface that will...Show more |
1Contec 1Solarview Compact Firmware Jun 17, 2026 Nov 17, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 SolarView Compact 6.00 was discovered to contain a command injection vulnerability via network_test.php |
There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control their username can exploit this issue to execute arbitrary code on the sy...Show more |
1Ibm 2Infosphere Information Server Infosphere Information Server On CloudJun 17, 2026 Nov 16, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 IBM InfoSphere DataStage 11.7 is vulnerable to a command injection vulnerability due to improper neutralization of special elements. IBM X-Force ID: 236687. |
1Cisco 2Firepower Extensible Operating System Firepower Threat DefenseJun 17, 2026 Nov 15, 2022 N/A· v4 6.7 MEDIUM· v3 N/A· v2 A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software and Cisco FXOS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system as root....Show more |
1Cisco 1Secure Firewall Management Center Jun 17, 2026 Nov 15, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 A vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. T...Show more |
1Cisco 1Secure Firewall Management Center Jun 17, 2026 Nov 15, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 A vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. T...Show more |
2Fedoraproject Invisible Island2Fedora XtermJun 17, 2026 Nov 10, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 xterm before 375 allows code execution via font ops, e.g., because an OSC 50 response may have Ctrl-g and therefore lead to command execution within the vi line-editing mode of Zsh. NOTE: font ops are not allowed in the...Show more |
D-Link DIR-823G v1.0.2 was found to contain a command injection vulnerability in the function SetNetworkTomographySettings. This vulnerability allows attackers to execute arbitrary commands via a crafted packet. |
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in OpenNebula OpenNebula core on Linux allows Remote Code Inclusion. |
IP-COM EW9 V15.11.0.14(9732) was discovered to contain a command injection vulnerability in the formSetDebugCfg function. |