← Back
CWE-77

3,617 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

JSON object

Loading...

CVEs (3,617)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Siemens
1Teamcenter
Jun 17, 2026
Aug 10, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.15), Teamcenter V13.0 (All versions < V13.0.0.10), Teamcenter V13.1 (All versions < V13.1.0.10), Teamcenter V13.2 (All versions < V13.2.0.9)...Show more
A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.15), Teamcenter V13.0 (All versions < V13.0.0.10), Teamcenter V13.1 (All versions < V13.1.0.10), Teamcenter V13.2 (All versions < V13.2.0.9), Teamcenter V13.3 (All versions < V13.3.0.5), Teamcenter V14.0 (All versions < V14.0.0.2). File Server Cache service in Teamcenter consist of a functionality that is vulnerable to command injection. This could potentially allow an attacker to perform remote code execution.Show less
1Dlink
1Dir 810l Firmware
Jun 17, 2026
Aug 3, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
D-Link DIR810LA1_FW102B22 was discovered to contain a command injection vulnerability via the Ping_addr function.
1Get Npm Package Version Project
1Get Npm Package Version
Jun 17, 2026
Aug 2, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The package get-npm-package-version before 1.0.7 are vulnerable to Command Injection via main function in index.js.
1Npos Tesseract Project
1Npos Tesseract
Jun 17, 2026
Aug 2, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
This affects all versions of package npos-tesseract. The injection point is located in line 55 in lib/ocr.js.
1Image Tiler Project
1Image Tiler
Jun 17, 2026
Aug 2, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
This affects the package image-tiler before 2.0.2.
1Heroku Env Project
1Heroku Env
Jun 17, 2026
Aug 2, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
This affects all versions of package heroku-env. The injection point is located in lib/get.js which is required by index.js.
1Gitblame Project
1Gitblame
Jun 17, 2026
Aug 2, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
This affects all versions of package gitblame. The injection point is located in line 15 in lib/gitblame.js.
1Node Latex Pdf Project
1Node Latex Pdf
Jun 17, 2026
Aug 2, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
This affects all versions of package node-latex-pdf.
1Curljs Project
1Curljs
Jun 17, 2026
Aug 2, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
This affects all versions of package curljs.
1Monorepo Build Project
1Monorepo Build
Jun 17, 2026
Aug 2, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
This affects all versions of package monorepo-build.
1Sonicwall
7Sws12 10fpoe Firmware
Sws12 8 FirmwareSws12 8poe Firmware+4 more
Jun 17, 2026
Jul 29, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Improper neutralization of special elements used in a user input allows an authenticated malicious user to perform remote code execution in the host system. This vulnerability impacts SonicWall Switch 1.1.1.0-2s and earl...Show more
Improper neutralization of special elements used in a user input allows an authenticated malicious user to perform remote code execution in the host system. This vulnerability impacts SonicWall Switch 1.1.1.0-2s and earlier versionsShow less
1Realtek
1Rtl819x Software Development Kit
Jun 17, 2026
Jul 28, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Realtek rtl819x-SDK before v3.6.1 allows command injection over the web interface.
1Nodepdf Project
1Nodepdf
Nov 21, 2024
Jul 28, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Input passed to the Pdf() function is shell escaped and passed to child_process.exec() during PDF rendering. However, the shell escape does not properly encode all special characters, namely, semicolon and curly braces....Show more
Input passed to the Pdf() function is shell escaped and passed to child_process.exec() during PDF rendering. However, the shell escape does not properly encode all special characters, namely, semicolon and curly braces. This can be abused to achieve command execution. This problem affects nodepdf 1.3.0.Show less
1Xopen Project
1Xopen
Jun 17, 2026
Jul 25, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
This affects all versions of package xopen. The injection point is located in line 14 in index.js in the exported function xopen(filepath)
1Ntesseract Project
1Ntesseract
Jun 17, 2026
Jul 25, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The package ntesseract before 0.2.9 are vulnerable to Command Injection via lib/tesseract.js.
1Npm Help Project
1Npm Help
Jun 17, 2026
Jul 25, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
This affects all versions of package npm-help. The injection point is located in line 13 in index.js file in export.latestVersion() function.
1Sonar Wrapper Project
1Sonar Wrapper
Jun 17, 2026
Jul 25, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
This affects all versions of package sonar-wrapper. The injection point is located in lib/sonarRunner.js.
1Deferred Exec Project
1Deferred Exec
Jun 17, 2026
Jul 25, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
This affects all versions of package deferred-exec. The injection point is located in line 42 in lib/deferred-exec.js
1Google Cloudstorage Commands Project
1Google Cloudstorage Commands
Jun 17, 2026
Jul 25, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
This affects all versions of package google-cloudstorage-commands.
1Ffmpeg Sdk Project
1Ffmpeg Sdk
Jun 17, 2026
Jul 25, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
This affects all versions of package ffmpeg-sdk. The injection point is located in line 9 in index.js.