CWE-77
3,617 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
CVEs (3,617)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
All versions of package git-archive are vulnerable to Command Injection via the exports function. |
The affected product is vulnerable to two instances of command injection, which may allow an attacker to remotely execute arbitrary code. |
1Abb 7Rmc 100 Lite Firmware Rmc 100 FirmwareUdc Firmware+4 moreJun 17, 2026 Jul 21, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in flow computer and remote controller pro...Show more |
Roxy-WI is a Web interface for managing HAProxy, Nginx and Keepalived servers. Prior to version 6.1.1.0, the system command can be run remotely via the subprocess_execute function without processing the inputs received f...Show more |
1Siemens 15Simatic Cp 1242 7 V2 Firmware Simatic Cp 1243 1 FirmwareSimatic Cp 1243 7 Lte Eu Firmware+12 moreJun 17, 2026 Jul 12, 2022 N/A· v4 9.8 CRITICAL· v3 9.3 HIGH· v2 A vulnerability has been identified in SIMATIC CP 1242-7 V2 (All versions < V3.3.46), SIMATIC CP 1243-1 (All versions < V3.3.46), SIMATIC CP 1243-7 LTE EU (All versions < V3.3.46), SIMATIC CP 1243-7 LTE US (All versions...Show more |
1Siemens 11Ruggedcom Rox Mx5000 Firmware Ruggedcom Rox Mx5000re FirmwareRuggedcom Rox Rx1400 Firmware+8 moreJun 17, 2026 Jul 12, 2022 N/A· v4 7.2 HIGH· v3 10.0 HIGH· v2 A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < 2.15.1), RUGGEDCOM ROX MX5000RE (All versions < 2.15.1), RUGGEDCOM ROX RX1400 (All versions < 2.15.1), RUGGEDCOM ROX RX1500 (All versions < 2.15...Show more |
1Wavlink 1Wl Wn575a3 Firmware Jun 17, 2026 Jul 7, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Wavlink WL-WN575A3 RPT75A3.V4300.201217 was discovered to contain a command injection vulnerability via the function obtw. This vulnerability allows attackers to execute arbitrary commands via a crafted POST request. |
1Totolink 1Ex300 V2 Firmware Jun 17, 2026 Jul 7, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 TOTOLINK EX300_V2 V4.0.3c.7484 was discovered to contain a command injection vulnerability via the langType parameter in the setLanguageCfg function. This vulnerability is exploitable via a crafted MQTT data packet. |
1Totolink 6A3000ru Firmware A3100r FirmwareA800r Firmware+3 moreJun 17, 2026 Jul 6, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Totolink A830R V5.9c.4729_B20191112, Totolink A3100R V4.1.2cu.5050_B20200504, Totolink A950RG V4.1.2cu.5161_B20200903, Totolink A800R V4.1.2cu.5137_B20200730, Totolink A3000RU V5.9c.5185_B20201128, Totolink A810R V4.1.2c...Show more |
1Hikvision 11Ds A71024 Firmware Ds A71048 FirmwareDs A71048r Cvs Firmware+8 moreJun 17, 2026 Jun 27, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. Due to the insufficient input validation, attacker can exploit the vulnerability to execute restricted comma...Show more |
ASUS RT-N53 3.0.0.4.376.3754 has a command injection vulnerability in the SystemCmd parameter of the apply.cgi interface. |
1Splunk 2Splunk Splunk Cloud PlatformJun 17, 2026 Jun 15, 2022 N/A· v4 8.1 HIGH· v3 4.0 MEDIUM· v2 Dashboards in Splunk Enterprise versions before 9.0 might let an attacker inject risky search commands into a form token when the token is used in a query in a cross-origin request. The result bypasses SPL safeguards for...Show more |
1Siemens 1Sinema Remote Connect Server Jun 17, 2026 Jun 14, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The affected application contains a file upload server that is vulnerable to command injection. An attacker could use this to ach...Show more |
1Ibm 1Sevone Network Performance Management Jun 17, 2026 Jun 7, 2022 N/A· v4 8.8 HIGH· v3 8.5 HIGH· v2 A vulnerability classified as critical has been found in SevOne Network Management System up to 5.7.2.22. This affects the file traceroute.php of the Traceroute Handler. The manipulation leads to privilege escalation wit...Show more |
23cx Debian2Debian Linux Phone System FirmwareJun 17, 2026 Jun 7, 2022 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 PhoneSystem Terminal in 3CX Phone System (Debian based installation) 16.0.0.1570 allows an authenticated attacker to run arbitrary commands with the phonesystem user privileges because of "<space><space> followed by <shi...Show more |
LibreNMS v22.3.0 was discovered to contain multiple command injection vulnerabilities via the service_ip, hostname, and service_param parameters. |
sharp is an application for Node.js image processing. Prior to version 0.30.5, there is a possible vulnerability in logic that is run only at `npm install` time when installing versions of `sharp` prior to the latest v0....Show more |
go-getter up to 1.5.11 and 2.0.2 allowed arbitrary host access via go-getter path traversal, symlink processing, and command injection flaws. Fixed in 1.6.1 and 2.1.0. |
A command injection security vulnerability has been identified in HPE Nimble Storage Hybrid Flash Arrays, HPE Nimble Storage All Flash Arrays and HPE Nimble Storage Secondary Flash Arrays that could allow an attacker to...Show more |
GoCD is a continuous delivery server. In GoCD versions prior to 22.1.0, it is possible for existing authenticated users who have permissions to edit or create pipeline materials or pipeline configuration repositories to...Show more |