← Back
CWE-77

3,617 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

JSON object

Loading...

CVEs (3,617)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Hestiacp
1Control Panel
Jun 17, 2026
Apr 28, 2022
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Command Injection Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.12. An authenticated remote attacker with low privileges can execute arbitrary code under root context.
1Bender
2Cc612 Firmware
Icc15xx Firmware
Jun 17, 2026
Apr 27, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In Bender/ebee Charge Controllers in multiple versions are prone to Command injection via Web interface. An authenticated attacker could enter shell commands into some input fields.
1Microsoft
5Windows 10
Windows 11Windows Server 2016+2 more
Jun 17, 2026
Apr 15, 2022
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
Windows DNS Server Remote Code Execution Vulnerability
1Thoughtworks
1Gocd
Jun 17, 2026
Apr 14, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker with privileges to create a new pipeline on a GoCD server can abuse a command-line injection in the Git URL "Test Connection" feature to execute arb...Show more
An issue was discovered in ThoughtWorks GoCD before 21.3.0. An attacker with privileges to create a new pipeline on a GoCD server can abuse a command-line injection in the Git URL "Test Connection" feature to execute arbitrary code.Show less
3Fedoraproject
NetappPython
5Active Iq Unified Manager
FedoraOntap Select Deploy Administration Utility+2 more
Nov 3, 2025
Apr 13, 2022
N/A· v4
7.6 HIGH· v3
8.0 HIGH· v2
In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call m...Show more
In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7, 3.8, 3.9Show less
1Citrix
1Xenmobile Server
Jun 17, 2026
Apr 13, 2022
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
Citrix XenMobile Server 10.12 through RP11, 10.13 through RP7, and 10.14 through RP4 allows Command Injection.
1Citrix
1Xenmobile Server
Jun 17, 2026
Apr 13, 2022
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
In Citrix XenMobile Server through 10.12 RP9, there is an Authenticated Command Injection vulnerability, leading to remote code execution with root privileges.
1Myscada
1Mypro
Jun 17, 2026
Apr 11, 2022
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
An authenticated user may be able to misuse parameters to inject arbitrary operating system commands into mySCADA myPRO versions 8.25.0 and prior.
1Dlink
1Dir 823g Firmware
Jun 17, 2026
Apr 7, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An Access Control vulnerability exists in D-Link DIR-823G REVA1 1.02B05 (Lastest) via any parameter in the HNAP1 function
1Cisco
1Staros
Jun 17, 2026
Apr 6, 2022
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
A vulnerability in the CLI of Cisco StarOS could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to insufficient input validation of CLI commands. An attacker...Show more
A vulnerability in the CLI of Cisco StarOS could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to insufficient input validation of CLI commands. An attacker could exploit this vulnerability by sending crafted commands to the CLI. A successful exploit could allow the attacker to execute arbitrary code with the privileges of the root user. To exploit this vulnerability, an attacker would need to have valid administrative credentials on an affected device.Show less
1Auvesy Mdt
2Autosave
Autosave For System Platform
Jun 17, 2026
Apr 1, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An attacker could leverage an API to pass along a malicious file that could then manipulate the process creation command line in MDT AutoSave versions prior to v6.02.06 and run a command line argument. This could then be...Show more
An attacker could leverage an API to pass along a malicious file that could then manipulate the process creation command line in MDT AutoSave versions prior to v6.02.06 and run a command line argument. This could then be leveraged to run a malicious process.Show less
1Oppo
1Quick App
Jun 17, 2026
Apr 1, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A command injection vulerability found in quick game engine allows arbitrary remote code in quick app. Allows remote attacke0rs to gain arbitrary code execution in quick game engine
1Totolink
1Ex300 V2 Firmware
Jun 17, 2026
Mar 31, 2022
N/A· v4
7.5 HIGH· v3
7.9 HIGH· v2
totolink EX300_v2 V4.0.3c.140_B20210429 was discovered to contain a command injection vulnerability via the component cloudupdate_check.
1Totolink
1Ex300 V2 Firmware
Jun 17, 2026
Mar 30, 2022
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
totolink EX300_v2 V4.0.3c.140_B20210429 was discovered to contain a command injection vulnerability via the component process forceugpo.
1Profelis
1Sambabox
Jun 17, 2026
Mar 30, 2022
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in ping tool of Profelis IT Consultancy SambaBox allows AUTHENTICATED user to cause run arbitrary code. This issue affects...Show more
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in ping tool of Profelis IT Consultancy SambaBox allows AUTHENTICATED user to cause run arbitrary code. This issue affects: Profelis IT Consultancy SambaBox 4.0 version 4.0 and prior versions on x86.Show less
1Draytek
3Vigor2960 Firmware
Vigor300b FirmwareVigor3900 Firmware
Jun 17, 2026
Mar 29, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A Remote Command Injection vulnerability exists in DrayTek Vigor 2960 1.5.1.3, DrayTek Vigor 3900 1.5.1.3, and DrayTek Vigor 300B 1.5.1.3 via a crafted HTTP message containing malformed QUERY STRING in mainfunction.cgi,...Show more
A Remote Command Injection vulnerability exists in DrayTek Vigor 2960 1.5.1.3, DrayTek Vigor 3900 1.5.1.3, and DrayTek Vigor 300B 1.5.1.3 via a crafted HTTP message containing malformed QUERY STRING in mainfunction.cgi, which could let a remote malicious user execute arbitrary code.Show less
1Synology
1Diskstation Manager
Jun 17, 2026
Mar 25, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Improper neutralization of special elements used in a command ('Command Injection') vulnerability in File service functionality in Synology DiskStation Manager (DSM) before 6.2.4-25556-2 allows remote authenticated users...Show more
Improper neutralization of special elements used in a command ('Command Injection') vulnerability in File service functionality in Synology DiskStation Manager (DSM) before 6.2.4-25556-2 allows remote authenticated users to execute arbitrary commands via unspecified vectors.Show less
1Tenda
1M3 Firmware
Jun 17, 2026
Mar 24, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /cgi-bin/uploadAccessCodePic.
1Tenda
1M3 Firmware
Jun 17, 2026
Mar 24, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/SetInternetLanInfo.
1Tenda
1M3 Firmware
Jun 17, 2026
Mar 24, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Tenda M3 1.10 V1.0.0.12(4856) was discovered to contain a command injection vulnerability via the component /goform/SetLanInfo.