CWE-77
3,617 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
CVEs (3,617)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
NETGEAR XR1000 devices before 1.0.0.58 are affected by command injection by an unauthenticated attacker. |
NETGEAR XR1000 devices before 1.0.0.58 are affected by command injection by an unauthenticated attacker. |
2Fedoraproject Redhat8Enterprise Linux Enterprise Linux EusEnterprise Linux Server Aus+5 moreJun 17, 2026 Dec 23, 2021 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This flaw allows an attacker to trick the root user into running a specially c...Show more |
1Node Windows Project 1Node Windows Jun 17, 2026 Dec 22, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 lib/cmd.js in the node-windows package before 1.0.0-beta.6 for Node.js allows command injection via the PID parameter. |
Mesa Labs AmegaView Versions 3.0 and prior has a command injection vulnerability that can be exploited to execute commands in the web server. |
Mesa Labs AmegaView version 3.0 is vulnerable to a command injection, which may allow an attacker to remotely execute arbitrary code. |
2Debian Itextpdf2Debian Linux ItextJun 17, 2026 Dec 15, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 iTextPDF in iText 7 and up to (excluding 4.4.13.3) 7.1.17 allows command injection via a CompareTool filename that is mishandled on the gs (aka Ghostscript) command line in GhostscriptHelper.java. |
1Digi 9Transport Dr64 Firmware Transport Sr44 FirmwareTransport Vc74 Firmware+6 moreJun 17, 2026 Dec 10, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An issue was discovered in Digi TransPort DR64, SR44 VC74, and WR. The ZING protocol allows arbitrary remote command execution with SUPER privileges. This allows an attacker (with knowledge of the protocol) to execute ar...Show more |
A command Injection vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform arbitrary command execution. |
A command injection vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform arbitrary command execution. |
VINGA WR-N300U 77.102.1.4853 is affected by a command execution vulnerability in the goahead component. |
1Zohocorp 1Manageengine Network Configuration Manager Jun 17, 2026 Nov 30, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zoho ManageEngine Network Configuration Manager before 125488 is vulnerable to command injection due to improper validation in the Ping functionality. |
There is a command injection vulnerability in CMA service module of FusionCompute product when processing the default certificate file. The software constructs part of a command using external special input from users, b...Show more |
The uri-block plugin in Apache APISIX before 2.10.2 uses $request_uri without verification. The $request_uri is the full original request URI without normalization. This makes it possible to construct a URI to bypass the...Show more |
In the wazuh-slack active response script in Wazuh 4.2.x before 4.2.5, untrusted user agents are passed to a curl command line, potentially resulting in remote code execution. |
1Amd 57Epyc 7232p Firmware Epyc 7251 FirmwareEpyc 7252 Firmware+54 moreJun 17, 2026 Nov 16, 2021 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 Insufficient ID command validation in the SEV Firmware may allow a local authenticated attacker to perform a denial of service of the PSP. |
In Ericsson Network Location before 2021-07-31, it is possible for an authenticated attacker to inject commands via file_name in the export functionality. For example, a new admin user could be created. |
An issue was discovered in Nagios XI 5.8.5. In the Manage Dashlets section of the Admin panel, an administrator can upload ZIP files. A command injection (within the name of the first file in the archive) allows an attac...Show more |
1Emerson 3Wireless 1410 Gateway Firmware Wireless 1410d Gateway FirmwareWireless 1420 Gateway FirmwareJun 17, 2026 Oct 22, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The affected product is vulnerable to a parameter injection via passphrase, which enables the attacker to supply uncontrolled input. |
1Yonyou 1Ufida Product Lifecycle Management Jun 17, 2026 Oct 22, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 All versions of yongyou PLM are affected by a command injection issue. UFIDA PLM (Product Life Cycle Management) is a strategic management method. It applies a series of enterprise application systems to support the enti...Show more |