← Back
CWE-77

3,617 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

JSON object

Loading...

CVEs (3,617)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Brokenlamp
1Slock
Jun 17, 2026
Aug 8, 2021
N/A· v4
8.1 HIGH· v3
5.1 MEDIUM· v2
An issue was discovered in the slock crate through 2020-11-17 for Rust. Slock<T> unconditionally implements Send and Sync.
1Rcu Cell Project
1Rcu Cell
Jun 17, 2026
Aug 8, 2021
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in the rcu_cell crate through 2020-11-14 for Rust. There are unconditional implementations of Send and Sync for RcuCell<T>.
1Bunch Project
1Bunch
Jun 17, 2026
Aug 8, 2021
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in the bunch crate through 2020-11-12 for Rust. There are unconditional implementations of Send and Sync for Bunch<T>.
1Kekbit Project
1Kekbit
Jun 17, 2026
Aug 8, 2021
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in the kekbit crate before 0.3.4 for Rust. For ShmWriter<H>, Send is implemented without requiring H: Send.
1Cache Project
1Cache
Jun 17, 2026
Aug 8, 2021
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in the cache crate through 2020-11-24 for Rust. There are unconditional implementations of Send and Sync for Cache<K>.
3Debian
DigintFedoraproject
3Btrbk
Debian LinuxFedora
Jun 17, 2026
Aug 7, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Btrbk before 0.31.2 allows command execution because of the mishandling of remote hosts filtering SSH commands using ssh_filter_btrbk.sh in authorized_keys.
1Roxy Wi
1Roxy Wi
Jun 17, 2026
Aug 7, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Roxy-WI through 5.2.2.0 allows command injection via /app/funct.py and /api/api_funct.py.
1Prolink
1Prc2402m Firmware
Jun 17, 2026
Aug 6, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In ProLink PRC2402M V1.0.18 and older, the set_ledonoff function in the adm.cgi binary, accessible with a page parameter value of ledonoff contains a trivial command injection where the value of the led_cmd parameter is...Show more
In ProLink PRC2402M V1.0.18 and older, the set_ledonoff function in the adm.cgi binary, accessible with a page parameter value of ledonoff contains a trivial command injection where the value of the led_cmd parameter is passed directly to do_system.Show less
1Combodo
1Itop
Jun 17, 2026
Jul 21, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Combodo iTop is an open source, web based IT Service Management tool. In versions prior to 2.7.4, there is a command injection vulnerability in the Setup Wizard when providing Graphviz executable path. The vulnerability...Show more
Combodo iTop is an open source, web based IT Service Management tool. In versions prior to 2.7.4, there is a command injection vulnerability in the Setup Wizard when providing Graphviz executable path. The vulnerability is patched in version 2.7.4 and 3.0.0.Show less
1Github
1Enterprise Server
Jun 17, 2026
Jul 14, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A path traversal vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled configuration options used by GitHub Pages were not sufficiently restri...Show more
A path traversal vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled configuration options used by GitHub Pages were not sufficiently restricted and made it possible to read files on the GitHub Enterprise Server instance. To exploit this vulnerability, an attacker would need permission to create and build a GitHub Pages site on the GitHub Enterprise Server instance. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.1.3 and was fixed in 3.1.3, 3.0.11, and 2.22.17. This vulnerability was reported via the GitHub Bug Bounty program.Show less
1Qsan
2Sanos
Xevo
Jun 17, 2026
Jul 7, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Command injection vulnerability in QSAN XEVO, SANOS allows remote unauthenticated attackers to execute arbitrary commands. Suggest contacting with QSAN and refer to recommendations in QSAN Document.
3Debian
DovecotFedoraproject
3Debian Linux
DovecotFedora
Jun 17, 2026
Jun 28, 2021
N/A· v4
4.8 MEDIUM· v3
5.8 MEDIUM· v2
The submission service in Dovecot before 2.3.15 allows STARTTLS command injection in lib-smtp. Sensitive information can be redirected to an attacker-controlled address.
1Evernote
1Evernote
Jun 17, 2026
Jun 24, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was found in the Evernote client for Windows 10, 7, and 2008 in the protocol handler. This enables attackers for arbitrary command execution if the user clicks on a specially crafted URL. AKA: WINNOTE-19941.
1Ibos
1Ibos
Jun 17, 2026
Jun 24, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In IBOS 4.5.4 Open, the database backup has Command Injection Vulnerability.
1Synology
1Download Station
Jun 17, 2026
Jun 18, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Improper neutralization of special elements used in a command ('Command Injection') vulnerability in task management component in Synology Download Station before 3.8.16-3566 allows remote authenticated users to execute...Show more
Improper neutralization of special elements used in a command ('Command Injection') vulnerability in task management component in Synology Download Station before 3.8.16-3566 allows remote authenticated users to execute arbitrary code via unspecified vectors.Show less
1Roonlabs
1Roon Server
Jun 17, 2026
Jun 8, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. Roon Labs has already fixed this vulnerability in the following versions: Roon Server 2021-05-18 and later
1Sharp Nec Displays
34C431 Firmware
C501 FirmwareC551 Firmware+31 more
Jun 17, 2026
Jun 7, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Sharp NEC Displays ((UN462A R1.300 and prior to it, UN462VA R1.300 and prior to it, UN492S R1.300 and prior to it, UN492VS R1.300 and prior to it, UN552A R1.300 and prior to it, UN552S R1.300 and prior to it, UN552VS R1....Show more
Sharp NEC Displays ((UN462A R1.300 and prior to it, UN462VA R1.300 and prior to it, UN492S R1.300 and prior to it, UN492VS R1.300 and prior to it, UN552A R1.300 and prior to it, UN552S R1.300 and prior to it, UN552VS R1.300 and prior to it, UN552 R1.300 and prior to it, UN552V R1.300 and prior to it, UX552S R1.300 and prior to it, UX552 R1.300 and prior to it, V864Q R2.000 and prior to it, C861Q R2.000 and prior to it, P754Q R2.000 and prior to it, V754Q R2.000 and prior to it, C751Q R2.000 and prior to it, V984Q R2.000 and prior to it, C981Q R2.000 and prior to it, P654Q R2.000 and prior to it, V654Q R2.000 and prior to it, C651Q R2.000 and prior to it, V554Q R2.000 and prior to it, P404 R3.200 and prior to it, P484 R3.200 and prior to it, P554 R3.200 and prior to it, V404 R3.200 and prior to it, V484 R3.200 and prior to it, V554 R3.200 and prior to it, V404-T R3.200 and prior to it, V484-T R3.200 and prior to it, V554-T R3.200 and prior to it, C501 R2.000 and prior to it, C551 R2.000 and prior to it, C431 R2.000 and prior to it) allows an attacker a buffer overflow and to execute remote code by sending long parameters that contains specific characters in http request.Show less
1Linuxfoundation
1@backstage/plugin Techdocs
Jun 17, 2026
Jun 3, 2021
N/A· v4
7.3 HIGH· v3
4.9 MEDIUM· v2
Backstage is an open platform for building developer portals. In versions of Backstage's Techdocs Plugin (`@backstage/plugin-techdocs`) prior to 0.9.5, a malicious internal actor can potentially upload documentation cont...Show more
Backstage is an open platform for building developer portals. In versions of Backstage's Techdocs Plugin (`@backstage/plugin-techdocs`) prior to 0.9.5, a malicious internal actor can potentially upload documentation content with malicious scripts by embedding the script within an `object` element. This may give access to sensitive data when other users visit that same documentation page. The ability to upload malicious content may be limited by internal code review processes, unless the chosen TechDocs deployment method is to use an object store and the actor has access to upload files directly to that store. The vulnerability is patched in the `0.9.5` release of `@backstage/plugin-techdocs`.Show less
1Linuxfoundation
1@backstage/techdocs Common
Jun 17, 2026
Jun 3, 2021
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
Backstage is an open platform for building developer portals, and techdocs-common contains common functionalities for Backstage's TechDocs. In versions of `@backstage/tehdocs-common` prior to 0.6.4, a malicious internal...Show more
Backstage is an open platform for building developer portals, and techdocs-common contains common functionalities for Backstage's TechDocs. In versions of `@backstage/tehdocs-common` prior to 0.6.4, a malicious internal actor is able to upload documentation content with malicious scripts. These scripts would normally be sanitized by the TechDocs frontend, but by tricking a user to visit the content via the TechDocs API, the content sanitazion will be bypassed. If the TechDocs API is hosted on the same origin as the Backstage app or other backend plugins, this may give access to sensitive data. The ability to upload malicious content may be limited by internal code review processes, unless the chosen TechDocs deployment method is to use an object store and the actor has access to upload files directly to that store. The vulnerability is patched in the `0.6.4` release of `@backstage/techdocs-common`.Show less
1Qnap
1Video Station
Jun 17, 2026
Jun 3, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A command injection vulnerability has been reported to affect certain versions of Video Station. If exploited, this vulnerability allows remote attackers to execute arbitrary commands. This issue affects: QNAP Systems In...Show more
A command injection vulnerability has been reported to affect certain versions of Video Station. If exploited, this vulnerability allows remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Video Station versions prior to 5.5.4 on QTS 4.5.2; versions prior to 5.5.4 on QuTS hero h4.5.2; versions prior to 5.5.4 on QuTScloud c4.5.4. This issue does not affect: QNAP Systems Inc. Video Station on QTS 4.3.6; on QTS 4.3.3.Show less