← Back
CWE-77

3,617 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

JSON object

Loading...

CVEs (3,617)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Debian
Freedesktop
2Debian Linux
Xdg Utils
Nov 21, 2024
Jun 2, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The open_generic_xdg_mime function in xdg-open in xdg-utils 1.1.0 rc1 in Debian, when using dash, does not properly handle local variables, which allows remote attackers to execute arbitrary commands via a crafted file.
12ndquadrant
1Pglogical
Jun 17, 2026
Jun 1, 2021
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
A shell injection flaw was found in pglogical in versions before 2.3.4 and before 3.6.26. An attacker with CREATEDB privileges on a PostgreSQL server can craft a database name that allows execution of shell commands as t...Show more
A shell injection flaw was found in pglogical in versions before 2.3.4 and before 3.6.26. An attacker with CREATEDB privileges on a PostgreSQL server can craft a database name that allows execution of shell commands as the postgresql user when calling pglogical.create_subscription().Show less
1Sangoma
1Restapps
Jun 17, 2026
May 31, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The restapps (aka Rest Phone apps) module for Sangoma FreePBX and PBXact 13, 14, and 15 through 15.0.19.2 allows remote code execution via a URL variable to an AMI command.
4Debian
GaleraclusterMariadb+1 more
4Debian Linux
Galera Cluster For MysqlMariadb+1 more
Jun 17, 2026
May 27, 2021
N/A· v4
9.0 CRITICAL· v3
6.8 MEDIUM· v2
A flaw was found in the mysql-wsrep component of mariadb. Lack of input sanitization in `wsrep_sst_method` allows for command injection that can be exploited by a remote attacker to execute arbitrary commands on galera c...Show more
A flaw was found in the mysql-wsrep component of mariadb. Lack of input sanitization in `wsrep_sst_method` allows for command injection that can be exploited by a remote attacker to execute arbitrary commands on galera cluster nodes. This threatens the system's confidentiality, integrity, and availability. This flaw affects mariadb versions before 10.1.47, before 10.2.34, before 10.3.25, before 10.4.15 and before 10.5.6.Show less
1Ivanti
1Connect Secure
Jun 17, 2026
May 27, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A command injection vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to perform remote code execution via Windows Resource Profiles Feature
1Versa Networks
1Versa Director
Jun 17, 2026
May 26, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
In Versa Director, the command injection is an attack in which the goal is execution of arbitrary commands on the host operating system via a vulnerable application. Command injection attacks are possible when an applica...Show more
In Versa Director, the command injection is an attack in which the goal is execution of arbitrary commands on the host operating system via a vulnerable application. Command injection attacks are possible when an application passes unsafe user supplied data (forms, cookies, HTTP headers etc.) to a system shell. In this attack, the attacker-supplied operating system commands are usually executed with the privileges of the vulnerable application. Command injection attacks are possible largely due to insufficient input validation.Show less
1Nagios
1Fusion
Jun 17, 2026
May 24, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Command Injection in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to nagios.
1Nagios
1Fusion
Jun 17, 2026
May 24, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Command Injection in Nagios Fusion 4.1.8 and earlier allows Privilege Escalation from apache to root in cmd_subsys.php.
1Nagios
1Fusion
Jun 17, 2026
May 24, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Command Injection in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation or Code Execution as root via vectors related to corrupt component installation in cmd_subsys.php.
1Cisco
1Dna Spaces\
Jun 17, 2026
May 22, 2021
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
Multiple vulnerabilities in Cisco DNA Spaces Connector could allow an authenticated, remote attacker to perform a command injection attack on an affected device. These vulnerabilities are due to insufficient input saniti...Show more
Multiple vulnerabilities in Cisco DNA Spaces Connector could allow an authenticated, remote attacker to perform a command injection attack on an affected device. These vulnerabilities are due to insufficient input sanitization when executing affected commands. A high-privileged attacker could exploit these vulnerabilities on a Cisco DNA Spaces Connector by injecting crafted input during command execution. A successful exploit could allow the attacker to execute arbitrary commands as root within the Connector docker container.Show less
1Cisco
6Wap125 Firmware
Wap131 FirmwareWap150 Firmware+3 more
Jun 17, 2026
May 22, 2021
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could allow an authenticated, remote attacker to perform command injection at...Show more
Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could allow an authenticated, remote attacker to perform command injection attacks against an affected device. These vulnerabilities are due to improper validation of user-supplied input. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to the web-based management interface of an affected system. A successful exploit could allow the attacker to execute arbitrary commands with root privileges on the device. To exploit these vulnerabilities, the attacker must have valid administrative credentials for the device.Show less
1Cisco
6Wap125 Firmware
Wap131 FirmwareWap150 Firmware+3 more
Jun 17, 2026
May 22, 2021
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could allow an authenticated, remote attacker to perform command injection at...Show more
Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could allow an authenticated, remote attacker to perform command injection attacks against an affected device. These vulnerabilities are due to improper validation of user-supplied input. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to the web-based management interface of an affected system. A successful exploit could allow the attacker to execute arbitrary commands with root privileges on the device. To exploit these vulnerabilities, the attacker must have valid administrative credentials for the device.Show less
1Cisco
6Wap125 Firmware
Wap131 FirmwareWap150 Firmware+3 more
Jun 17, 2026
May 22, 2021
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could allow an authenticated, remote attacker to perform command injection at...Show more
Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could allow an authenticated, remote attacker to perform command injection attacks against an affected device. These vulnerabilities are due to improper validation of user-supplied input. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to the web-based management interface of an affected system. A successful exploit could allow the attacker to execute arbitrary commands with root privileges on the device. To exploit these vulnerabilities, the attacker must have valid administrative credentials for the device.Show less
1Cisco
6Wap125 Firmware
Wap131 FirmwareWap150 Firmware+3 more
Jun 17, 2026
May 22, 2021
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could allow an authenticated, remote attacker to perform command injection at...Show more
Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could allow an authenticated, remote attacker to perform command injection attacks against an affected device. These vulnerabilities are due to improper validation of user-supplied input. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to the web-based management interface of an affected system. A successful exploit could allow the attacker to execute arbitrary commands with root privileges on the device. To exploit these vulnerabilities, the attacker must have valid administrative credentials for the device.Show less
1Cisco
6Wap125 Firmware
Wap131 FirmwareWap150 Firmware+3 more
Jun 17, 2026
May 22, 2021
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could allow an authenticated, remote attacker to perform command injection at...Show more
Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could allow an authenticated, remote attacker to perform command injection attacks against an affected device. These vulnerabilities are due to improper validation of user-supplied input. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to the web-based management interface of an affected system. A successful exploit could allow the attacker to execute arbitrary commands with root privileges on the device. To exploit these vulnerabilities, the attacker must have valid administrative credentials for the device.Show less
1Cisco
6Wap125 Firmware
Wap131 FirmwareWap150 Firmware+3 more
Jun 17, 2026
May 22, 2021
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could allow an authenticated, remote attacker to perform command injection at...Show more
Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could allow an authenticated, remote attacker to perform command injection attacks against an affected device. These vulnerabilities are due to improper validation of user-supplied input. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to the web-based management interface of an affected system. A successful exploit could allow the attacker to execute arbitrary commands with root privileges on the device. To exploit these vulnerabilities, the attacker must have valid administrative credentials for the device.Show less
1Cisco
6Wap125 Firmware
Wap131 FirmwareWap150 Firmware+3 more
Jun 17, 2026
May 22, 2021
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could allow an authenticated, remote attacker to perform command injection at...Show more
Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could allow an authenticated, remote attacker to perform command injection attacks against an affected device. These vulnerabilities are due to improper validation of user-supplied input. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to the web-based management interface of an affected system. A successful exploit could allow the attacker to execute arbitrary commands with root privileges on the device. To exploit these vulnerabilities, the attacker must have valid administrative credentials for the device.Show less
1Cisco
6Wap125 Firmware
Wap131 FirmwareWap150 Firmware+3 more
Jun 17, 2026
May 22, 2021
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could allow an authenticated, remote attacker to perform command injection at...Show more
Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could allow an authenticated, remote attacker to perform command injection attacks against an affected device. These vulnerabilities are due to improper validation of user-supplied input. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to the web-based management interface of an affected system. A successful exploit could allow the attacker to execute arbitrary commands with root privileges on the device. To exploit these vulnerabilities, the attacker must have valid administrative credentials for the device.Show less
1Cisco
6Wap125 Firmware
Wap131 FirmwareWap150 Firmware+3 more
Jun 17, 2026
May 22, 2021
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could allow an authenticated, remote attacker to perform command injection at...Show more
Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series Wireless Access Points could allow an authenticated, remote attacker to perform command injection attacks against an affected device. These vulnerabilities are due to improper validation of user-supplied input. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to the web-based management interface of an affected system. A successful exploit could allow the attacker to execute arbitrary commands with root privileges on the device. To exploit these vulnerabilities, the attacker must have valid administrative credentials for the device.Show less
1Pluck Cms
1Pluck
Jun 17, 2026
May 18, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In Pluck-4.7.10-dev2 admin background, a remote command execution vulnerability exists when uploading files.