CWE-77
3,617 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
CVEs (3,617)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Amd 65Epyc 7232p Epyc 7251Epyc 7252+62 moreJun 17, 2026 May 13, 2021 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 In the AMD SEV/SEV-ES feature, memory can be rearranged in the guest address space that is not detected by the attestation mechanism which could be used by a malicious hypervisor to potentially lead to arbitrary code exe...Show more |
1Amd 65Epyc 7232p Epyc 7251Epyc 7252+62 moreJun 17, 2026 May 13, 2021 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 The lack of nested page table protection in the AMD SEV/SEV-ES feature could potentially lead to arbitrary code execution within the guest VM if a malicious administrator has access to compromise the server hypervisor. |
A command injection vulnerability has been reported to affect certain versions of Malware Remover. If exploited, this vulnerability allows remote attackers to execute arbitrary commands. This issue affects: QNAP Systems...Show more |
Ticketer is a command based ticket system cog (plugin) for the red discord bot. A vulnerability allowing discord users to expose sensitive information has been found in the Ticketer cog. Please upgrade to version 1.0.1 a...Show more |
1Cisco 1Hyperflex Hx Data Platform Jun 17, 2026 May 6, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information a...Show more |
Arbitrary PHP code execution vulnerability in Drupal Core under certain circumstances. An attacker could trick an administrator into visiting a malicious site that could result in creating a carefully named directory on...Show more |
1Cisco 2Adaptive Security Appliance Software Firepower Threat DefenseJun 17, 2026 Apr 29, 2021 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 A vulnerability in the upgrade process of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to inject commands that could be e...Show more |
1Chinamobile 1An Lianbao Wf 1 Firmware Jun 17, 2026 Apr 29, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Command injection vulnerability in China Mobile An Lianbao WF-1 1.01 via the 'ip' parameter with a POST request to /api/ZRQos/set_online_client. |
Akuvox C315 115.116.2613 allows remote command Injection via the cfgd_server service. The attack vector is sending a payload to port 189 (default root 0.0.0.0). |
1Avaya 1Session Border Controller For Enterprise Jun 17, 2026 Apr 23, 2021 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A command injection vulnerability in Avaya Session Border Controller for Enterprise could allow an authenticated, remote attacker to send specially crafted messages and execute arbitrary commands with the affected system...Show more |
NFX Series devices using Juniper Networks Junos OS are susceptible to a local command execution vulnerability thereby allowing an attacker to elevate their privileges via the Junos Device Management Daemon (JDMD) process...Show more |
NFX Series devices using Juniper Networks Junos OS are susceptible to a local code execution vulnerability thereby allowing an attacker to elevate their privileges via the Junos Device Management Daemon (JDMD) process. T...Show more |
IBM Resilient SOAR V38.0 could allow a privileged user to create create malicious scripts that could be executed as another user. IBM X-Force ID: 198759. |
1Fibaro 2Home Center 2 Firmware Home Center Lite FirmwareJun 17, 2026 Apr 19, 2021 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 In Fibaro Home Center 2 and Lite devices with firmware version 4.540 and older an authenticated user can run commands as root user using a command injection vulnerability. |
A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. We have already fixed this vu...Show more |
1Openclinic Ga Project 1Openclinic Ga Jun 17, 2026 Apr 13, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An exploitable unatuhenticated command injection exists in the OpenClinic GA 5.173.3. Specially crafted web requests can cause commands to be executed on the server. An attacker can send a web request with parameters con...Show more |
4Debian FedoraprojectLinux+1 more13Cloud Backup Debian LinuxFedora+10 moreJun 17, 2026 Apr 8, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 BPF JIT compilers in the Linux kernel through 5.11.12 have incorrect computation of branch displacements, allowing them to execute arbitrary code within the kernel context. This affects arch/x86/net/bpf_jit_comp.c and ar...Show more |
1Grandstream 7Grp2612 Firmware Grp2612p FirmwareGrp2612w Firmware+4 moreJun 17, 2026 Mar 29, 2021 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 Grandstream GRP261x VoIP phone running firmware version 1.0.3.6 (Base) allows Command Injection as root in its administrative web interface. |
1Invigo 1Automatic Device Management Jun 17, 2026 Mar 25, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A command injection on the /admin/broadcast.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote authenticated attackers to execute arbitrary PHP code on the server as the user running the app...Show more |
A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to execute arbitrary code with root privileges on the underlying operating system of an affected device. The vulnerabil...Show more |