CWE-77
3,617 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
CVEs (3,617)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A vulnerability in Cisco IOx application hosting environment of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands into the underlying operating system as the root user. This vulnerabi...Show more |
A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands to be executed with root privileges on the underlying operating system. This vulnerabil...Show more |
A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled configuration options used by GitHub Pages were not sufficiently...Show more |
1Netgear 5Rbk852 Firmware Rbk853 FirmwareRbk854 Firmware+2 moreJun 17, 2026 Mar 23, 2021 N/A· v4 9.6 CRITICAL· v3 5.8 MEDIUM· v2 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RBK854 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before...Show more |
1Netgear 11Rbk752 Firmware Rbk753 FirmwareRbk753s Firmware+8 moreJun 17, 2026 Mar 23, 2021 N/A· v4 9.6 CRITICAL· v3 5.8 MEDIUM· v2 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RBK854 before 3.2.17.12, RBR850 before 3.2.17.12, RBS850 before 3.2...Show more |
1Netgear 13Rbk752 Firmware Rbk753 FirmwareRbk753s Firmware+10 moreJun 17, 2026 Mar 23, 2021 N/A· v4 9.6 CRITICAL· v3 5.8 MEDIUM· v2 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBW30 before 2.6.2.2, RBS40V before 2.6.2.4, RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RBK854 before 3.2.17.1...Show more |
1Netgear 5Rbk852 Firmware Rbk853 FirmwareRbk854 Firmware+2 moreJun 17, 2026 Mar 23, 2021 N/A· v4 9.6 CRITICAL· v3 5.8 MEDIUM· v2 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RBK854 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before...Show more |
1Netgear 5Rbk852 Firmware Rbk853 FirmwareRbk854 Firmware+2 moreJun 17, 2026 Mar 23, 2021 N/A· v4 8.4 HIGH· v3 5.2 MEDIUM· v2 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RBK854 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.1...Show more |
1Netgear 11Rbk852 Firmware Rbk853 FirmwareRbk854 Firmware+8 moreJun 17, 2026 Mar 23, 2021 N/A· v4 9.0 CRITICAL· v3 5.2 MEDIUM· v2 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RBK854 before 3.2.17.12, RBR850 before 3.2.17.12, RBS850 before 3.2.17.12...Show more |
1Netgear 5Rbk852 Firmware Rbk853 FirmwareRbk854 Firmware+2 moreJun 17, 2026 Mar 23, 2021 N/A· v4 8.4 HIGH· v3 5.2 MEDIUM· v2 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RBK854 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.1...Show more |
1Netgear 3Wnr2000v5 Firmware Xr450 FirmwareXr500 FirmwareJun 17, 2026 Mar 23, 2021 N/A· v4 8.4 HIGH· v3 5.2 MEDIUM· v2 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects XR450 before 2.3.2.114, XR500 before 2.3.2.114, and WNR2000v5 before 1.0.0.76. |
1Eslint Fixer Project 1Eslint Fixer Jun 17, 2026 Mar 19, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The eslint-fixer package through 0.1.5 for Node.js allows command injection via shell metacharacters to the fix function. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. The...Show more |
fs-path node module before 0.0.25 is vulnerable to command injection by way of user-supplied inputs via the `copy`, `copySync`, `remove`, and `removeSync` methods. |
A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled configuration of the underlying parsers used by GitHub Pages wer...Show more |
3Debian FedoraprojectSaltstack3Debian Linux FedoraSaltJun 17, 2026 Feb 27, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in SaltStack Salt before 3002.5. Sending crafted web requests to the Salt API can result in salt.utils.thin.gen_thin() command injection because of different handling of single versus double quote...Show more |
3Debian FedoraprojectSaltstack3Debian Linux FedoraSaltJun 17, 2026 Feb 27, 2021 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 An issue was discovered in SaltStack Salt before 3002.5. The minion's restartcheck is vulnerable to command injection via a crafted process name. This allows for a local privilege escalation by any user able to create a...Show more |
The EFM ipTIME C200 IP Camera is affected by a Command Injection vulnerability in /login.cgi?logout=1 script. To exploit this vulnerability, an attacker can send a GET request that executes arbitrary OS commands via cook...Show more |
1Netgear 19Ac2100 Firmware Ac2400 FirmwareAc2600 Firmware+16 moreJun 17, 2026 Feb 12, 2021 N/A· v4 6.8 MEDIUM· v3 7.7 HIGH· v2 This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6020, R6080, R6120, R6220, R6260, R6700v2, R6800, R6900v2, R7450, JNR3210, WNR2020, Nighthawk AC2100, a...Show more |
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1860 firmware version 1.04B03 WiFi extenders. Authentication is not required to exploit this vulnerab...Show more |
1Dlink 2Dsl 2888a Firmware Dva 2800 FirmwareJun 17, 2026 Feb 12, 2021 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DVA-2800 and DSL-2888A routers. Authentication is not required to exploit this vulnerability. The specifi...Show more |