CWE-77
3,617 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
CVEs (3,617)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Netgear 6Rbk752 Firmware Rbk852 FirmwareRbr750 Firmware+3 moreJun 17, 2026 Oct 9, 2020 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK752 before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3.2.15.25, RBK852 before 3.2.15.25, RBR850 before 3.2...Show more |
In the `@actions/core` npm module before version 1.2.6,`addPath` and `exportVariable` functions communicate with the Actions Runner over stdout by generating a string in a specific format. Workflows that log untrusted da...Show more |
In screencap, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege in a system process with User execution privileges needed. User interaction is not ne...Show more |
An issue was discovered in Titan SpamTitan 7.07. Improper input sanitization of the parameter community on the page snmp-x.php would allow a remote attacker to inject commands into the file snmpd.conf that would allow ex...Show more |
A command injection vulnerability in Trend Micro ServerProtect for Linux 3.0 could allow an attacker to execute arbitrary code on an affected system. An attacker must first obtain admin/root privileges on the SPLX consol...Show more |
In Xiaomi router R3600 ROM version<1.0.66, filters in the set_WAN6 interface can be bypassed, causing remote code execution. The router administrator can gain root access from this vulnerability. |
3Fedoraproject OpensuseSamba3Cifs Utils FedoraLeapJun 17, 2026 Sep 9, 2020 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 It was found that cifs-utils' mount.cifs was invoking a shell when requesting the Samba password, which could be used to inject arbitrary commands. An attacker able to invoke mount.cifs with special permission, such as v...Show more |
1Qualcomm 7Ipq4019 Firmware Ipq6018 FirmwareIpq8064 Firmware+4 moreJun 17, 2026 Sep 8, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 u'In the lbd service, an external user can issue a specially crafted debug command to overwrite arbitrary files with arbitrary content resulting in remote code execution.' in Snapdragon Connectivity, Snapdragon Consumer...Show more |
1Huawei 3B2368 22 Firmware B2368 57 FirmwareB2368 66 FirmwareJun 17, 2026 Sep 3, 2020 N/A· v4 6.8 MEDIUM· v3 7.7 HIGH· v2 B2368-22 V100R001C00;B2368-57 V100R001C00;B2368-66 V100R001C00 have a command injection vulnerability. An attacker with high privileges may exploit this vulnerability through some operations on the LAN. Due to insufficie...Show more |
1Dlink 9Dcs 2530l Firmware Dcs 2670l FirmwareDcs 4603 Firmware+6 moreJun 17, 2026 Sep 2, 2020 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. cgi-bin/ddns_enc.cgi allows authenticated command injection. |
NETGEAR R8300 devices before 1.0.2.134 are affected by command injection by an unauthenticated attacker. |
A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled configuration of the underlying parsers used by GitHub Pages wer...Show more |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of installations of Marvell QConvergeConsole 5.5.0.64. Although authentication is required to exploit this vulnerability, the...Show more |
Several potential command injections vulnerabilities exist in the AT command interface of ALEOS before 4.11.0, and 4.9.4. |
2Opensuse Ui3Backports Sle Edgeswitch FirmwareLeapJun 17, 2026 Aug 17, 2020 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A command injection vulnerability exists in EdgeSwitch firmware <v1.9.0 that allowed an authenticated read-only user to execute arbitrary shell commands over the HTTP interface, allowing them to escalate privileges. |
Improper input validation in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5 allows SQL Injection. |
FusionCompute 8.0.0 have a command injection vulnerability. The software does not sufficiently validate certain parameters post from user, successful exploit could allow an authenticated attacker to launch a command inje...Show more |
1Mock2easy Project 1Mock2easy Jun 17, 2026 Jul 29, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 This affects all versions of package mock2easy. a malicious user could inject commands through the _data variable: Affected Area require('../server/getJsonByCurl')(mock2easy, function (error, stdout) { if (error) { retur...Show more |
1Ruckuswireless 1Unleashed Firmware Jun 17, 2026 Jul 28, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 emfd/libemf in Ruckus Wireless Unleashed through 200.7.10.102.92 allows a remote attacker to achieve command injection via a crafted HTTP request. This affects C110, E510, H320, H510, M510, R320, R310, R500, R510 R600, R...Show more |
1Ruckuswireless 1Unleashed Firmware Jun 17, 2026 Jul 28, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 rkscli in Ruckus Wireless Unleashed through 200.7.10.92 allows a remote attacker to achieve command injection and jailbreak the CLI via a crafted CLI command. This affects C110, E510, H320, H510, M510, R320, R310, R500,...Show more |