CWE-77
3,801 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
CVEs (3,801)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Lenovo 3Smart Camera C2e Firmware Smart Camera X3 FirmwareSmart Camera X5 FirmwareJun 17, 2026 Aug 17, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 A vulnerability was reported in Lenovo Smart Camera X3, X5, and C2E that could allow command injection by setting a specially crafted network configuration. This vulnerability is the same as CNVD-2020-68652. |
Dell EMC PowerScale OneFS versions 8.2.x - 9.1.1.x contain an improper neutralization of special elements used in an OS command. This vulnerability could allow the compadmin user to elevate privileges. This only impacts...Show more |
Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a command injection vulnerability in mail agent settings. Version 6.4.3.1 contains a patch. As workarounds for older versions of 6.1, 6.2,...Show more |
2Ivanti Pulsesecure2Connect Secure Pulse Connect SecureJun 17, 2026 Aug 16, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform command injection via an unsanitized web parameter in the administrator web console. |
2Ivanti Pulsesecure2Connect Secure Pulse Connect SecureJun 17, 2026 Aug 16, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform command injection via an unsanitized web parameter. |
1Dcce 1Mac1100 Plc Firmware Jun 17, 2026 Aug 13, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An issue in Dut Computer Control Engineering Co.'s PLC MAC1100 allows attackers to execute arbitrary code. |
1Netgear 10Rbk20 Firmware Rbk40 FirmwareRbk50 Firmware+7 moreJun 17, 2026 Aug 11, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK40 before 2.5.1.16, RBR40 before 2.5.1.16, RBS40 before 2.5.1.16, RBK20 before 2.5.1.16, RBR20 before 2.5.1.16, RB...Show more |
1Netgear 4D7800 Firmware R7800 FirmwareR8900 Firmware+1 moreJun 17, 2026 Aug 11, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D7800 before 1.0.1.56, R7800 before 1.0.2.68, R8900 before 1.0.4.26, and R9000 before 1.0.4.26. |
1Netgear 6D8500 Firmware R6900p FirmwareR7000p Firmware+3 moreJun 17, 2026 Aug 11, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D8500 before 1.0.3.58, R6900P before 1.3.2.132, R7000P before 1.3.2.132, R7100LG before 1.0.0.64, WNDR3400v3 before 1...Show more |
1Netgear 34Cbr40 Firmware Ex6100 FirmwareEx6150 Firmware+31 moreJun 17, 2026 Aug 11, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.14, EX6100v2 before 1.0.1.98, EX6150v2 before 1.0.1.98, EX6250 before 1.0.0.132, EX6400 before 1.0...Show more |
1Netgear 5R6400 Firmware R7900p FirmwareR8000p Firmware+2 moreJun 17, 2026 Aug 11, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6400 before 1.0.1.50, R7900P before 1.4.1.50, R8000P before 1.4.1.50, RAX75 before 1.0.1.62, and RAX80 before 1.0.1.62. |
1Netgear 4R6400 Firmware R6700 FirmwareR6900 Firmware+1 moreJun 17, 2026 Aug 11, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6400 before 1.0.1.52, R6400v2 before 1.0.4.84, R6700v3 before 1.0.4.84, R6700v2 before 1.2.0.62, R6900v2 before 1.2.0.62,...Show more |
1Netgear 14R6250 Firmware R6300 FirmwareR6400 Firmware+11 moreJun 17, 2026 Aug 11, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6250 before 1.0.4.36, R6300v2 before 1.0.4.36, R6400 before 1.0.1.50, R6400v2 before 1.0.2.66, R6700v3 before 1.0.2.66, R6...Show more |
1Netgear 6Rax200 Firmware Rax75 FirmwareRax80 Firmware+3 moreJun 17, 2026 Aug 11, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RAX200 before 1.0.4.120, RAX75 before 1.0.4.120, RAX80 before 1.0.4.120, RBK852 before 3.2.17.12, RBR850 before 3.2.17.12,...Show more |
In KDE KMail 19.12.3 (aka 5.13.3), the SMTP STARTTLS option is not honored (and cleartext messages are sent) unless "Server requires authentication" is checked. |
In KDE Trojita 0.7, man-in-the-middle attackers can create new folders because untagged responses from an IMAP server are accepted before STARTTLS. |
In Alpine before 2.25, untagged responses from an IMAP server are accepted before STARTTLS. |
An issue was discovered in the lettre crate before 0.9.6 for Rust. In an e-mail message body, an attacker can place a . character after two <CR><LF> sequences and then inject arbitrary SMTP commands. |
1Multiqueue Project 1Multiqueue Jun 17, 2026 Aug 8, 2021 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in the multiqueue crate through 2020-12-25 for Rust. There are unconditional implementations of Send for InnerSend<RW, T>, InnerRecv<RW, T>, FutInnerSend<RW, T>, and FutInnerRecv<RW, T>. |
An issue was discovered in the syncpool crate before 0.1.6 for Rust. There is an unconditional implementation of Send for Bucket2. |