CWE-77
3,617 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
CVEs (3,617)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Adobe Download Manager version 2.0.0.518 have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution. |
Advantech iView, versions 5.6 and prior, has an improper neutralization of special elements used in a command (“command injection”) vulnerability. Successful exploitation of this vulnerability may allow an attacker to se...Show more |
In iPear, the manual execution of the eval() function can lead to command injection. Only PCs where commands are manually executed via "For Developers" are affected. This function allows executing any PHP code within iPe...Show more |
A command injection vulnerability in the `devcert` module may lead to remote code execution when users of the module pass untrusted input to the `certificateFor` function. |
We have recently released new version of UniFi Protect firmware v1.13.3 and v1.14.10 for Unifi Cloud Key Gen2 Plus and UniFi Dream Machine Pro/UNVR respectively that fixes vulnerabilities found on Protect firmware v1.13....Show more |
Chrome Extension for e-Tax Reception System Ver1.0.0.0 allows remote attackers to execute an arbitrary command via unspecified vectors. |
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution. |
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution. |
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution. |
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution. |
1Draytek 3Vigor2960 Firmware Vigor300b FirmwareVigor3900 FirmwareJun 17, 2026 Jun 24, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 On Draytek Vigor3900, Vigor2960, and Vigor 300B devices before 1.5.1.1, there are some command-injection vulnerabilities in the mainfunction.cgi file. |
1Mi 1Mijia Inkjet Printer Firmware Jun 17, 2026 Jun 24, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered on Xiaomi Mi Jia ink-jet printer < 3.4.6_0138. Injecting parameters to ippserver through the web management background, resulting in command execution vulnerabilities. |
1Openfind 2Mailaudit MailgatesJun 17, 2026 Jun 23, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Openfind MailGates contains a Command Injection flaw, when receiving email with specific strings, malicious code in the mail attachment will be triggered and gain unauthorized access to system files. |
In mversion before 2.0.0, there is a command injection vulnerability. This issue may lead to remote code execution if a client of the library calls the vulnerable method with untrusted input. This vulnerability is patche...Show more |
1Netgear 12Rbk752 Firmware Rbk753 FirmwareRbk753s Firmware+9 moreJun 17, 2026 Jun 18, 2020 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK752 before 3.2.15.25, RBK753 before 3.2.15.25, RBK753S before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3....Show more |
1Netgear 12Rbk752 Firmware Rbk753 FirmwareRbk753s Firmware+9 moreJun 17, 2026 Jun 18, 2020 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK752 before 3.2.15.25, RBK753 before 3.2.15.25, RBK753S before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3....Show more |
1Netgear 12Rbk752 Firmware Rbk753 FirmwareRbk753s Firmware+9 moreJun 17, 2026 Jun 18, 2020 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK752 before 3.2.15.25, RBK753 before 3.2.15.25, RBK753S before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3....Show more |
1Netgear 12Rbk752 Firmware Rbk753 FirmwareRbk753s Firmware+9 moreJun 17, 2026 Jun 18, 2020 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK752 before 3.2.15.25, RBK753 before 3.2.15.25, RBK753S before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3....Show more |
1Netgear 12Rbk752 Firmware Rbk753 FirmwareRbk753s Firmware+9 moreJun 17, 2026 Jun 18, 2020 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK752 before 3.2.15.25, RBK753 before 3.2.15.25, RBK753S before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3....Show more |
1Netgear 12Rbk752 Firmware Rbk753 FirmwareRbk753s Firmware+9 moreJun 17, 2026 Jun 18, 2020 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK752 before 3.2.15.25, RBK753 before 3.2.15.25, RBK753S before 3.2.15.25, RBR750 before 3.2.15.25, RBS750 before 3....Show more |