← Back
CWE-77

3,801 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

JSON object

Loading...

CVEs (3,801)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Noise Search Project
1Noise Search
Jun 17, 2026
Aug 8, 2021
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in the noise_search crate through 2020-12-10 for Rust. There are unconditional implementations of Send and Sync for MvccRwLock.
1Dces Project
1Dces
Jun 17, 2026
Aug 8, 2021
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in the dces crate through 2020-12-09 for Rust. The World type is marked as Send but lacks bounds on its EntityStore and ComponentStore.
1Lever Project
1Lever
Jun 17, 2026
Aug 8, 2021
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in the lever crate before 0.1.1 for Rust. AtomicBox<T> implements the Send and Sync traits for all types T.
1Toolshed Project
1Toolshed
Jun 17, 2026
Aug 8, 2021
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in the toolshed crate through 2020-11-15 for Rust. In CopyCell<T>, the Send trait lacks bounds on the contained type.
1Brokenlamp
1Slock
Jun 17, 2026
Aug 8, 2021
N/A· v4
8.1 HIGH· v3
5.1 MEDIUM· v2
An issue was discovered in the slock crate through 2020-11-17 for Rust. Slock<T> unconditionally implements Send and Sync.
1Rcu Cell Project
1Rcu Cell
Jun 17, 2026
Aug 8, 2021
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in the rcu_cell crate through 2020-11-14 for Rust. There are unconditional implementations of Send and Sync for RcuCell<T>.
1Bunch Project
1Bunch
Jun 17, 2026
Aug 8, 2021
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in the bunch crate through 2020-11-12 for Rust. There are unconditional implementations of Send and Sync for Bunch<T>.
1Kekbit Project
1Kekbit
Jun 17, 2026
Aug 8, 2021
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in the kekbit crate before 0.3.4 for Rust. For ShmWriter<H>, Send is implemented without requiring H: Send.
1Cache Project
1Cache
Jun 17, 2026
Aug 8, 2021
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in the cache crate through 2020-11-24 for Rust. There are unconditional implementations of Send and Sync for Cache<K>.
3Debian
DigintFedoraproject
3Btrbk
Debian LinuxFedora
Jun 17, 2026
Aug 7, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Btrbk before 0.31.2 allows command execution because of the mishandling of remote hosts filtering SSH commands using ssh_filter_btrbk.sh in authorized_keys.
1Roxy Wi
1Roxy Wi
Jun 17, 2026
Aug 7, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Roxy-WI through 5.2.2.0 allows command injection via /app/funct.py and /api/api_funct.py.
1Prolink
1Prc2402m Firmware
Jun 17, 2026
Aug 6, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In ProLink PRC2402M V1.0.18 and older, the set_ledonoff function in the adm.cgi binary, accessible with a page parameter value of ledonoff contains a trivial command injection where the value of the led_cmd parameter is...Show more
In ProLink PRC2402M V1.0.18 and older, the set_ledonoff function in the adm.cgi binary, accessible with a page parameter value of ledonoff contains a trivial command injection where the value of the led_cmd parameter is passed directly to do_system.Show less
1Combodo
1Itop
Jun 17, 2026
Jul 21, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Combodo iTop is an open source, web based IT Service Management tool. In versions prior to 2.7.4, there is a command injection vulnerability in the Setup Wizard when providing Graphviz executable path. The vulnerability...Show more
Combodo iTop is an open source, web based IT Service Management tool. In versions prior to 2.7.4, there is a command injection vulnerability in the Setup Wizard when providing Graphviz executable path. The vulnerability is patched in version 2.7.4 and 3.0.0.Show less
1Github
1Enterprise Server
Jun 17, 2026
Jul 14, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A path traversal vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled configuration options used by GitHub Pages were not sufficiently restri...Show more
A path traversal vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled configuration options used by GitHub Pages were not sufficiently restricted and made it possible to read files on the GitHub Enterprise Server instance. To exploit this vulnerability, an attacker would need permission to create and build a GitHub Pages site on the GitHub Enterprise Server instance. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.1.3 and was fixed in 3.1.3, 3.0.11, and 2.22.17. This vulnerability was reported via the GitHub Bug Bounty program.Show less
1Qsan
2Sanos
Xevo
Jun 17, 2026
Jul 7, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Command injection vulnerability in QSAN XEVO, SANOS allows remote unauthenticated attackers to execute arbitrary commands. Suggest contacting with QSAN and refer to recommendations in QSAN Document.
3Debian
DovecotFedoraproject
3Debian Linux
DovecotFedora
Jun 17, 2026
Jun 28, 2021
N/A· v4
4.8 MEDIUM· v3
5.8 MEDIUM· v2
The submission service in Dovecot before 2.3.15 allows STARTTLS command injection in lib-smtp. Sensitive information can be redirected to an attacker-controlled address.
1Evernote
1Evernote
Jun 17, 2026
Jun 24, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was found in the Evernote client for Windows 10, 7, and 2008 in the protocol handler. This enables attackers for arbitrary command execution if the user clicks on a specially crafted URL. AKA: WINNOTE-19941.
1Ibos
1Ibos
Jun 17, 2026
Jun 24, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In IBOS 4.5.4 Open, the database backup has Command Injection Vulnerability.
1Synology
1Download Station
Jun 17, 2026
Jun 18, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Improper neutralization of special elements used in a command ('Command Injection') vulnerability in task management component in Synology Download Station before 3.8.16-3566 allows remote authenticated users to execute...Show more
Improper neutralization of special elements used in a command ('Command Injection') vulnerability in task management component in Synology Download Station before 3.8.16-3566 allows remote authenticated users to execute arbitrary code via unspecified vectors.Show less
1Roonlabs
1Roon Server
Jun 17, 2026
Jun 8, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. Roon Labs has already fixed this vulnerability in the following versions: Roon Server 2021-05-18 and later