← Back
CWE-77

3,617 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

JSON object

Loading...

CVEs (3,617)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Debian
GraphicsmagickOpensuse
4Backports Sle
Debian LinuxGraphicsmagick+1 more
Jun 17, 2026
Mar 18, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In GraphicsMagick before 1.3.32, the text filename component allows remote attackers to read arbitrary files via a crafted image because of TranslateTextEx for SVG.
1Paloaltonetworks
1Pan Os
Jun 17, 2026
Mar 11, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A shell command injection vulnerability in the PAN-OS CLI allows a local authenticated user to escape the restricted shell and escalate privileges. This issue affects only PAN-OS 8.1 versions earlier than PAN-OS 8.1.13....Show more
A shell command injection vulnerability in the PAN-OS CLI allows a local authenticated user to escape the restricted shell and escalate privileges. This issue affects only PAN-OS 8.1 versions earlier than PAN-OS 8.1.13. This issue does not affect PAN-OS 7.1, PAN-OS 9.0, or later PAN-OS versions. This issue is fixed in PAN-OS 8.1.13, and all later versions.Show less
1Gitlab
1Gitlab
Jun 17, 2026
Mar 10, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in GitLab Community and Enterprise Edition 11.11. A specially crafted payload would allow an authenticated malicious user to execute commands remotely through the repository download feature. It a...Show more
An issue was discovered in GitLab Community and Enterprise Edition 11.11. A specially crafted payload would allow an authenticated malicious user to execute commands remotely through the repository download feature. It allows Command Injection.Show less
1Cisco
3Remote Phy 120 Firmware
Remote Phy 220 FirmwareRemote Phy Shelf 7200 Firmware
Jun 17, 2026
Mar 4, 2020
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
A vulnerability in Cisco Remote PHY Device Software could allow an authenticated, local attacker to execute commands on the underlying Linux shell of an affected device with root privileges. The vulnerability exists beca...Show more
A vulnerability in Cisco Remote PHY Device Software could allow an authenticated, local attacker to execute commands on the underlying Linux shell of an affected device with root privileges. The vulnerability exists because the affected software does not properly sanitize user-supplied input. An attacker who has valid administrator access to an affected device could exploit this vulnerability by supplying certain CLI commands with crafted arguments. A successful exploit could allow the attacker to run arbitrary commands as the root user, which could result in a complete system compromise.Show less
1Kill Port Process Project
1Kill Port Process
Jun 17, 2026
Feb 28, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The kill-port-process package version < 2.2.0 is vulnerable to a Command Injection vulnerability.
1Arubanetworks
1Airwave
Jun 17, 2026
Feb 27, 2020
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
There are command injection vulnerabilities present in the AirWave application. Certain input fields controlled by an administrative user are not properly sanitized before being parsed by AirWave. If conditions are met,...Show more
There are command injection vulnerabilities present in the AirWave application. Certain input fields controlled by an administrative user are not properly sanitized before being parsed by AirWave. If conditions are met, an attacker can obtain command execution on the host.Show less
1Tonnet
8Tat 70432n Firmware
Tat 71416g1 FirmwareTat 71832g1 Firmware+5 more
Jun 17, 2026
Feb 27, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
DVR firmware in TAT-76 and TAT-77 series of products, provided by TONNET do not properly verify patch files. Attackers can inject a specific command into a patch file and gain access to the system.
1Huawei
1Gaussdb 200
Jun 17, 2026
Feb 18, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
GaussDB 200 with version of 6.5.1 have a command injection vulnerability. The software constructs part of a command using external input from users, but the software does not sufficiently validate the user input. Success...Show more
GaussDB 200 with version of 6.5.1 have a command injection vulnerability. The software constructs part of a command using external input from users, but the software does not sufficiently validate the user input. Successful exploit could allow the attacker to inject certain commands.Show less
1Huawei
1Gaussdb 200
Jun 17, 2026
Feb 18, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
GaussDB 200 with version of 6.5.1 have a command injection vulnerability. Due to insufficient input validation, remote attackers with low permissions could exploit this vulnerability by sending crafted commands to the af...Show more
GaussDB 200 with version of 6.5.1 have a command injection vulnerability. Due to insufficient input validation, remote attackers with low permissions could exploit this vulnerability by sending crafted commands to the affected device. Successful exploit could allow an attacker to execute commands.Show less
1Adobe
1Digital Editions
Jun 17, 2026
Feb 13, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Adobe Digital Editions versions 4.5.10 and below have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.
1Ibm
1Security Secret Server
Jun 17, 2026
Jan 28, 2020
N/A· v4
2.7 LOW· v3
4.0 MEDIUM· v2
IBM Security Secret Server 10.7 could allow a privileged user to perform unauthorized command injection due to imporoper input neutralization of special elements. IBM X-Force ID: 170011.
1Cisco
2Collaboration Meeting Rooms
Webex Video Mesh
Jun 17, 2026
Jan 26, 2020
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
A vulnerability in the web-based management interface of Cisco Webex Video Mesh could allow an authenticated, remote attacker to execute arbitrary commands on the affected system. The vulnerability is due to improper val...Show more
A vulnerability in the web-based management interface of Cisco Webex Video Mesh could allow an authenticated, remote attacker to execute arbitrary commands on the affected system. The vulnerability is due to improper validation of user-supplied input by the web-based management interface of the affected software. An attacker could exploit this vulnerability by logging in to the web-based management interface with administrative privileges and supplying crafted requests to the application. A successful exploit could allow the attacker to execute arbitrary commands on the underlying Linux operating system with root privileges on a targeted node.Show less
1Cisco
1Sd Wan Firmware
Jun 17, 2026
Jan 26, 2020
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
A vulnerability in the WebUI of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to inject and execute arbitrary commands with vmanage user privileges on an affected system. The vulnerability is du...Show more
A vulnerability in the WebUI of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to inject and execute arbitrary commands with vmanage user privileges on an affected system. The vulnerability is due to insufficient input validation of data parameters for certain fields in the affected solution. An attacker could exploit this vulnerability by configuring a malicious username on the login page of the affected solution. A successful exploit could allow the attacker to inject and execute arbitrary commands with vmanage user privileges on an affected system.Show less
4Canonical
DebianOpensuse+1 more
4Debian Linux
LeapSalt+1 more
Jun 17, 2026
Jan 17, 2020
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
In SaltStack Salt through 2019.2.0, the salt-api NET API with the ssh client enabled is vulnerable to command injection. This allows an unauthenticated attacker with network access to the API endpoint to execute arbitrar...Show more
In SaltStack Salt through 2019.2.0, the salt-api NET API with the ssh client enabled is vulnerable to command injection. This allows an unauthenticated attacker with network access to the API endpoint to execute arbitrary code on the salt-api host.Show less
1Atlassian
1Bitbucket
Jun 17, 2026
Jan 15, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Bitbucket Server and Bitbucket Data Center versions starting from version 3.0.0 before version 5.16.11, from version 6.0.0 before 6.0.11, from version 6.1.0 before 6.1.9, from version 6.2.0 before 6.2.7, from version 6.3...Show more
Bitbucket Server and Bitbucket Data Center versions starting from version 3.0.0 before version 5.16.11, from version 6.0.0 before 6.0.11, from version 6.1.0 before 6.1.9, from version 6.2.0 before 6.2.7, from version 6.3.0 before 6.3.6, from version 6.4.0 before 6.4.4, from version 6.5.0 before 6.5.3, from version 6.6.0 before 6.6.3, from version 6.7.0 before 6.7.3, from version 6.8.0 before 6.8.2, and from version 6.9.0 before 6.9.1 had a Remote Code Execution vulnerability via certain user input fields. A remote attacker with user level permissions can exploit this vulnerability to run arbitrary commands on the victim's systems. Using a specially crafted payload as user input, the attacker can execute arbitrary commands on the victim's Bitbucket Server or Bitbucket Data Center instance.Show less
1Xorux
1Lpar2rrd
Nov 21, 2024
Jan 10, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
LPAR2RRD ≤ 4.53 and ≤ 3.5 has arbitrary command injection on the application server.
1Parallels
1Parallels Desktop
Jun 17, 2026
Jan 7, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop Parallels Desktop version 14.1.3 (45485). An attacker must first obtain the ability to execute low-privilege...Show more
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop Parallels Desktop version 14.1.3 (45485). An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the Parallels Service. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to escalate privileges and execute code in the context of root. Was ZDI-CAN-8685.Show less
1Adobe
1Brackets
Jun 17, 2026
Dec 19, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Brackets versions 1.14 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.
1Gitlab
1Gitlab
Jun 17, 2026
Dec 18, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A command injection exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to inject commands via the API through the blobs scope.
1Qnap
1Qts
Nov 21, 2024
Dec 4, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
This command injection vulnerability in File Station allows attackers to execute commands on the affected device. To fix the vulnerability, QNAP recommend updating QTS to their latest versions.