CWE-77
3,801 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
CVEs (3,801)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Debian FedoraprojectLinux+1 more13Cloud Backup Debian LinuxFedora+10 moreJun 17, 2026 Apr 8, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 BPF JIT compilers in the Linux kernel through 5.11.12 have incorrect computation of branch displacements, allowing them to execute arbitrary code within the kernel context. This affects arch/x86/net/bpf_jit_comp.c and ar...Show more |
1Grandstream 7Grp2612 Firmware Grp2612p FirmwareGrp2612w Firmware+4 moreJun 17, 2026 Mar 29, 2021 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 Grandstream GRP261x VoIP phone running firmware version 1.0.3.6 (Base) allows Command Injection as root in its administrative web interface. |
1Invigo 1Automatic Device Management Jun 17, 2026 Mar 25, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A command injection on the /admin/broadcast.php script of Invigo Automatic Device Management (ADM) through 5.0 allows remote authenticated attackers to execute arbitrary PHP code on the server as the user running the app...Show more |
A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to execute arbitrary code with root privileges on the underlying operating system of an affected device. The vulnerabil...Show more |
A vulnerability in Cisco IOx application hosting environment of Cisco IOS XE Software could allow an authenticated, remote attacker to inject commands into the underlying operating system as the root user. This vulnerabi...Show more |
A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands to be executed with root privileges on the underlying operating system. This vulnerabil...Show more |
A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled configuration options used by GitHub Pages were not sufficiently...Show more |
1Netgear 5Rbk852 Firmware Rbk853 FirmwareRbk854 Firmware+2 moreJun 17, 2026 Mar 23, 2021 N/A· v4 9.6 CRITICAL· v3 5.8 MEDIUM· v2 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RBK854 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before...Show more |
1Netgear 11Rbk752 Firmware Rbk753 FirmwareRbk753s Firmware+8 moreJun 17, 2026 Mar 23, 2021 N/A· v4 9.6 CRITICAL· v3 5.8 MEDIUM· v2 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RBK854 before 3.2.17.12, RBR850 before 3.2.17.12, RBS850 before 3.2...Show more |
1Netgear 13Rbk752 Firmware Rbk753 FirmwareRbk753s Firmware+10 moreJun 17, 2026 Mar 23, 2021 N/A· v4 9.6 CRITICAL· v3 5.8 MEDIUM· v2 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBW30 before 2.6.2.2, RBS40V before 2.6.2.4, RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RBK854 before 3.2.17.1...Show more |
1Netgear 5Rbk852 Firmware Rbk853 FirmwareRbk854 Firmware+2 moreJun 17, 2026 Mar 23, 2021 N/A· v4 9.6 CRITICAL· v3 5.8 MEDIUM· v2 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RBK854 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before...Show more |
1Netgear 5Rbk852 Firmware Rbk853 FirmwareRbk854 Firmware+2 moreJun 17, 2026 Mar 23, 2021 N/A· v4 8.4 HIGH· v3 5.2 MEDIUM· v2 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RBK854 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.1...Show more |
1Netgear 11Rbk852 Firmware Rbk853 FirmwareRbk854 Firmware+8 moreJun 17, 2026 Mar 23, 2021 N/A· v4 9.0 CRITICAL· v3 5.2 MEDIUM· v2 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RBK854 before 3.2.17.12, RBR850 before 3.2.17.12, RBS850 before 3.2.17.12...Show more |
1Netgear 5Rbk852 Firmware Rbk853 FirmwareRbk854 Firmware+2 moreJun 17, 2026 Mar 23, 2021 N/A· v4 8.4 HIGH· v3 5.2 MEDIUM· v2 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RBK854 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.1...Show more |
1Netgear 3Wnr2000v5 Firmware Xr450 FirmwareXr500 FirmwareJun 17, 2026 Mar 23, 2021 N/A· v4 8.4 HIGH· v3 5.2 MEDIUM· v2 Certain NETGEAR devices are affected by command injection by an authenticated user. This affects XR450 before 2.3.2.114, XR500 before 2.3.2.114, and WNR2000v5 before 1.0.0.76. |
1Eslint Fixer Project 1Eslint Fixer Jun 17, 2026 Mar 19, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The eslint-fixer package through 0.1.5 for Node.js allows command injection via shell metacharacters to the fix function. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. The...Show more |
fs-path node module before 0.0.25 is vulnerable to command injection by way of user-supplied inputs via the `copy`, `copySync`, `remove`, and `removeSync` methods. |
A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled configuration of the underlying parsers used by GitHub Pages wer...Show more |
3Debian FedoraprojectSaltstack3Debian Linux FedoraSaltJun 17, 2026 Feb 27, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in SaltStack Salt before 3002.5. Sending crafted web requests to the Salt API can result in salt.utils.thin.gen_thin() command injection because of different handling of single versus double quote...Show more |
3Debian FedoraprojectSaltstack3Debian Linux FedoraSaltJun 17, 2026 Feb 27, 2021 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 An issue was discovered in SaltStack Salt before 3002.5. The minion's restartcheck is vulnerable to command injection via a crafted process name. This allows for a local privilege escalation by any user able to create a...Show more |