CWE-77
3,617 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
CVEs (3,617)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian GraphicsmagickOpensuse4Backports Sle Debian LinuxGraphicsmagick+1 moreJun 17, 2026 Mar 18, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In GraphicsMagick before 1.3.32, the text filename component allows remote attackers to read arbitrary files via a crafted image because of TranslateTextEx for SVG. |
A shell command injection vulnerability in the PAN-OS CLI allows a local authenticated user to escape the restricted shell and escalate privileges. This issue affects only PAN-OS 8.1 versions earlier than PAN-OS 8.1.13....Show more |
An issue was discovered in GitLab Community and Enterprise Edition 11.11. A specially crafted payload would allow an authenticated malicious user to execute commands remotely through the repository download feature. It a...Show more |
1Cisco 3Remote Phy 120 Firmware Remote Phy 220 FirmwareRemote Phy Shelf 7200 FirmwareJun 17, 2026 Mar 4, 2020 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 A vulnerability in Cisco Remote PHY Device Software could allow an authenticated, local attacker to execute commands on the underlying Linux shell of an affected device with root privileges. The vulnerability exists beca...Show more |
1Kill Port Process Project 1Kill Port Process Jun 17, 2026 Feb 28, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The kill-port-process package version < 2.2.0 is vulnerable to a Command Injection vulnerability. |
There are command injection vulnerabilities present in the AirWave application. Certain input fields controlled by an administrative user are not properly sanitized before being parsed by AirWave. If conditions are met,...Show more |
1Tonnet 8Tat 70432n Firmware Tat 71416g1 FirmwareTat 71832g1 Firmware+5 moreJun 17, 2026 Feb 27, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 DVR firmware in TAT-76 and TAT-77 series of products, provided by TONNET do not properly verify patch files. Attackers can inject a specific command into a patch file and gain access to the system. |
GaussDB 200 with version of 6.5.1 have a command injection vulnerability. The software constructs part of a command using external input from users, but the software does not sufficiently validate the user input. Success...Show more |
GaussDB 200 with version of 6.5.1 have a command injection vulnerability. Due to insufficient input validation, remote attackers with low permissions could exploit this vulnerability by sending crafted commands to the af...Show more |
Adobe Digital Editions versions 4.5.10 and below have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution. |
IBM Security Secret Server 10.7 could allow a privileged user to perform unauthorized command injection due to imporoper input neutralization of special elements. IBM X-Force ID: 170011. |
1Cisco 2Collaboration Meeting Rooms Webex Video MeshJun 17, 2026 Jan 26, 2020 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 A vulnerability in the web-based management interface of Cisco Webex Video Mesh could allow an authenticated, remote attacker to execute arbitrary commands on the affected system. The vulnerability is due to improper val...Show more |
A vulnerability in the WebUI of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to inject and execute arbitrary commands with vmanage user privileges on an affected system. The vulnerability is du...Show more |
4Canonical DebianOpensuse+1 more4Debian Linux LeapSalt+1 moreJun 17, 2026 Jan 17, 2020 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 In SaltStack Salt through 2019.2.0, the salt-api NET API with the ssh client enabled is vulnerable to command injection. This allows an unauthenticated attacker with network access to the API endpoint to execute arbitrar...Show more |
Bitbucket Server and Bitbucket Data Center versions starting from version 3.0.0 before version 5.16.11, from version 6.0.0 before 6.0.11, from version 6.1.0 before 6.1.9, from version 6.2.0 before 6.2.7, from version 6.3...Show more |
LPAR2RRD ≤ 4.53 and ≤ 3.5 has arbitrary command injection on the application server. |
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop Parallels Desktop version 14.1.3 (45485). An attacker must first obtain the ability to execute low-privilege...Show more |
Brackets versions 1.14 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution. |
A command injection exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to inject commands via the API through the blobs scope. |
This command injection vulnerability in File Station allows attackers to execute commands on the affected device. To fix the vulnerability, QNAP recommend updating QTS to their latest versions. |