← Back
CWE-77

3,617 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

JSON object

Loading...

CVEs (3,617)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Qnap
1Music Station
Nov 21, 2024
Dec 4, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
This command injection vulnerability in Music Station allows attackers to execute commands on the affected device. To fix the vulnerability, QNAP recommend updating Music Station to their latest versions.
1Ui
1Unifi Video Controller
Jun 17, 2026
Nov 26, 2019
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
A privilege escalation exists in UniFi Video Controller =<3.10.6 that would allow an attacker on the local machine to run arbitrary commands.
1Untangle
1Ng Firewall
Jun 17, 2026
Nov 14, 2019
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
The Untangle NG firewall 14.2.0 is vulnerable to an authenticated command injection when logged in as an admin user.
1Google
1Android
Jun 17, 2026
Nov 13, 2019
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
In the Bootloader, there is a possible kernel command injection due to missing command sanitization. This could lead to a local elevation of privilege with System execution privileges needed. User interaction is not need...Show more
In the Bootloader, there is a possible kernel command injection due to missing command sanitization. This could lead to a local elevation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-80316910Show less
1Veritas
6Access
Access ApplianceCluster Server+3 more
Jun 17, 2026
Nov 5, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An arbitrary command injection vulnerability in the Cluster Server component of Veritas InfoScale allows an unauthenticated remote attacker to execute arbitrary commands as root or administrator. These Veritas products a...Show more
An arbitrary command injection vulnerability in the Cluster Server component of Veritas InfoScale allows an unauthenticated remote attacker to execute arbitrary commands as root or administrator. These Veritas products are affected: Access 7.4.2 and earlier, Access Appliance 7.4.2 and earlier, Flex Appliance 1.2 and earlier, InfoScale 7.3.1 and earlier, InfoScale between 7.4.0 and 7.4.1, Veritas Cluster Server (VCS) 6.2.1 and earlier on Linux/UNIX, Veritas Cluster Server (VCS) 6.1 and earlier on Windows, Storage Foundation HA (SFHA) 6.2.1 and earlier on Linux/UNIX, and Storage Foundation HA (SFHA) 6.1 and earlier on Windows.Show less
1360
5Safe Router P0 Firmware
Safe Router P1 FirmwareSafe Router P2 Firmware+2 more
Nov 21, 2024
Nov 4, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A command injection vulnerability exists when the authorized user passes crafted parameter to background process in the router. This affects 360 router series products (360 Safe Router P0,P1,P2,P3,P4), the affected versi...Show more
A command injection vulnerability exists when the authorized user passes crafted parameter to background process in the router. This affects 360 router series products (360 Safe Router P0,P1,P2,P3,P4), the affected version is V2.0.61.58897.Show less
1Sonatype
1Nexus Repository Manager
Jun 17, 2026
Nov 1, 2019
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
There is an OS Command Injection in Nexus Repository Manager <= 2.14.14 (bypass CVE-2019-5475) that could allow an attacker a Remote Code Execution (RCE). All instances using CommandLineExecutor.java with user-supplied d...Show more
There is an OS Command Injection in Nexus Repository Manager <= 2.14.14 (bypass CVE-2019-5475) that could allow an attacker a Remote Code Execution (RCE). All instances using CommandLineExecutor.java with user-supplied data is vulnerable, such as the Yum Configuration Capability.Show less
1Ztw
1Zx297520v3 Firmware
Jun 17, 2026
Oct 31, 2019
N/A· v4
8.0 HIGH· v3
7.7 HIGH· v2
The 7520V3V1.0.0B09P27 version, and all earlier versions of ZTE product ZX297520V3 are impacted by a Command Injection vulnerability. Unauthorized users can exploit this vulnerability to control the user terminal system.
2Arubanetworks
Siemens
2Instant
W1750d Firmware
Nov 21, 2024
Oct 30, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Aruba Instant 4.x prior to 6.4.4.8-4.2.4.12, 6.5.x prior to 6.5.4.11, 8.3.x prior to 8.3.0.6, and 8.4.x prior to 8.4.0.1 allows Command injection.
1Trendmicro
1Apex One
Jun 17, 2026
Oct 28, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Trend Micro Apex One could be exploited by an attacker utilizing a command injection vulnerability to extract files from an arbitrary zip file to a specific folder on the Apex One server, which could potentially lead to...Show more
Trend Micro Apex One could be exploited by an attacker utilizing a command injection vulnerability to extract files from an arbitrary zip file to a specific folder on the Apex One server, which could potentially lead to remote code execution (RCE). The remote process execution is bound to the IUSR account, which has restricted permission and is unable to make major system changes. An attempted attack requires user authentication.Show less
1Adobe
1Experience Manager
Jun 17, 2026
Oct 25, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Adobe Experience Manager versions 6.5, 6.4, 6.3 and 6.2 have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.
1Softing
3Uagate 840d Firmware
Uagate Mb FirmwareUagate Si Firmware
Jun 17, 2026
Oct 10, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
An issue was discovered in Softing uaGate (SI, MB, 840D) firmware through 1.71.00.1225. A CGI script is vulnerable to command injection via a maliciously crafted form parameter.
1Zingbox
1Inspector
Jun 17, 2026
Oct 9, 2019
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
A security vulnerability exists in Zingbox Inspector version 1.293 and earlier, that allows for remote code execution if the Inspector were sent a malicious command from the Zingbox cloud, or if the Zingbox Inspector wer...Show more
A security vulnerability exists in Zingbox Inspector version 1.293 and earlier, that allows for remote code execution if the Inspector were sent a malicious command from the Zingbox cloud, or if the Zingbox Inspector were tampered with to connect to an attacker's cloud endpoint.Show less
1Jetbrains
1Ktor
Jun 17, 2026
Oct 2, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
JetBrains Ktor framework before 1.2.0-rc does not sanitize the username provided by the user for the LDAP protocol, leading to command injection.
1Adobe
1Coldfusion
Jun 17, 2026
Sep 27, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
ColdFusion 2018- update 4 and earlier and ColdFusion 2016- update 11 and earlier have a Command Injection via Vulnerable component vulnerability. Successful exploitation could lead to Arbitrary code execution in the cont...Show more
ColdFusion 2018- update 4 and earlier and ColdFusion 2016- update 11 and earlier have a Command Injection via Vulnerable component vulnerability. Successful exploitation could lead to Arbitrary code execution in the context of the current user.Show less
1Cloudfoundry
1Uaa Release
Jun 17, 2026
Sep 26, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
CF UAA versions prior to 74.1.0 can request scopes for a client that shouldn't be allowed by submitting an array of requested scopes. A remote malicious user can escalate their own privileges to any scope, allowing them...Show more
CF UAA versions prior to 74.1.0 can request scopes for a client that shouldn't be allowed by submitting an array of requested scopes. A remote malicious user can escalate their own privileges to any scope, allowing them to take control of UAA and the resources it controls.Show less
1Cloudfoundry
1User Account And Authentication
Jun 17, 2026
Sep 26, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
CF UAA versions prior to 74.1.0, allow external input to be directly queried against. A remote malicious user with 'client.write' and 'groups.update' can craft a SCIM query, which leaks information that allows an escalat...Show more
CF UAA versions prior to 74.1.0, allow external input to be directly queried against. A remote malicious user with 'client.write' and 'groups.update' can craft a SCIM query, which leaks information that allows an escalation of privileges, ultimately allowing the malicious user to gain control of UAA scopes they should not have.Show less
1Cisco
1Ios Xe
Jun 17, 2026
Sep 25, 2019
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
A vulnerability in a Virtualization Manager (VMAN) related CLI command of Cisco IOS XE Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying Linux operating system with a p...Show more
A vulnerability in a Virtualization Manager (VMAN) related CLI command of Cisco IOS XE Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying Linux operating system with a privilege level of root. The vulnerability is due to insufficient validation of arguments passed to a specific VMAN CLI command on the affected device. An attacker who has administrator access to an affected device could exploit this vulnerability by including malicious input as the argument of an affected command. A successful exploit could allow the attacker to execute arbitrary commands on the device with root privileges, which may lead to complete system compromise.Show less
1Cisco
3Cloud Services Router 1000v Firmware
Integrated Services Virtual Router FirmwareIos
Jun 17, 2026
Sep 25, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands with elevated privileges on the affected device. For more infor...Show more
Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands with elevated privileges on the affected device. For more information about these vulnerabilities, see the Details section of this advisory.Show less
1Cisco
2Ios
Ios Xe
Jun 17, 2026
Sep 25, 2019
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands with elevated privileges on the affected device. For more infor...Show more
Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands with elevated privileges on the affected device. For more information about these vulnerabilities, see the Details section of this advisory.Show less