CWE-77
3,617 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
CVEs (3,617)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In WebAccess versions 8.4.1 and prior, multiple command injection vulnerabilities are caused by a lack of proper validation of user-supplied data and may allow arbitrary file deletion and remote code execution. |
In MobaXterm 11.1 and 12.1, the protocol handler is vulnerable to command injection. A crafted link can trigger a popup asking whether the user wants to run MobaXterm to handle the link. If accepted, another popup appear...Show more |
In readArgumentList of zygote.java in Android 10, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. U...Show more |
Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution. |
Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution. |
1Adobe 2Acrobat Dc Acrobat Reader DcJun 17, 2026 Aug 20, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a command...Show more |
The web-based configuration interface of the TP-Link M7350 V3 with firmware before 190531 is affected by several post-authentication command injection vulnerabilities. |
NCSOFT Game Launcher, NC Launcher2 2.4.1.691 and earlier versions have a vulnerability in the custom protocol handler that could allow remote attacker to execute arbitrary command. User interaction is required to exploit...Show more |
2Fedoraproject Radare2Fedora Radare2Jun 17, 2026 Aug 7, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In radare2 before 3.7.0, a command injection vulnerability exists in bin_symbols() in libr/core/cbin.c. By using a crafted executable file, it's possible to execute arbitrary shell commands with the permissions of the vi...Show more |
cPanel before 64.0.21 allows demo accounts to execute Cpanel::SPFUI API commands (SEC-246). |
cPanel before 68.0.15 allows local root code execution via cpdavd (SEC-333). |
cPanel before 11.54.0.4 allows certain file-chmod operations in scripts/secureit (SEC-82). |
cPanel before 11.54.0.4 allows code execution in the context of shared users via JSON-API (SEC-76). |
2Cimg Debian2Cimg Library Debian LinuxJun 17, 2026 Jul 25, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 CImg The CImg Library v.2.3.3 and earlier is affected by: command injection. The impact is: RCE. The component is: load_network() function. The attack vector is: Loading an image from a user-controllable url can lead to...Show more |
Adobe Campaign Classic version 18.10.5-8984 and earlier versions have a Command injection vulnerability. Successful exploitation could lead to Arbitrary Code Execution in the context of the current user. |
1Automattic 1Camptix Event Ticketing Nov 21, 2024 Jul 18, 2019 N/A· v4 7.5 HIGH· v3 5.1 MEDIUM· v2 The CampTix Event Ticketing plugin before 1.5 for WordPress allows CSV injection when the export tool is used. |
1Cisco 10Spa500ds Firmware Spa500s FirmwareSpa501g Firmware+7 moreJun 17, 2026 Jul 17, 2019 N/A· v4 6.6 MEDIUM· v3 4.6 MEDIUM· v2 A vulnerability in Cisco Small Business SPA500 Series IP Phones could allow a physically proximate attacker to execute arbitrary commands on the device. The vulnerability is due to improper input validation in the device...Show more |
1Linksys 2Re6300 Firmware Re6400 FirmwareJun 17, 2026 Jul 17, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Unsanitized user input in the web interface for Linksys WiFi extender products (RE6400 and RE6300 through 1.2.04.022) allows for remote command execution. An attacker can access system OS configurations and commands that...Show more |
Command Injection in EdgeMAX EdgeSwitch prior to 1.8.2 allow an Admin user to execute commands as root. |
1Cisco 1Enterprise Nfv Infrastructure Software Jun 17, 2026 Jul 6, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system (OS) of an affected device as root. Th...Show more |