CWE-77
3,617 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
CVEs (3,617)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An attacker could inject commands to delete files and/or delete the contents of a file on CX-Supervisor (Versions 3.42 and prior) through a specially crafted project file. |
Imperva SecureSphere running v12.0.0.50 is vulnerable to local arbitrary code execution, escaping sealed-mode. |
Imperva SecureSphere gateway (GW) running v13, for both pre-First Time Login or post-First Time Login (FTL), if the attacker knows the basic authentication passwords, the GW may be vulnerable to RCE through specially cra...Show more |
Insufficient data validation in crosh could lead to a command injection under chronos privileges in Networking in Google Chrome on Chrome OS prior to 61.0.3163.113 allowed a local attacker to execute arbitrary code via a...Show more |
1Microsoft 5Excel Viewer Internet ExplorerOffice+2 moreJun 17, 2026 Jan 8, 2019 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Office Word Vie...Show more |
1Xerox 10Altalink B8045 Firmware Altalink B8055 FirmwareAltalink B8065 Firmware+7 moreNov 21, 2024 Jan 3, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The web application on Xerox AltaLink B80xx before 100.008.028.05200, C8030/C8035 before 100.001.028.05200, C8045/C8055 before 100.002.028.05200, and C8070 before 100.003.028.05200 allows unauthenticated command injectio...Show more |
FreeSWITCH through 1.8.2, when mod_xml_rpc is enabled, allows remote attackers to execute arbitrary commands via the api/system or txtapi/system (or api/bg_system or txtapi/bg_system) query string on TCP port 8080, as de...Show more |
Command Injection vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2.6 build 20180829 and earlier versions could allow remote attackers to run arbitrary commands on the...Show more |
A system command injection vulnerability in zyshclient in ZyXEL NSA325 V2 version 4.81 allows attackers to execute system commands via the web application API. |
1Apex Publish Static Files Project 1Apex Publish Static Files Nov 21, 2024 Oct 30, 2018 N/A· v4 10.0 CRITICAL· v3 10.0 HIGH· v2 A command injection vulnerability in the apex-publish-static-files npm module version <2.0.1 which allows arbitrary shell command execution through a maliciously crafted argument. |
A command injection vulnerability in libnmapp package for versions <0.4.16 allows arbitrary commands to be executed via arguments to the range options. |
3Debian RedhatZmanda3Amanda Debian LinuxEnterprise LinuxNov 21, 2024 Oct 24, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. The "runtar" setuid root binary does not check for additional arguments supplied after --create, allo...Show more |
1Citrix 2Netscaler Sd Wan Sd WanNov 21, 2024 Oct 23, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A Command Injection issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4. |
1Redhat 5Ceph Iscsi Cli Ceph StorageEnterprise Linux Desktop+2 moreNov 21, 2024 Oct 9, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 It was found that ceph-isci-cli package as shipped by Red Hat Ceph Storage 2 and 3 is using python-werkzeug in debug shell mode. This is done by setting debug=True in file /usr/bin/rbd-target-api provided by ceph-isci-cl...Show more |
A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to execute commands on the underlying Linux shell of an affected device with root privileges. The vulnerability exis...Show more |
A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to execute commands on the underlying Linux shell of an affected device with root privileges. The vulnerability exis...Show more |
1Cisco 1Cloud Services Platform 2100 Firmware Nov 21, 2024 Oct 5, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A vulnerability in the web-based management interface of Cisco Cloud Services Platform 2100 could allow an authenticated, remote attacker to perform command injection. The vulnerability is due to insufficient input valid...Show more |
1Cisco 8Vbond Orchestrator Vedge 1000 FirmwareVedge 100 Firmware+5 moreNov 21, 2024 Oct 5, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A vulnerability in the command-line interface (CLI) in the Cisco SD-WAN Solution could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges. The vulnerability is due...Show more |
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an authenticated, remote attacker to inject and execute arbitrary commands with root privileges o...Show more |
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an authenticated, remote attacker to inject and execute arbitrary commands with root privileges o...Show more |