CWE-77
3,617 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
CVEs (3,617)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Asus 7Ea N66 Firmware Rp Ac52 FirmwareRp Ac56 Firmware+4 moreNov 21, 2024 Jul 13, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A command injection vulnerability exists in apply.cgi on the ASUS RP-AC52 access point, firmware version 1.0.1.1s and possibly earlier, web interface specifically in the action_script parameter. The action_script paramet...Show more |
1Microsoft 1Wireless Display Adapter Firmware Jun 17, 2026 Jul 11, 2018 N/A· v4 5.5 MEDIUM· v3 5.2 MEDIUM· v2 A command injection vulnerability exists in the Microsoft Wireless Display Adapter (MWDA) when the Microsoft Wireless Display Adapter does not properly manage user input, aka "Microsoft Wireless Display Adapter Command I...Show more |
1Schneider Electric 1U.motion Builder Jun 17, 2026 Jul 3, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Schneider Electric U.motion Builder software versions prior to v1.3.4, a remote command injection allows authentication bypass. |
1Dell 3Idrac7 Firmware Idrac8 FirmwareIdrac9 FirmwareNov 21, 2024 Jul 2, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Dell EMC iDRAC7/iDRAC8, versions prior to 2.60.60.60, and iDRAC9 versions prior to 3.21.21.21 contain a command injection vulnerability in the SNMP agent. A remote authenticated malicious iDRAC user with configuration pr...Show more |
1Dell 2Idrac6 Modular Idrac6 MonolithicNov 21, 2024 Jul 2, 2018 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 The web-based diagnostics console in Dell EMC iDRAC6 (Monolithic versions prior to 2.91 and Modular all versions) contains a command injection vulnerability. A remote authenticated malicious iDRAC user with access to the...Show more |
1Microfocus 1Secure Messaging Gateway Nov 21, 2024 Jun 29, 2018 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 An OS command injection vulnerability in the web administration component of Micro Focus Secure Messaging Gateway (SMG) allows a remote attacker authenticated as a privileged user to execute arbitrary OS commands on the...Show more |
Command injection vulnerability in LDAP Server in QNAP QTS 4.2.6 build 20171208, QTS 4.3.3 build 20180402, QTS 4.3.4 build 20180413 and their earlier versions could allow remote attackers to run arbitrary commands or ins...Show more |
The version control adapters component of TIBCO Data Virtualization (formerly known as Cisco Information Server) contains vulnerabilities that may allow for arbitrary command execution. Affected releases are TIBCO Data V...Show more |
Missing escaping of ESSID values in sysconfig of SUSE Linux Enterprise allows attackers controlling an access point to cause execute arbitrary code. Affected releases are sysconfig prior to 0.83.7-2.1. |
2Mdadm Project Opensuse2Mdadm OpensuseNov 21, 2024 Jun 8, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The mdcheck script of the mdadm package for openSUSE 13.2 prior to version 3.3.1-5.14.1 does not properly sanitize device names, which allows local attackers to execute arbitrary commands as root. |
Command injection vulnerability in EZ-Internet in Synology Router Manager (SRM) before 1.1.6-6931 allows remote authenticated users to execute arbitrary command via the username parameter. |
Command injection vulnerability in EZ-Internet in Synology DiskStation Manager (DSM) before 6.2-23739 allows remote authenticated users to execute arbitrary command via the username parameter. |
dns-sync is a sync/blocking dns resolver. If untrusted user input is allowed into the resolve() method then command injection is possible. |
1Pdfinfojs Project 1Pdfinfojs Nov 21, 2024 Jun 1, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The pdfinfojs NPM module versions <= 0.3.6 has a command injection vulnerability that allows an attacker to execute arbitrary commands on the victim's machine. |
sudo before version 1.8.18p1 is vulnerable to a bypass in the sudo noexec restriction if application run via sudo executed wordexp() C library function with a user supplied argument. A local user permitted to run such ap...Show more |
2Fedoraproject Redhat7Enterprise Linux Enterprise Linux DesktopEnterprise Linux Server+4 moreNov 21, 2024 May 17, 2018 N/A· v4 7.5 HIGH· v3 7.9 HIGH· v2 DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in the NetworkManager integration script included in the DHCP client. A malicious DHCP server, or an at...Show more |
1Cisco 1Network Functions Virtualization Infrastructure Nov 21, 2024 May 17, 2018 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, high-privileged, local attacker to perform a command injection attack. The vulnerability is due to insuffic...Show more |
1Tinywebgallery 1Wordpress Flash Uploader Nov 21, 2024 Apr 25, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The WordPress Flash Uploader plugin before 3.1.3 for WordPress allows remote attackers to execute arbitrary commands via vectors related to invalid characters in image_magic_path. |
An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can allow for a user t...Show more |
An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can allow for a user t...Show more |