CWE-77
3,800 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
CVEs (3,800)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A vulnerability in a Virtualization Manager (VMAN) related CLI command of Cisco IOS XE Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying Linux operating system with a p...Show more |
1Cisco 3Cloud Services Router 1000v Firmware Integrated Services Virtual Router FirmwareIosJun 17, 2026 Sep 25, 2019 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands with elevated privileges on the affected device. For more infor...Show more |
Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands with elevated privileges on the affected device. For more infor...Show more |
In WebAccess versions 8.4.1 and prior, multiple command injection vulnerabilities are caused by a lack of proper validation of user-supplied data and may allow arbitrary file deletion and remote code execution. |
In MobaXterm 11.1 and 12.1, the protocol handler is vulnerable to command injection. A crafted link can trigger a popup asking whether the user wants to run MobaXterm to handle the link. If accepted, another popup appear...Show more |
In readArgumentList of zygote.java in Android 10, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. U...Show more |
Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution. |
Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution. |
1Adobe 2Acrobat Dc Acrobat Reader DcJun 17, 2026 Aug 20, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Adobe Acrobat and Reader versions 2019.012.20035 and earlier, 2019.012.20035 and earlier, 2017.011.30142 and earlier, 2017.011.30143 and earlier, 2015.006.30497 and earlier, and 2015.006.30498 and earlier have a command...Show more |
The web-based configuration interface of the TP-Link M7350 V3 with firmware before 190531 is affected by several post-authentication command injection vulnerabilities. |
NCSOFT Game Launcher, NC Launcher2 2.4.1.691 and earlier versions have a vulnerability in the custom protocol handler that could allow remote attacker to execute arbitrary command. User interaction is required to exploit...Show more |
2Fedoraproject Radare2Fedora Radare2Jun 17, 2026 Aug 7, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In radare2 before 3.7.0, a command injection vulnerability exists in bin_symbols() in libr/core/cbin.c. By using a crafted executable file, it's possible to execute arbitrary shell commands with the permissions of the vi...Show more |
cPanel before 64.0.21 allows demo accounts to execute Cpanel::SPFUI API commands (SEC-246). |
cPanel before 68.0.15 allows local root code execution via cpdavd (SEC-333). |
cPanel before 11.54.0.4 allows certain file-chmod operations in scripts/secureit (SEC-82). |
cPanel before 11.54.0.4 allows code execution in the context of shared users via JSON-API (SEC-76). |
2Cimg Debian2Cimg Library Debian LinuxJun 17, 2026 Jul 25, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 CImg The CImg Library v.2.3.3 and earlier is affected by: command injection. The impact is: RCE. The component is: load_network() function. The attack vector is: Loading an image from a user-controllable url can lead to...Show more |
Adobe Campaign Classic version 18.10.5-8984 and earlier versions have a Command injection vulnerability. Successful exploitation could lead to Arbitrary Code Execution in the context of the current user. |
1Automattic 1Camptix Event Ticketing Nov 21, 2024 Jul 18, 2019 N/A· v4 7.5 HIGH· v3 5.1 MEDIUM· v2 The CampTix Event Ticketing plugin before 1.5 for WordPress allows CSV injection when the export tool is used. |
1Cisco 10Spa500ds Firmware Spa500s FirmwareSpa501g Firmware+7 moreJun 17, 2026 Jul 17, 2019 N/A· v4 6.6 MEDIUM· v3 4.6 MEDIUM· v2 A vulnerability in Cisco Small Business SPA500 Series IP Phones could allow a physically proximate attacker to execute arbitrary commands on the device. The vulnerability is due to improper input validation in the device...Show more |