CWE-77
3,617 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
CVEs (3,617)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Net Ping External Project 1Net Ping External May 13, 2026 Nov 7, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The Net::Ping::External extension through 0.15 for Perl does not properly sanitize arguments (e.g., invalid hostnames) containing shell metacharacters before use of backticks in External.pm, allowing for shell command in...Show more |
1Meetcircle 1Circle With Disney Firmware May 13, 2026 Nov 7, 2017 N/A· v4 6.5 MEDIUM· v3 6.1 MEDIUM· v2 An exploitable vulnerability exists in the WiFi Channel parsing of Circle with Disney running firmware 2.0.1. A specially crafted SSID can cause the device to execute arbitrary sed commands. An attacker needs to setup an...Show more |
1Cisco 1Firepower Extensible Operating System May 13, 2026 Nov 2, 2017 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A vulnerability in the Smart Licensing Manager service of the Cisco Firepower 4100 Series Next-Generation Firewall (NGFW) and Firepower 9300 Security Appliance could allow an authenticated, remote attacker to inject arbi...Show more |
The get_login_ip_config_file function in Eyou Mail System before 3.6 allows remote attackers to execute arbitrary commands via shell metacharacters in the domain parameter to admin/domain/ip_login_set/d_ip_login_get.php. |
1Node Printer Project 1Node Printer May 13, 2026 Oct 23, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The printDirect function in lib/printer.js in the node-printer module 0.0.1 and earlier for Node.js allows remote attackers to execute arbitrary commands via unspecified characters in the lpr command. |
1Codem Transcode Project 1Codem Transcode May 13, 2026 Oct 23, 2017 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 The codem-transcode module before 0.5.0 for Node.js, when ffprobe is enabled, allows remote attackers to execute arbitrary commands via a POST request to /probe. |
1Form Manager Project 1Form Manager May 13, 2026 Oct 17, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Eval injection vulnerability in the fm_saveHelperGatherItems function in ajax.php in the Form Manager plugin before 1.7.3 for WordPress allows remote attackers to execute arbitrary code via unspecified vectors. |
The web administrative portal in Zhone zNID GPON 2426A before S3.0.501 allows remote attackers to execute arbitrary commands via shell metacharacters in the ipAddr parameter to zhnping.cmd. |
Certain combinations of Junos OS CLI commands and arguments have been found to be exploitable in a way that can allow unauthorized access to the operating system. This may allow any user with permissions to run these CLI...Show more |
1Seagate 1Blackarmor Nas 220 Firmware May 13, 2026 Oct 11, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Seagate BlackArmor NAS devices with firmware sg2000-2000.1331 allow remote attackers to execute arbitrary commands via shell metacharacters in the ip parameter to backupmgt/getAlias.php. |
UI-Dialog 1.09 and earlier allows remote attackers to execute arbitrary commands. |
QNAP discovered a number of command injection vulnerabilities found in Music Station versions 4.8.6 (for QTS 4.2.x), 5.0.7 (for QTS 4.3.x), and earlier. If exploited, these vulnerabilities may allow a remote attacker to...Show more |
1Huawei 10Fusionserver Ch121 V3 Fusionserver Ch220 V3Fusionserver Ch222 V3+7 moreMay 13, 2026 Oct 3, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The login page of the server on Huawei FusionServer rack servers RH2288 V3 with software before V100R003C00SPC603, RH2288H V3 with software before V100R003C00SPC503, XH628 V3 with software before V100R003C00SPC602, RH128...Show more |
Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0013 allows local users to submit commands to the System Update service (SUService.exe) and gain privileges by launching signed Lenovo executables. |
1Ibm 3Security Identity Governance And Intelligence Security Identity ManagerSecurity Privileged Identity ManagerMay 13, 2026 Sep 28, 2017 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 IBM Security Identity Manager Virtual Appliance 6.0 and 7.0 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this...Show more |
2Devscripts Devel Team Fedoraproject2Devscripts FedoraMay 13, 2026 Sep 25, 2017 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 scripts/licensecheck.pl in devscripts before 2.15.7 allows local users to execute arbitrary shell commands. |
Proxy command injection vulnerabilities in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allow remote attackers to execute arbitrary code on vulnerable installations. |
1Ibm 1Maximo Asset Management May 13, 2026 Sep 12, 2017 N/A· v4 5.5 MEDIUM· v3 6.0 MEDIUM· v2 IBM Maximo Asset Management 7.5 and 7.6 could allow an authenticated user to inject commands into work orders that could be executed by another user that downloads the affected file. IBM X-Force ID: 126538. |
A vulnerability in the CLI command-parsing code of Cisco Meeting Server could allow an authenticated, local attacker to perform command injection and escalate their privileges to root. The attacker must first authenticat...Show more |
The help window in Epicor CRS Retail Store before 3.2.03.01.008 allows local users to execute arbitrary code by injecting Javascript into the window source to create a button that spawns a command shell. |