← Back
CWE-77

3,617 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

JSON object

Loading...

CVEs (3,617)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Net Ping External Project
1Net Ping External
May 13, 2026
Nov 7, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The Net::Ping::External extension through 0.15 for Perl does not properly sanitize arguments (e.g., invalid hostnames) containing shell metacharacters before use of backticks in External.pm, allowing for shell command in...Show more
The Net::Ping::External extension through 0.15 for Perl does not properly sanitize arguments (e.g., invalid hostnames) containing shell metacharacters before use of backticks in External.pm, allowing for shell command injection and arbitrary command execution if untrusted input is used.Show less
1Meetcircle
1Circle With Disney Firmware
May 13, 2026
Nov 7, 2017
N/A· v4
6.5 MEDIUM· v3
6.1 MEDIUM· v2
An exploitable vulnerability exists in the WiFi Channel parsing of Circle with Disney running firmware 2.0.1. A specially crafted SSID can cause the device to execute arbitrary sed commands. An attacker needs to setup an...Show more
An exploitable vulnerability exists in the WiFi Channel parsing of Circle with Disney running firmware 2.0.1. A specially crafted SSID can cause the device to execute arbitrary sed commands. An attacker needs to setup an access point reachable by the device to trigger this vulnerability.Show less
1Cisco
1Firepower Extensible Operating System
May 13, 2026
Nov 2, 2017
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A vulnerability in the Smart Licensing Manager service of the Cisco Firepower 4100 Series Next-Generation Firewall (NGFW) and Firepower 9300 Security Appliance could allow an authenticated, remote attacker to inject arbi...Show more
A vulnerability in the Smart Licensing Manager service of the Cisco Firepower 4100 Series Next-Generation Firewall (NGFW) and Firepower 9300 Security Appliance could allow an authenticated, remote attacker to inject arbitrary commands that could be executed with root privileges. The vulnerability is due to insufficient input validation of certain Smart Licensing configuration parameters. An authenticated attacker could exploit the vulnerability by configuring a malicious URL within the affected feature. A successful exploit could allow the attacker to execute arbitrary commands with root privileges. This vulnerability affects the following Cisco Firepower Security products running FX-OS code trains 1.1.3, 1.1.4, and 2.0.1 (versions 2.1.1, 2.2.1, and 2.2.2 are not affected): Firepower 4100 Series Next-Generation Firewall and Firepower 9300 Security Appliance. Cisco Bug IDs: CSCvb86863.Show less
1Eyou
1Eyou
May 13, 2026
Oct 24, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The get_login_ip_config_file function in Eyou Mail System before 3.6 allows remote attackers to execute arbitrary commands via shell metacharacters in the domain parameter to admin/domain/ip_login_set/d_ip_login_get.php.
1Node Printer Project
1Node Printer
May 13, 2026
Oct 23, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The printDirect function in lib/printer.js in the node-printer module 0.0.1 and earlier for Node.js allows remote attackers to execute arbitrary commands via unspecified characters in the lpr command.
1Codem Transcode Project
1Codem Transcode
May 13, 2026
Oct 23, 2017
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
The codem-transcode module before 0.5.0 for Node.js, when ffprobe is enabled, allows remote attackers to execute arbitrary commands via a POST request to /probe.
1Form Manager Project
1Form Manager
May 13, 2026
Oct 17, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Eval injection vulnerability in the fm_saveHelperGatherItems function in ajax.php in the Form Manager plugin before 1.7.3 for WordPress allows remote attackers to execute arbitrary code via unspecified vectors.
1Dasanzhone
1Znid 2426a Firmware
May 13, 2026
Oct 17, 2017
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
The web administrative portal in Zhone zNID GPON 2426A before S3.0.501 allows remote attackers to execute arbitrary commands via shell metacharacters in the ipAddr parameter to zhnping.cmd.
1Juniper
1Junos
May 13, 2026
Oct 13, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Certain combinations of Junos OS CLI commands and arguments have been found to be exploitable in a way that can allow unauthorized access to the operating system. This may allow any user with permissions to run these CLI...Show more
Certain combinations of Junos OS CLI commands and arguments have been found to be exploitable in a way that can allow unauthorized access to the operating system. This may allow any user with permissions to run these CLI commands the ability to achieve elevated privileges and gain complete control of the device. Affected releases are Juniper Networks Junos OS 11.4 prior to 11.4R13-S3; 12.1X46 prior to 12.1X46-D60; 12.1X47 prior to 12.1X47-D45; 12.3 prior to 12.3R12; 12.3X48 prior to 12.3X48-D35; 13.2 prior to 13.2R9; 13.3 prior to 13.3R4-S11, 13.3R9; 14.1 prior to 14.1R4-S12, 14.1R7; 14.1X53 prior to 14.1X53-D28, 14.1X53-D40; 14.1X55 prior to 14.1X55-D35; 14.2 prior to 14.2R3-S10, 14.2R4-S7, 14.2R5; 15.1 prior to 15.1F4, 15.1R3; 15.1X49 prior to 15.1X49-D60; 15.1X53 prior to 15.1X53-D57, 15.1X53-D70.Show less
1Seagate
1Blackarmor Nas 220 Firmware
May 13, 2026
Oct 11, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Seagate BlackArmor NAS devices with firmware sg2000-2000.1331 allow remote attackers to execute arbitrary commands via shell metacharacters in the ip parameter to backupmgt/getAlias.php.
1Cpan
1Ui\
May 13, 2026
Oct 10, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
UI-Dialog 1.09 and earlier allows remote attackers to execute arbitrary commands.
1Qnap
1Music Station
May 13, 2026
Oct 6, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
QNAP discovered a number of command injection vulnerabilities found in Music Station versions 4.8.6 (for QTS 4.2.x), 5.0.7 (for QTS 4.3.x), and earlier. If exploited, these vulnerabilities may allow a remote attacker to...Show more
QNAP discovered a number of command injection vulnerabilities found in Music Station versions 4.8.6 (for QTS 4.2.x), 5.0.7 (for QTS 4.3.x), and earlier. If exploited, these vulnerabilities may allow a remote attacker to run arbitrary commands on the NAS.Show less
1Huawei
10Fusionserver Ch121 V3
Fusionserver Ch220 V3Fusionserver Ch222 V3+7 more
May 13, 2026
Oct 3, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The login page of the server on Huawei FusionServer rack servers RH2288 V3 with software before V100R003C00SPC603, RH2288H V3 with software before V100R003C00SPC503, XH628 V3 with software before V100R003C00SPC602, RH128...Show more
The login page of the server on Huawei FusionServer rack servers RH2288 V3 with software before V100R003C00SPC603, RH2288H V3 with software before V100R003C00SPC503, XH628 V3 with software before V100R003C00SPC602, RH1288 V3 with software before V100R003C00SPC602, RH2288A V2 with software before V100R002C00SPC701, RH1288A V2 with software before V100R002C00SPC502, RH8100 V3 with software before V100R003C00SPC110, CH222 V3 with software before V100R001C00SPC161, CH220 V3 with software before V100R001C00SPC161, and CH121 V3 with software before V100R001C00SPC161 allows remote attackers to bypass access restrictions and enter commands via unspecified parameters, as demonstrated by a "user creation command."Show less
1Lenovo
1System Update
May 13, 2026
Oct 3, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0013 allows local users to submit commands to the System Update service (SUService.exe) and gain privileges by launching signed Lenovo executables.
1Ibm
3Security Identity Governance And Intelligence
Security Identity ManagerSecurity Privileged Identity Manager
May 13, 2026
Sep 28, 2017
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
IBM Security Identity Manager Virtual Appliance 6.0 and 7.0 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this...Show more
IBM Security Identity Manager Virtual Appliance 6.0 and 7.0 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 127394.Show less
2Devscripts Devel Team
Fedoraproject
2Devscripts
Fedora
May 13, 2026
Sep 25, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
scripts/licensecheck.pl in devscripts before 2.15.7 allows local users to execute arbitrary shell commands.
1Trendmicro
1Mobile Security
May 13, 2026
Sep 22, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Proxy command injection vulnerabilities in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allow remote attackers to execute arbitrary code on vulnerable installations.
1Ibm
1Maximo Asset Management
May 13, 2026
Sep 12, 2017
N/A· v4
5.5 MEDIUM· v3
6.0 MEDIUM· v2
IBM Maximo Asset Management 7.5 and 7.6 could allow an authenticated user to inject commands into work orders that could be executed by another user that downloads the affected file. IBM X-Force ID: 126538.
1Cisco
1Meeting Server
May 13, 2026
Sep 7, 2017
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
A vulnerability in the CLI command-parsing code of Cisco Meeting Server could allow an authenticated, local attacker to perform command injection and escalate their privileges to root. The attacker must first authenticat...Show more
A vulnerability in the CLI command-parsing code of Cisco Meeting Server could allow an authenticated, local attacker to perform command injection and escalate their privileges to root. The attacker must first authenticate to the application with valid administrator credentials. The vulnerability is due to insufficient validation of user-supplied input at the CLI for certain commands. An attacker could exploit this vulnerability by authenticating to the affected application and submitting a crafted CLI command for execution at the Cisco Meeting Server CLI. An exploit could allow the attacker to perform command injection and escalate their privilege level to root. Vulnerable Products: This vulnerability exists in Cisco Meeting Server software versions prior to and including 2.0, 2.1, and 2.2. Cisco Bug IDs: CSCvf53830.Show less
1Epicor
1Crs Retail Store
May 13, 2026
Sep 6, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
The help window in Epicor CRS Retail Store before 3.2.03.01.008 allows local users to execute arbitrary code by injecting Javascript into the window source to create a button that spawns a command shell.