CWE-77
3,617 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
CVEs (3,617)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's configuration utilities for adding (and detecting) Active Directory servers was vulnerable to remote command injection, aka NSWA-1314. |
Command injection vulnerability in Junos Space before 15.2R2 allows attackers to execute arbitrary code as a root user. |
Unquoted executable path vulnerability in Client Management and Gateway components in McAfee (now Intel Security) ePO Deep Command (eDC) 2.2 and 2.1 allows authenticated users to execute a command of their choice via dro...Show more |
A command-injection vulnerability exists in a web application on a custom-built GoAhead web server used on Foscam, Vstarcam, and multiple white-label IP camera models. The mail-sending form in the mail.htm page allows an...Show more |
1Festivaltts4r Project 1Festivaltts4r May 13, 2026 Mar 3, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The festivaltts4r gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a string to the (1) to_speech or (2) to_mp3 method in lib/festivaltts4r/festival4r.rb. |
The installPackage function in the installerHelper subcomponent in Libmacgpg in GPG Suite before 2015.06 allows local users to execute arbitrary commands with root privileges via shell metacharacters in the xmlPath argum...Show more |
1Dell 1Sonicwall Secure Remote Access Server May 13, 2026 Feb 22, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface. This vulnerability occurs in the 'viewcert' CGI (/cgi-bin/vi...Show more |
1Dell 1Sonicwall Secure Remote Access Server May 13, 2026 Feb 22, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface. This vulnerability occurs in the 'extensionsettings' CGI (/c...Show more |
1Dell 1Sonicwall Secure Remote Access Server May 13, 2026 Feb 22, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to two Remote Command Injection vulnerabilities in its web administrative interface. These vulnerabilities occur in the diagnostics CGI (/cgi...Show more |
An issue was discovered in Tesla Motors Model S automobile, all firmware versions before version 7.1 (2.36.31) with web browser functionality enabled. The vehicle's Gateway ECU is susceptible to commands that may allow a...Show more |
1Netcommwireless 1Hspa 3g10wve Firmware May 13, 2026 Feb 9, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 ping.cgi in NetCommWireless HSPA 3G10WVE wireless routers with firmware before 3G10WVE-L101-S306ETS-C01_R05 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the DIA_IPADDRESS pa...Show more |
1Sendquick 2Avera Sms Gateway Firmware Entera Sms Gateway FirmwareMay 13, 2026 Feb 5, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered on SendQuick Entera and Avera devices before 2HF16. Multiple Command Injection vulnerabilities allow attackers to execute arbitrary system commands. |
EMC Documentum D2 version 4.5 and EMC Documentum D2 version 4.6 has a DQL Injection Vulnerability that could potentially be exploited by malicious users to compromise the affected system. An authenticated low-privileged...Show more |
2Dell Emc3Recoverpoint Recoverpoint For Virtual MachinesRecoverpoint For Virtual MachinesJul 10, 2026 Feb 3, 2017 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 EMC RecoverPoint versions before 4.4.1.1 and EMC RecoverPoint for Virtual Machines versions before 5.0 are affected by multiple command injection vulnerabilities where a malicious administrator with configuration privile...Show more |
IBM Tivoli Endpoint Manager could allow a user under special circumstances to inject commands that would be executed with unnecessary higher privileges than expected. |
1Trendmicro 1Virtual Mobile Infrastructure May 13, 2026 Jan 30, 2017 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 The handle_certificate function in /vmi/manager/engine/management/commands/apns_worker.py in Trend Micro Virtual Mobile Infrastructure before 5.1 allows remote authenticated users to execute arbitrary commands via shell...Show more |
An issue was discovered on the D-Link DWR-932B router. qmiweb allows command injection with ` characters. |
The Sophos Web Appliance Remote / Secure Web Gateway server (version 4.2.1.3) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface. These vulnerabilities occur in MgrDiagnosticToo...Show more |
The Sophos Web Appliance (version 4.2.1.3) is vulnerable to two Remote Command Injection vulnerabilities affecting its web administrative interface. These vulnerabilities occur in the MgrReport.php (/controllers/MgrRepor...Show more |
2Debian Enlightenment2Debian Linux TerminologyMay 13, 2026 Jan 23, 2017 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Terminology 0.7.0 allows remote attackers to execute arbitrary commands via escape sequences that modify the window title and then are written to the terminal, a similar issue to CVE-2003-0063. |