CWE-77
3,617 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
CVEs (3,617)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Corega CG-WLBARGL devices allow remote authenticated users to execute arbitrary commands via unspecified vectors. |
1Cisco 3Network Analysis Module Prime Network Analysis Module SoftwarePrime Virtual Network Analysis Module SoftwareMay 6, 2026 Jun 3, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Cisco Prime Network Analysis Module (NAM) before 6.1(1) patch.6.1-2-final and 6.2.x before 6.2(1) and Prime Virtual Network Analysis Module (vNAM) before 6.1(1) patch.6.1-2-final and 6.2.x before 6.2(1) allow remote atta...Show more |
2Debian Tardiff Project2Debian Linux TardiffMay 6, 2026 May 6, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Cool Projects TarDiff allows remote attackers to execute arbitrary commands via shell metacharacters in the name of a (1) tar file or (2) file within a tar file. |
2Apache Oracle2Siebel E Billing StrutsMay 6, 2026 Apr 26, 2016 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, allow remote attackers to execute arbitrary code via method: prefix, related to chained expressions. |
1Systech 1Syslink Sl 1000 Modular Gateway Firmware May 6, 2026 Apr 25, 2016 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 flu.cgi in the web interface on SysLINK SL-1000 Machine-to-Machine (M2M) Modular Gateway devices with firmware before 01A.8 allows remote authenticated users to execute arbitrary commands via the 5066 (aka dnsmasq) param...Show more |
The validateAdminConfig handler in the Analytics Management Console in HPE Vertica 7.0.x before 7.0.2.12, 7.1.x before 7.1.2-12, and 7.2.x before 7.2.2-1 allows remote attackers to execute arbitrary commands via the mcPo...Show more |
xymond in Xymon 4.1.x, 4.2.x, and 4.3.x before 4.3.25 allow remote authenticated users to execute arbitrary commands via shell metacharacters in the adduser_name argument in (1) web/useradm.c or (2) web/chpasswd.c. |
1Apache 2Directory Studio Ldap StudioMay 6, 2026 Apr 11, 2016 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 The CSV export in Apache LDAP Studio and Apache Directory Studio before 2.0.0-M10 does not properly escape field values, which might allow attackers to execute arbitrary commands by leveraging a crafted LDAP entry that i...Show more |
1Sonicwall 3Analyzer Global Management SystemUma Em5000 FirmwareMay 6, 2026 Feb 17, 2016 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The cliserver implementation in Dell SonicWALL GMS, Analyzer, and UMA EM5000 7.2, 8.0, and 8.1 before Hotfix 168056 allows remote attackers to deserialize and execute arbitrary Java code via crafted XML data. |
1Sonicwall 3Analyzer Global Management SystemUma Em5000 FirmwareMay 6, 2026 Feb 17, 2016 N/A· v4 9.9 CRITICAL· v3 9.0 HIGH· v2 The GMS ViewPoint (GMSVP) web application in Dell SonicWALL GMS, Analyzer, and UMA EM5000 7.2, 8.0, and 8.1 before Hotfix 168056 allows remote authenticated users to execute arbitrary commands via vectors related to conf...Show more |
General Electric (GE) Industrial Solutions UPS SNMP/Web Adapter devices with firmware before 4.8 allow remote authenticated users to execute arbitrary commands via unspecified vectors. |
1Colorscore Project 1Colorscore May 6, 2026 Jan 8, 2016 N/A· v4 10.0 CRITICAL· v3 10.0 HIGH· v2 The initialize method in the Histogram class in lib/colorscore/histogram.rb in the colorscore gem before 0.0.5 for Ruby allows context-dependent attackers to execute arbitrary code via shell metacharacters in the (1) ima...Show more |
The portal in IBM Tivoli Monitoring (ITM) 6.2.2 through FP9, 6.2.3 through FP5, and 6.3.0 before FP7 allows remote authenticated users to execute arbitrary commands by leveraging Take Action view authority and providing...Show more |
Bluetooth in Android before 5.1.1 LMY48X and 6.0 before 2015-11-01 allows attackers to send commands to a debugging port, and consequently gain privileges, via a crafted application, as demonstrated by obtaining Signatur...Show more |
1Ibm 2Integration Bus Websphere Message BrokerMay 6, 2026 Oct 26, 2015 N/A· v4 N/A· v3 3.2 LOW· v2 IBM WebSphere Message Broker 8 before 8.0.0.6 and Integration Bus 9 before 9.0.0.4 do not check authorization for MQSISTARTMSGFLOW and MQSISTOPMSGFLOW commands, which allows local users to bypass intended access restrict...Show more |
1Ibm 2General Parallel File System Spectrum ScaleMay 6, 2026 Oct 26, 2015 N/A· v4 N/A· v3 7.2 HIGH· v2 IBM General Parallel File System (GPFS) 3.5.x before 3.5.0.27 and 4.1.x before 4.1.1.2 and Spectrum Scale 4.1.1.x before 4.1.1.2 allow local users to obtain root privileges for command execution via unspecified vectors. |
SolarWinds Log and Event Manager (LEM) allows remote attackers to execute arbitrary commands on managed computers via a request to services/messagebroker/nonsecurestreamingamf involving the traceroute functionality. |
1Ibm 1Qradar Security Information And Event Manager May 6, 2026 Oct 4, 2015 N/A· v4 N/A· v3 9.0 HIGH· v2 IBM QRadar SIEM 7.1 MR2 before Patch 11 IF02 and 7.2.x before 7.2.5 Patch 4 allows remote authenticated users to execute arbitrary commands with root privileges by leveraging admin access. |
1Ibm 1Qradar Security Information And Event Manager May 6, 2026 Oct 4, 2015 N/A· v4 N/A· v3 9.0 HIGH· v2 The xmlrpc.cgi Webmin script in IBM QRadar SIEM 7.1 MR2 before Patch 11 IF02 and 7.2.x before 7.2.5 Patch 4 allows remote authenticated users to execute arbitrary commands with root privileges via unspecified vectors. |
Endian Firewall before 3.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) NEW_PASSWORD_1 or (2) NEW_PASSWORD_2 parameter to cgi-bin/chpasswd.cgi. |