← Back
CWE-77

3,617 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

JSON object

Loading...

CVEs (3,617)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Symantec
1Web Gateway
May 6, 2026
Sep 20, 2015
N/A· v4
N/A· v3
8.3 HIGH· v2
The management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allows remote authenticated users to execute arbitrary commands at boot time via unspecified vectors.
1Redhat
1Openshift
May 6, 2026
Sep 18, 2015
N/A· v4
N/A· v3
6.5 MEDIUM· v2
rubygem-openshift-origin-console in Red Hat OpenShift 2.2 allows remote authenticated users to execute arbitrary commands via a crafted request to the Broker.
1Synology
1Video Station
May 6, 2026
Sep 11, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
Synology Video Station before 1.5-0763 allows remote attackers to execute arbitrary shell commands via shell metacharacters in the subtitle_codepage parameter to subtitle.cgi.
1Pacemaker/corosync Configuration System Project
1Pacemaker/corosync Configuration System
May 6, 2026
Sep 3, 2015
N/A· v4
N/A· v3
8.5 HIGH· v2
The pcsd web UI in PCS 0.9.139 and earlier allows remote authenticated users to execute arbitrary commands via "escape characters" in a URL.
2Bittorrent
Utorrent
2Bittorrent
Utorrent
May 6, 2026
Aug 13, 2015
N/A· v4
N/A· v3
9.3 HIGH· v2
BitTorrent and uTorrent allow remote attackers to inject command line parameters and execute arbitrary commands via a crafted URL using the (1) bittorrent or (2) magnet protocol.
1Citrix
2Netscaler Application Delivery Controller Firmware
Netscaler Gateway Firmware
May 6, 2026
Jul 16, 2015
N/A· v4
N/A· v3
9.0 HIGH· v2
The Management Interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.1 before 10.1.132.8, 10.5 before Build 56.15, and 10.5.e before Build 56.1505.e allows remote authenticated user...Show more
The Management Interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.1 before 10.1.132.8, 10.5 before Build 56.15, and 10.5.e before Build 56.1505.e allows remote authenticated users to execute arbitrary shell commands via shell metacharacters in the filter parameter to rapi/ipsec_logs.Show less
1Centreon
1Centreon
May 6, 2026
Jul 14, 2015
N/A· v4
N/A· v3
6.5 MEDIUM· v2
The escape_command function in include/Administration/corePerformance/getStats.php in Centreon (formerly Merethis Centreon) 2.5.4 and earlier (fixed in Centreon 19.10.0) uses an incorrect regular expression, which allows...Show more
The escape_command function in include/Administration/corePerformance/getStats.php in Centreon (formerly Merethis Centreon) 2.5.4 and earlier (fixed in Centreon 19.10.0) uses an incorrect regular expression, which allows remote authenticated users to execute arbitrary commands via shell metacharacters in the ns_id parameter.Show less
1Watchguard
1Xcs
May 6, 2026
Jul 8, 2015
N/A· v4
N/A· v3
6.5 MEDIUM· v2
Watchguard XCS 9.2 and 10.0 before build 150522 allow remote authenticated users to execute arbitrary commands via shell metacharacters in the id parameter to ADMIN/mailqueue.spl.
1Emc
1Isilon Onefs
May 6, 2026
Jul 4, 2015
N/A· v4
N/A· v3
9.0 HIGH· v2
The log-gather implementation in the web administration interface in EMC Isilon OneFS 6.5.x.x through 7.1.1.x before 7.1.1.5 and 7.2.0.x before 7.2.0.2 allows remote authenticated users to execute arbitrary commands with...Show more
The log-gather implementation in the web administration interface in EMC Isilon OneFS 6.5.x.x through 7.1.1.x before 7.1.1.5 and 7.2.0.x before 7.2.0.2 allows remote authenticated users to execute arbitrary commands with root privileges via unspecified vectors.Show less
1Apple
1Mac Os X
May 6, 2026
Jul 3, 2015
N/A· v4
N/A· v3
4.4 MEDIUM· v2
Spotlight in Apple OS X before 10.10.4 allows attackers to execute arbitrary commands via a crafted name of a photo file within the local photo library.
1Apple
1Mac Os X
May 6, 2026
Jul 3, 2015
N/A· v4
N/A· v3
7.2 HIGH· v2
AppleThunderboltEDMService in Apple OS X before 10.10.4 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified Thunderbolt commands.
1Ibm
1Tivoli Storage Manager Fastback
May 6, 2026
Jun 30, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
The server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to execute arbitrary commands via unspecified vectors, a different vulnerability than CVE-2015-1938.
1Ibm
1Tivoli Storage Manager Fastback
May 6, 2026
Jun 30, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
The server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to execute arbitrary commands with SYSTEM privileges via unspecified vectors.
1Ibm
1Tivoli Storage Manager Fastback
May 6, 2026
Jun 30, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
The server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to execute arbitrary commands via unspecified vectors, a different vulnerability than CVE-2015-1986.
1Xcloner
1Xcloner
May 6, 2026
Jun 17, 2015
N/A· v4
N/A· v3
6.5 MEDIUM· v2
cloner.functions.php in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to execute arbitrary commands via a file containing filenames with shell metacharacters, as demonstrated by using the backu...Show more
cloner.functions.php in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to execute arbitrary commands via a file containing filenames with shell metacharacters, as demonstrated by using the backup comments feature to create the file.Show less
2Canonical
Module Signature Project
2Module Signature
Ubuntu Linux
May 6, 2026
May 19, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
Module::Signature before 0.74 allows remote attackers to execute arbitrary shell commands via a crafted SIGNATURE file which is not properly handled when generating checksums from a signed manifest.
1Emc
1Autostart
May 6, 2026
May 7, 2015
N/A· v4
N/A· v3
9.3 HIGH· v2
ftagent.exe in EMC AutoStart 5.4.x and 5.5.x before 5.5.0.508 HF4 allows remote attackers to execute arbitrary commands via crafted packets.
1Bittorrent
1Sync
May 6, 2026
Apr 13, 2015
N/A· v4
N/A· v3
9.3 HIGH· v2
BitTorrent Sync allows remote attackers to execute arbitrary commands via a crafted btsync: link.
1Apache
1Cassandra
May 6, 2026
Apr 3, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
The default configuration in Apache Cassandra 1.2.0 through 1.2.19, 2.0.0 through 2.0.13, and 2.1.0 through 2.1.3 binds an unauthenticated JMX/RMI interface to all network interfaces, which allows remote attackers to exe...Show more
The default configuration in Apache Cassandra 1.2.0 through 1.2.19, 2.0.0 through 2.0.13, and 2.1.0 through 2.1.3 binds an unauthenticated JMX/RMI interface to all network interfaces, which allows remote attackers to execute arbitrary Java code via an RMI request.Show less
2Fedoraproject
Selinux
2Fedora
Setroubleshoot
May 6, 2026
Mar 30, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
The get_rpm_nvr_by_file_path_temporary function in util.py in setroubleshoot before 3.2.22 allows remote attackers to execute arbitrary commands via shell metacharacters in a file name.