CWE-77
3,617 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
CVEs (3,617)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Emerson 6Dl 8000 Remote Terminal Unit Dl 8000 Remote Terminal Unit FirmwareRoc 800 Remote Terminal Unit+3 moreMay 6, 2026 Dec 8, 2014 N/A· v4 N/A· v3 10.0 HIGH· v2 Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 and earlier allows remote attackers to execute arbitrary commands via a...Show more |
3Debian FedoraprojectLsyncd Project3Debian Linux FedoraLsyncdMay 6, 2026 Dec 5, 2014 N/A· v4 N/A· v3 7.5 HIGH· v2 default-rsyncssh.lua in Lsyncd 2.1.5 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a filename. |
Technicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers to execute arbitrary commands via shell metacharacters in the ping field (setobject_ip parameter). |
canto_curses/guibase.py in Canto Curses before 0.9.0 allows remote feed servers to execute arbitrary commands via shell metacharacters in a URL in a feed. |
The fetch_url function in usr.bin/ftp/fetch.c in tnftp, as used in NetBSD 5.1 through 5.1.4, 5.2 through 5.2.2, 6.0 through 6.0.6, and 6.1 through 6.1.5 allows remote attackers to execute arbitrary commands via a | (pipe...Show more |
2Apache Libreoffice2Libreoffice OpenofficeMay 6, 2026 Aug 26, 2014 N/A· v4 N/A· v3 9.3 HIGH· v2 Apache OpenOffice before 4.1.1 allows remote attackers to execute arbitrary commands and possibly have other unspecified impact via a crafted Calc spreadsheet. |
The generate_local_queue function in utils/cups-browsed.c in cups-browsed in cups-filters before 1.0.53 allows remote IPP printers to execute arbitrary commands via shell metacharacters in the host name. NOTE: this vuln...Show more |
The BWOCXRUN.BwocxrunCtrl.1 control contains a method named “CreateProcess.” This method contains validation to ensure an attacker cannot run arbitrary command lines. After validation, the values supplied in the HTML...Show more |
A setup script for fabric interconnect devices in Cisco Unified Computing System (UCS) allows remote attackers to execute arbitrary commands via invalid parameters, aka Bug ID CSCtg20790. |
8Apple DebianFedoraproject+5 more17Application Stack Debian LinuxEnterprise Linux Desktop+14 moreApr 21, 2026 May 11, 2012 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers...Show more |
4Canonical DebianExim+1 more4Debian Linux EximOpensuse+1 moreApr 21, 2026 Dec 14, 2010 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands, as demonstrated...Show more |
3Canonical FedoraprojectOracle3Fedora MysqlUbuntu LinuxApr 29, 2026 Jul 13, 2010 N/A· v4 N/A· v3 3.5 LOW· v2 MySQL before 5.1.48 allows remote authenticated users with alter database privileges to cause a denial of service (server crash and database loss) via an ALTER DATABASE command with a #mysql50# string followed by a . (do...Show more |
3Apache CanonicalDebian3Debian Linux OpenofficeUbuntu LinuxApr 29, 2026 Feb 16, 2010 N/A· v4 N/A· v3 9.3 HIGH· v2 OpenOffice.org (OOo) 2.0.4, 2.4.1, and 3.1.1 does not properly enforce Visual Basic for Applications (VBA) macro security settings, which allows remote attackers to run arbitrary macros via a crafted document. |
1Al Enterprise 1Omnipcx Enterprise Communication Server Apr 21, 2026 Sep 18, 2007 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the user parameter during a...Show more |
PHP remote file inclusion vulnerability in welcome.php in phpLDAPadmin 0.9.6 and 0.9.7 allows remote attackers to execute arbitrary PHP code via the custom_welcome_page parameter. |
1Hp 1Openview Network Node Manager Apr 16, 2026 Sep 2, 2005 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) node parameter to connectedNodes.ovpl, (2) cdpView.ovpl, (3) freeIPaddrs.ovpl, a...Show more |
webdist CGI program (webdist.cgi) in SGI IRIX allows remote attackers to execute arbitrary commands via shell metacharacters in the distloc parameter. |