← Back
CWE-77

3,794 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

JSON object

Loading...

CVEs (3,794)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Pacemaker/corosync Configuration System Project
1Pacemaker/corosync Configuration System
May 6, 2026
Sep 3, 2015
N/A· v4
N/A· v3
8.5 HIGH· v2
The pcsd web UI in PCS 0.9.139 and earlier allows remote authenticated users to execute arbitrary commands via "escape characters" in a URL.
2Bittorrent
Utorrent
2Bittorrent
Utorrent
May 6, 2026
Aug 13, 2015
N/A· v4
N/A· v3
9.3 HIGH· v2
BitTorrent and uTorrent allow remote attackers to inject command line parameters and execute arbitrary commands via a crafted URL using the (1) bittorrent or (2) magnet protocol.
1Citrix
2Netscaler Application Delivery Controller Firmware
Netscaler Gateway Firmware
May 6, 2026
Jul 16, 2015
N/A· v4
N/A· v3
9.0 HIGH· v2
The Management Interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.1 before 10.1.132.8, 10.5 before Build 56.15, and 10.5.e before Build 56.1505.e allows remote authenticated user...Show more
The Management Interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.1 before 10.1.132.8, 10.5 before Build 56.15, and 10.5.e before Build 56.1505.e allows remote authenticated users to execute arbitrary shell commands via shell metacharacters in the filter parameter to rapi/ipsec_logs.Show less
1Centreon
1Centreon
May 6, 2026
Jul 14, 2015
N/A· v4
N/A· v3
6.5 MEDIUM· v2
The escape_command function in include/Administration/corePerformance/getStats.php in Centreon (formerly Merethis Centreon) 2.5.4 and earlier (fixed in Centreon 19.10.0) uses an incorrect regular expression, which allows...Show more
The escape_command function in include/Administration/corePerformance/getStats.php in Centreon (formerly Merethis Centreon) 2.5.4 and earlier (fixed in Centreon 19.10.0) uses an incorrect regular expression, which allows remote authenticated users to execute arbitrary commands via shell metacharacters in the ns_id parameter.Show less
1Watchguard
1Xcs
May 6, 2026
Jul 8, 2015
N/A· v4
N/A· v3
6.5 MEDIUM· v2
Watchguard XCS 9.2 and 10.0 before build 150522 allow remote authenticated users to execute arbitrary commands via shell metacharacters in the id parameter to ADMIN/mailqueue.spl.
1Emc
1Isilon Onefs
May 6, 2026
Jul 4, 2015
N/A· v4
N/A· v3
9.0 HIGH· v2
The log-gather implementation in the web administration interface in EMC Isilon OneFS 6.5.x.x through 7.1.1.x before 7.1.1.5 and 7.2.0.x before 7.2.0.2 allows remote authenticated users to execute arbitrary commands with...Show more
The log-gather implementation in the web administration interface in EMC Isilon OneFS 6.5.x.x through 7.1.1.x before 7.1.1.5 and 7.2.0.x before 7.2.0.2 allows remote authenticated users to execute arbitrary commands with root privileges via unspecified vectors.Show less
1Apple
1Mac Os X
May 6, 2026
Jul 3, 2015
N/A· v4
N/A· v3
4.4 MEDIUM· v2
Spotlight in Apple OS X before 10.10.4 allows attackers to execute arbitrary commands via a crafted name of a photo file within the local photo library.
1Apple
1Mac Os X
May 6, 2026
Jul 3, 2015
N/A· v4
N/A· v3
7.2 HIGH· v2
AppleThunderboltEDMService in Apple OS X before 10.10.4 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified Thunderbolt commands.
1Ibm
1Tivoli Storage Manager Fastback
May 6, 2026
Jun 30, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
The server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to execute arbitrary commands via unspecified vectors, a different vulnerability than CVE-2015-1938.
1Ibm
1Tivoli Storage Manager Fastback
May 6, 2026
Jun 30, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
The server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to execute arbitrary commands with SYSTEM privileges via unspecified vectors.
1Ibm
1Tivoli Storage Manager Fastback
May 6, 2026
Jun 30, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
The server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to execute arbitrary commands via unspecified vectors, a different vulnerability than CVE-2015-1986.
1Xcloner
1Xcloner
May 6, 2026
Jun 17, 2015
N/A· v4
N/A· v3
6.5 MEDIUM· v2
cloner.functions.php in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to execute arbitrary commands via a file containing filenames with shell metacharacters, as demonstrated by using the backu...Show more
cloner.functions.php in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to execute arbitrary commands via a file containing filenames with shell metacharacters, as demonstrated by using the backup comments feature to create the file.Show less
2Canonical
Module Signature Project
2Module Signature
Ubuntu Linux
May 6, 2026
May 19, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
Module::Signature before 0.74 allows remote attackers to execute arbitrary shell commands via a crafted SIGNATURE file which is not properly handled when generating checksums from a signed manifest.
1Emc
1Autostart
May 6, 2026
May 7, 2015
N/A· v4
N/A· v3
9.3 HIGH· v2
ftagent.exe in EMC AutoStart 5.4.x and 5.5.x before 5.5.0.508 HF4 allows remote attackers to execute arbitrary commands via crafted packets.
1Bittorrent
1Sync
May 6, 2026
Apr 13, 2015
N/A· v4
N/A· v3
9.3 HIGH· v2
BitTorrent Sync allows remote attackers to execute arbitrary commands via a crafted btsync: link.
1Apache
1Cassandra
May 6, 2026
Apr 3, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
The default configuration in Apache Cassandra 1.2.0 through 1.2.19, 2.0.0 through 2.0.13, and 2.1.0 through 2.1.3 binds an unauthenticated JMX/RMI interface to all network interfaces, which allows remote attackers to exe...Show more
The default configuration in Apache Cassandra 1.2.0 through 1.2.19, 2.0.0 through 2.0.13, and 2.1.0 through 2.1.3 binds an unauthenticated JMX/RMI interface to all network interfaces, which allows remote attackers to execute arbitrary Java code via an RMI request.Show less
2Fedoraproject
Selinux
2Fedora
Setroubleshoot
May 6, 2026
Mar 30, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
The get_rpm_nvr_by_file_path_temporary function in util.py in setroubleshoot before 3.2.22 allows remote attackers to execute arbitrary commands via shell metacharacters in a file name.
1Websense
2Triton
V Series Appliances
May 6, 2026
Mar 26, 2015
N/A· v4
N/A· v3
6.5 MEDIUM· v2
The network diagnostics tool (CommandLineServlet) in the Appliance Manager command line utility (CLU) in Websense TRITON 7.8.3 and V-Series appliances before 7.8.4 Hotfix 02 allows remote authenticated users to execute a...Show more
The network diagnostics tool (CommandLineServlet) in the Appliance Manager command line utility (CLU) in Websense TRITON 7.8.3 and V-Series appliances before 7.8.4 Hotfix 02 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the "second" parameter of a command, as demonstrated by the Destination parameter in the ping command.Show less
2Canonical
Linuxfoundation
2Cups Filters
Ubuntu Linux
May 6, 2026
Mar 24, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
The remove_bad_chars function in utils/cups-browsed.c in cups-filters before 1.0.66 allows remote IPP printers to execute arbitrary commands via consecutive shell metacharacters in the (1) model or (2) PDL. NOTE: this vu...Show more
The remove_bad_chars function in utils/cups-browsed.c in cups-filters before 1.0.66 allows remote IPP printers to execute arbitrary commands via consecutive shell metacharacters in the (1) model or (2) PDL. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2707.Show less
3Fedoraproject
OpensuseSuse
3Fedora
OpensuseOpensuse Osc
May 6, 2026
Mar 16, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
osc before 0.151.0 allows remote attackers to execute arbitrary commands via shell metacharacters in a _service file.