CWE-77
3,617 CVEs • Abstraction: Class • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
CVEs (3,617)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
orval generates type-safe JS clients (TypeScript) from any valid OpenAPI v3 or Swagger v2 specification. Prior to 7.18.0, the MCP server generation logic relies on string manipulation that incorporates the summary field...Show more |
1Sangfor 1Operation And Maintenance Security Management System Jun 17, 2026 Jan 10, 2026 5.5 MEDIUM· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability was identified in Sangfor Operation and Maintenance Management System up to 3.0.8. The affected element is the function SessionController of the file /isomp-protocol/protocol/session. Such manipulation of...Show more |
WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. Prior to version 0.2.5, there is a command injection vulnerability that allows authenticated users to inject stdio_conf...Show more |
OpenProject is an open-source, web-based project management software. For OpenProject version 16.6.1 and below, a registered administrator can execute arbitrary command by configuring sendmail binary path and sending a t...Show more |
1Sangfor 1Operation And Maintenance Security Management System Jun 17, 2026 Jan 9, 2026 8.9 HIGH· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A vulnerability was determined in Sangfor Operation and Maintenance Management System up to 3.0.8. Impacted is the function WriterHandle.getCmd of the file /isomp-protocol/protocol/getCmd. This manipulation of the argume...Show more |
1Sangfor 1Operation And Maintenance Management System Jun 17, 2026 Jan 9, 2026 8.9 HIGH· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A vulnerability was found in Sangfor Operation and Maintenance Management System up to 3.0.8. This issue affects some unknown processing of the file /isomp-protocol/protocol/getHis of the component HTTP POST Request Hand...Show more |
1Sangfor 1Operation And Maintenance Management System Jun 17, 2026 Jan 9, 2026 7.4 HIGH· v4 9.8 CRITICAL· v3 9.0 HIGH· v2 A vulnerability has been found in Sangfor Operation and Maintenance Management System up to 3.0.8. This vulnerability affects the function uploadCN of the file VersionController.java. The manipulation of the argument fil...Show more |
A DLL hijacking vulnerability in Axtion ODISSAAS ODIS v1.8.4 allows attackers to execute arbitrary code via a crafted DLL file. |
EDIMAX BR-6208AC V2_1.02 is vulnerable to Command Injection. This arises because the pppUserName field is directly passed to a shell command via the system() function without proper sanitization. An attacker can exploit...Show more |
A Command Injection Vulnerability has been discovered in the DHCP daemon service of D-Link DIR895LA1 v102b07. The vulnerability exists in the lease renewal processing logic where the DHCP hostname parameter is directly c...Show more |
1Zenitel 2Icx500 Firmware Icx510 FirmwareJun 17, 2026 Jan 9, 2026 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Remote Code Execution vulnerability that allows unauthenticated attackers to inject arbitrary commands into the hostname of the device. |
This vulnerability allows authenticated attackers to execute commands via the hostname of the device. |
1Dlink 1Di 8200g Firmware Jun 17, 2026 Jan 9, 2026 2.1 LOW· v4 9.8 CRITICAL· v3 6.5 MEDIUM· v2 A vulnerability was found in D-Link DI-8200G 17.12.20A1. This affects an unknown function of the file /upgrade_filter.asp. The manipulation of the argument path results in command injection. The attack may be performed f...Show more |
1Ui 4Airfiber Af60 Xg Firmware Airfiber Af60 FirmwareAirmax Ac Firmware+1 moreJun 17, 2026 Jan 8, 2026 N/A· v4 5.4 MEDIUM· v3 N/A· v2 A malicious actor in Wi-Fi range of the affected product could leverage a vulnerability in the airMAX Wireless Protocol to achieve a remote code execution (RCE) within the affected product. Affected Products:...Show more |
1Ui 4Ubb Xg Firmware Ubb FirmwareUdb Pro Sector Firmware+1 moreJun 17, 2026 Jan 8, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 A malicious actor in Wi-Fi range of the affected product could leverage a vulnerability in the airMAX Wireless Protocol to achieve a remote code execution (RCE) within the affected product. Affected Products: UBB-X...Show more |
1Veeam 1Veeam Backup & Replication Jun 17, 2026 Jan 8, 2026 N/A· v4 9.0 CRITICAL· v3 N/A· v2 This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a malicious interval or order parameter. |
1Veeam 1Veeam Backup & Replication Jun 17, 2026 Jan 8, 2026 N/A· v4 9.1 CRITICAL· v3 N/A· v2 This vulnerability allows a Backup Administrator to perform remote code execution (RCE) as the postgres user by sending a
malicious password parameter. |
An issue was discovered in the AppConnector component version 10.10.0.183 and earlier of enaio 10.10, in the AppConnector component version 11.0.0.183 and earlier of enaio 11.0, and in the AppConnctor component version 1...Show more |
1Veeam 1Veeam Backup & Replication Jun 17, 2026 Jan 8, 2026 N/A· v4 9.8 CRITICAL· v3 N/A· v2 This vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicious
backup configuration file. |
A command injection vulnerability exists in the GL-iNet GL-AXT1800 router firmware v4.6.8. The vulnerability is present in the `plugins.install_package` RPC method, which fails to properly sanitize user input in package...Show more |