← Back
CWE-77

3,617 CVEs • Abstraction: Class • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

JSON object

Loading...

CVEs (3,617)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
-
-
Jun 17, 2026
Oct 22, 2025
N/A· v4
2.7 LOW· v3
N/A· v2
A high privileged remote attacker can influence the parameters passed to the openssl command due to improper neutralization of special elements when adding a password protected self-signed certificate.
1Reolink
1Reolink
Jun 17, 2026
Oct 21, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Reolink desktop application 8.18.12 contains a command injection vulnerability in its scheduled cache-clearing mechanism via a crafted folder name. NOTE: this is disputed by the Supplier because a crafted folder name wou...Show more
Reolink desktop application 8.18.12 contains a command injection vulnerability in its scheduled cache-clearing mechanism via a crafted folder name. NOTE: this is disputed by the Supplier because a crafted folder name would arise only if the local user were attacking himself.Show less
-
-
Jun 17, 2026
Oct 21, 2025
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Bambu Studio 2.1.1.52 and earlier is affected by a vulnerability that allows arbitrary code execution during application startup. The application loads a network plugin without validating its digital signature or verifyi...Show more
Bambu Studio 2.1.1.52 and earlier is affected by a vulnerability that allows arbitrary code execution during application startup. The application loads a network plugin without validating its digital signature or verifying its authenticity. A local attacker can exploit this behavior by placing a malicious component in the expected location, which is controllable by the attacker (e.g., under %APPDATA%), resulting in code execution within the context of the user. The main application is digitally signed, which may allow a malicious component to inherit trust and evade detection by security solutions that rely on signed parent processes.Show less
1Zohocorp
1Manageengine Admanager Plus
Jun 17, 2026
Oct 21, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
Zohocorp ManageEngine ADManager Plus version before 8024 are vulnerable to authenticated command injection vulnerability in the Custom Script component.
-
-
Jun 17, 2026
Oct 21, 2025
6.9 MEDIUM· v4
N/A· v3
N/A· v2
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in The Wikimedia Foundation Mediawiki Foundation - Springboard Extension allows Command Injection.This issue affects Media...Show more
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in The Wikimedia Foundation Mediawiki Foundation - Springboard Extension allows Command Injection.This issue affects Mediawiki Foundation - Springboard Extension: master.Show less
1Flowiseai
1Flowise
Jun 17, 2026
Oct 17, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Flowise through v3.0.4 is vulnerable to remote code execution via unsanitized evaluation of user input in the "Supabase RPC Filter" field.
-
-
Jun 17, 2026
Oct 16, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An arbitrary file upload vulnerability in SageMath, Inc CoCalc before commit 0d2ff58 allows attackers to execute arbitrary code via uploading a crafted SVG file.
-
-
Jun 17, 2026
Oct 16, 2025
N/A· v4
5.1 MEDIUM· v3
N/A· v2
Reolink Video Doorbell WiFi DB_566128M5MP_W performs insufficient validation of firmware update signatures. This allows attackers to load malicious firmware images, resulting in arbitrary code execution with root privile...Show more
Reolink Video Doorbell WiFi DB_566128M5MP_W performs insufficient validation of firmware update signatures. This allows attackers to load malicious firmware images, resulting in arbitrary code execution with root privileges. NOTE: this is disputed by the Supplier because the integrity of updates is instead assured via a "private encryption algorithm" and other "tamper-proof verification."Show less
1Zoom
4Meeting Software Development Kit
RoomsWorkplace Desktop+1 more
Jun 17, 2026
Oct 15, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Command injection in some Zoom Clients for Windows may allow an authenticated user to conduct a disclosure of information via network access.
1Flowiseai
1Flowise
Jul 14, 2026
Oct 14, 2025
8.4 HIGH· v4
9.9 CRITICAL· v3
N/A· v2
Flowise v3.0.1 < 3.0.8 and all versions after with 'ALLOW_BUILTIN_DEP' enabled contain an authenticated remote code execution vulnerability and node VM sandbox escape due to insecure use of integrated modules (Puppeteer...Show more
Flowise v3.0.1 < 3.0.8 and all versions after with 'ALLOW_BUILTIN_DEP' enabled contain an authenticated remote code execution vulnerability and node VM sandbox escape due to insecure use of integrated modules (Puppeteer and Playwright) within the nodevm execution environment. An authenticated attacker able to create or run a tool that leverages Puppeteer/Playwright can specify attacker-controlled browser binary paths and parameters. When the tool executes, the attacker-controlled executable/parameters are run on the host and circumvent the intended nodevm sandbox restrictions, resulting in execution of arbitrary code in the context of the host. This vulnerability was incorrectly assigned as a duplicate CVE-2025-26319 by the developers and should be considered distinct from that identifier.Show less
-
-
Jun 17, 2026
Oct 14, 2025
N/A· v4
7.2 HIGH· v3
N/A· v2
A vulnerability in the web-based management interface of network access point configuration services could allow an authenticated remote attacker to perform remote command execution. Successful exploitation could allow a...Show more
A vulnerability in the web-based management interface of network access point configuration services could allow an authenticated remote attacker to perform remote command execution. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system.Show less
1Arubanetworks
1Arubaos
Jun 17, 2026
Oct 14, 2025
N/A· v4
6.2 MEDIUM· v3
N/A· v2
An authenticated command injection vulnerability exists in the command line interface binary of AOS-10 GW and AOS-8 Controllers/Mobility Conductor operating system. Exploitation of this vulnerability requires physical ac...Show more
An authenticated command injection vulnerability exists in the command line interface binary of AOS-10 GW and AOS-8 Controllers/Mobility Conductor operating system. Exploitation of this vulnerability requires physical access to the hardware controllers. A successful attack could allow an authenticated malicious actor with physical access to execute arbitrary commands as a privileged user on the underlying operating system.Show less
1Arubanetworks
1Arubaos
Jun 17, 2026
Oct 14, 2025
N/A· v4
7.2 HIGH· v3
N/A· v2
An authenticated command injection vulnerability exists in the CLI binary of an AOS-8 Controller/Mobility Conductor operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitr...Show more
An authenticated command injection vulnerability exists in the CLI binary of an AOS-8 Controller/Mobility Conductor operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitrary commands as a privileged user on the underlying operating system.Show less
1Arubanetworks
1Arubaos
Jun 17, 2026
Oct 14, 2025
N/A· v4
7.2 HIGH· v3
N/A· v2
An authenticated command injection vulnerability exists in the CLI binary of an AOS-8 Controller/Mobility Conductor operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitr...Show more
An authenticated command injection vulnerability exists in the CLI binary of an AOS-8 Controller/Mobility Conductor operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitrary commands as a privileged user on the underlying operating system.Show less
1Dlink
1Dap 2695 Firmware
Jun 17, 2026
Oct 13, 2025
5.1 MEDIUM· v4
9.8 CRITICAL· v3
5.8 MEDIUM· v2
A vulnerability was detected in D-Link DAP-2695 2.00RC131. This affects the function fwupdater_main of the file rgbin of the component Firmware Update Handler. Performing manipulation results in os command injection. The...Show more
A vulnerability was detected in D-Link DAP-2695 2.00RC131. This affects the function fwupdater_main of the file rgbin of the component Firmware Update Handler. Performing manipulation results in os command injection. The attack may be initiated remotely. This vulnerability only affects products that are no longer supported by the maintainer.Show less
1Mingsoft
1Mcms
Jul 5, 2026
Oct 10, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An arbitrary file upload vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary code via uploading a crafted file.
1Huayi Tec
1Jeewms
Jun 17, 2026
Oct 10, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An arbitrary file upload vulnerability exists in JeeWMS 20250820, which is caused by the lack of file checking in the saveFiles function in /jeewms/cgUploadController.do. An attacker with normal privileges was able to up...Show more
An arbitrary file upload vulnerability exists in JeeWMS 20250820, which is caused by the lack of file checking in the saveFiles function in /jeewms/cgUploadController.do. An attacker with normal privileges was able to upload a malicious file that would lead to remote code execution.Show less
1Microsoft
1365 Copilot Chat
Jun 17, 2026
Oct 9, 2025
N/A· v4
9.3 CRITICAL· v3
N/A· v2
Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network.
1Microsoft
1365 Copilot Chat
Jun 17, 2026
Oct 9, 2025
N/A· v4
9.3 CRITICAL· v3
N/A· v2
Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to perform information disclosure locally.
1Microsoft
1365 Word Copilot
Jun 17, 2026
Oct 9, 2025
N/A· v4
9.3 CRITICAL· v3
N/A· v2
Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized attacker to disclose information over a network.