← Back
CWE-78

6,645 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

JSON object

Loading...

CVEs (6,645)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Vim
1Vim
Jun 17, 2026
Feb 27, 2026
N/A· v4
7.8 HIGH· v3
N/A· v2
Vim is an open source, command line text editor. Prior to version 9.2.0073, an OS command injection vulnerability exists in the `netrw` standard plugin bundled with Vim. By inducing a user to open a crafted URL (e.g., us...Show more
Vim is an open source, command line text editor. Prior to version 9.2.0073, an OS command injection vulnerability exists in the `netrw` standard plugin bundled with Vim. By inducing a user to open a crafted URL (e.g., using the `scp://` protocol handler), an attacker can execute arbitrary shell commands with the privileges of the Vim process. Version 9.2.0073 fixes the issue.Show less
1Wegia
1Wegia
Jun 17, 2026
Feb 27, 2026
N/A· v4
7.2 HIGH· v3
N/A· v2
WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, a critical Remote Code Execution (RCE) vulnerability exists in the WeGIA application's database restoration functionality. An attacker with admi...Show more
WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, a critical Remote Code Execution (RCE) vulnerability exists in the WeGIA application's database restoration functionality. An attacker with administrative access (which can be obtained via the previously reported Authentication Bypass) can execute arbitrary OS commands on the server by uploading a backup file with a specifically crafted filename. Version 3.6.5 fixes the issue.Show less
1Johnsoncontrols
1Frick Controls Quantum Hd Firmware
Jun 17, 2026
Feb 27, 2026
8.8 HIGH· v4
9.8 CRITICAL· v3
N/A· v2
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows OS Command Injection. Insufficient validation of input in cert...Show more
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows OS Command Injection. Insufficient validation of input in certain parameters may permit unexpected actions, which could impact the security of the device before authentication occurs.This issue affects Frick Controls Quantum HD version 10.22 and prior.Show less
2Logicminds
Redhat
2Rubyipmi
Satellite
Jun 17, 2026
Feb 27, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
A flaw was found in rubyipmi, a gem used in the Baseboard Management Controller (BMC) component of Red Hat Satellite. An authenticated attacker with host creation or update permissions could exploit this vulnerability by...Show more
A flaw was found in rubyipmi, a gem used in the Baseboard Management Controller (BMC) component of Red Hat Satellite. An authenticated attacker with host creation or update permissions could exploit this vulnerability by crafting a malicious username for the BMC interface. This could lead to remote code execution (RCE) on the system.Show less
1Totolink
1N300rh Firmware
Jun 17, 2026
Feb 27, 2026
8.9 HIGH· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A security flaw has been discovered in Totolink N300RH 6.1c.1353_B20190305. Affected by this vulnerability is the function setWebWlanIdx of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Perform...Show more
A security flaw has been discovered in Totolink N300RH 6.1c.1353_B20190305. Affected by this vulnerability is the function setWebWlanIdx of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Performing a manipulation of the argument webWlanIdx results in os command injection. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.Show less
1Copeland
3Xweb 300d Pro Firmware
Xweb 500b Pro FirmwareXweb 500d Pro Firmware
Jun 17, 2026
Feb 27, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by modifying malicious input injected into the MBird...Show more
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by modifying malicious input injected into the MBird SMS service URL and/or code via the utility route which is later processed during system setup, leading to remote code execution.Show less
1Copeland
3Xweb 300d Pro Firmware
Xweb 500b Pro FirmwareXweb 500d Pro Firmware
Jun 17, 2026
Feb 27, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the server usernam...Show more
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the server username and/or password fields of the restore action in the API V1 route.Show less
1Copeland
3Xweb 300d Pro Firmware
Xweb 500b Pro FirmwareXweb 500d Pro Firmware
Jun 17, 2026
Feb 27, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the Wi-Fi SSID and...Show more
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the Wi-Fi SSID and/or password fields can lead to remote code execution when the configuration is processed.Show less
1Copeland
3Xweb 300d Pro Firmware
Xweb 500b Pro FirmwareXweb 500d Pro Firmware
Jun 17, 2026
Feb 27, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into parameters of...Show more
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into parameters of the Modbus command tool in the debug route.Show less
1Copeland
3Xweb 300d Pro Firmware
Xweb 500b Pro FirmwareXweb 500d Pro Firmware
Jun 17, 2026
Feb 27, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by configuring a maliciously crafted LCD state whic...Show more
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by configuring a maliciously crafted LCD state which is later processed during system setup, enabling remote code execution.Show less
1Copeland
3Xweb 300d Pro Firmware
Xweb 500b Pro FirmwareXweb 500d Pro Firmware
Jun 17, 2026
Feb 27, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by supplying a crafted template file to the devices...Show more
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by supplying a crafted template file to the devices route.Show less
1Copeland
3Xweb 300d Pro Firmware
Xweb 500b Pro FirmwareXweb 500d Pro Firmware
Jun 17, 2026
Feb 27, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by sending malicious input injected into the server...Show more
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by sending malicious input injected into the server username field of the import preconfiguration action in the API V1 route.Show less
1Copeland
3Xweb 300d Pro Firmware
Xweb 500b Pro FirmwareXweb 500d Pro Firmware
Jun 17, 2026
Feb 27, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by providing malicious input via the device hostname...Show more
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by providing malicious input via the device hostname configuration which is later processed during system setup, resulting in remote code execution.Show less
1Copeland
3Xweb 300d Pro Firmware
Xweb 500b Pro FirmwareXweb 500d Pro Firmware
Jun 17, 2026
Feb 27, 2026
N/A· v4
6.6 MEDIUM· v3
N/A· v2
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by supplying a crafted firmware update file via t...Show more
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by supplying a crafted firmware update file via the firmware update route.Show less
1Copeland
3Xweb 300d Pro Firmware
Xweb 500b Pro FirmwareXweb 500d Pro Firmware
Jun 17, 2026
Feb 27, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into requests sent to t...Show more
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into requests sent to the restore route.Show less
1Copeland
3Xweb 300d Pro Firmware
Xweb 500b Pro FirmwareXweb 500d Pro Firmware
Jun 17, 2026
Feb 27, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the devices fiel...Show more
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the devices field when accessing the get setup route.Show less
1Copeland
3Xweb 300d Pro Firmware
Xweb 500b Pro FirmwareXweb 500d Pro Firmware
Jun 17, 2026
Feb 27, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into OpenSSL argume...Show more
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into OpenSSL argument fields within requests sent to the utility route, leading to remote code execution.Show less
1Copeland
3Xweb 300d Pro Firmware
Xweb 500b Pro FirmwareXweb 500d Pro Firmware
Jun 17, 2026
Feb 27, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the devices field...Show more
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the devices field of the firmware update apply action.Show less
1Copeland
3Xweb 300d Pro Firmware
Xweb 500b Pro FirmwareXweb 500d Pro Firmware
Jun 17, 2026
Feb 27, 2026
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an unauthenticated attacker to achieve remote code execution on the system by sending a crafted request to the libraries inst...Show more
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an unauthenticated attacker to achieve remote code execution on the system by sending a crafted request to the libraries installation route and injecting malicious input into the request body.Show less
1Copeland
3Xweb 300d Pro Firmware
Xweb 500b Pro FirmwareXweb 500d Pro Firmware
Jun 17, 2026
Feb 27, 2026
N/A· v4
7.2 HIGH· v3
N/A· v2
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into requests sent to...Show more
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into requests sent to the firmware update route.Show less