CWE-78
6,663 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CVEs (6,663)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.420.7, the Git Repository field during project creation is vulnerable to command injection....Show more |
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0.0-beta.420.7, a Remote Code Execution (RCE)*vulnerability exists in Coolify's application deploymen...Show more |
In the backup parameters, a user with high privilege is able to concatenate custom instructions to the backup setup. Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerabilit...Show more |
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Nuvation Energy Multi-Stack Controller (MSC) allows OS Command Injection.This issue affects Multi-Stack Controll...Show more |
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Nuvation Energy Multi-Stack Controller (MSC) allows OS Command Injection.This issue affects Multi-Stack Controll...Show more |
Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.19.0, an unauthenticated attacker can pollute the internal state (`restoreFilePath`) of the server via the `/skServer/valid...Show more |
RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions prior to 0.23.0, a low-privileged authenticated user (normal login account) can execute arbitrary system commands on the server host proc...Show more |
Gargoyle router management utility versions 1.5.x contain an authenticated OS command execution vulnerability in /utility/run_commands.sh. The application fails to properly restrict or validate input supplied via the 'co...Show more |
meterN 1.2.3 contains an authenticated remote code execution vulnerability in admin_meter2.php and admin_indicator2.php scripts. Attackers can exploit the 'COMMANDx' and 'LIVECOMMANDx' POST parameters to execute arbitrar...Show more |
Cypress Solutions CTM-200 2.7.1 contains an authenticated command injection vulnerability in the firmware upgrade script that allows remote attackers to execute shell commands. Attackers can exploit the 'fw_url' paramete...Show more |
VPN Firewall developed by QNO Technology has an OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS commands and execute them on the server. |
VPN Firewall developed by QNO Technology has an OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS commands and execute them on the server. |
1Ateme 1Flamingo Xl Firmware Jun 17, 2026 Dec 30, 2025 8.6 HIGH· v4 10.0 CRITICAL· v3 N/A· v2 Anevia Flamingo XL 3.2.9 contains a restricted shell vulnerability that allows remote attackers to escape the sandboxed environment through the traceroute command. Attackers can exploit the traceroute command to inject s...Show more |
1Sound4 9Big Voice2 Firmware Big Voice4 FirmwareFirst Firmware+6 moreJun 17, 2026 Dec 30, 2025 8.5 HIGH· v4 7.8 HIGH· v3 N/A· v2 SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains a conditional command injection vulnerability that allows local authenticated users to create malicious files in the /tmp directory. Unauthenticated attackers can execute comm...Show more |
1Sound4 9Big Voice2 Firmware Big Voice4 FirmwareFirst Firmware+6 moreJun 17, 2026 Dec 30, 2025 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated command injection vulnerability in the username parameter. Attackers can exploit index.php and login.php scripts by injecting arbitrary shel...Show more |
1Sound4 9Big Voice2 Firmware Big Voice4 FirmwareFirst Firmware+6 moreJun 17, 2026 Dec 30, 2025 8.7 HIGH· v4 8.8 HIGH· v3 N/A· v2 SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an authenticated command injection vulnerability in the www-data-handler.php script that allows attackers to inject system commands through the 'services' POST parameter. Atta...Show more |
1Sound4 9Big Voice2 Firmware Big Voice4 FirmwareFirst Firmware+6 moreJun 17, 2026 Dec 30, 2025 8.5 HIGH· v4 7.8 HIGH· v3 N/A· v2 SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains a conditional command injection vulnerability that allows local authenticated users to create malicious files in the /tmp directory. Unauthenticated attackers can execute comm...Show more |
1Sound4 9Big Voice2 Firmware Big Voice4 FirmwareFirst Firmware+6 moreJun 17, 2026 Dec 30, 2025 8.5 HIGH· v4 7.8 HIGH· v3 N/A· v2 SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains a command injection vulnerability that allows local authenticated users to create malicious files in the /tmp directory with .dns.pid extension. Unauthenticated attackers can...Show more |
1Minidvblinux 1Minidvblinux Jun 17, 2026 Dec 30, 2025 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 MiniDVBLinux 5.4 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary commands as root through the 'command' GET parameter. Attackers can exploit the /tpl/commands....Show more |
A vulnerability was found in Tenda W6-S 1.0.0.4(510). This affects the function TendaAte of the file /goform/ate of the component ATE Service. Performing a manipulation results in os command injection. The attack may be...Show more |