CWE-78
6,732 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CVEs (6,732)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
pyLoad is a free and open-source Download Manager. The folder `/.pyload/scripts` has scripts which are run when certain actions are completed, for e.g. a download is finished. By downloading a executable file to a folder...Show more |
MangoOS before 5.2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the Active Process Command feature. |
A command execution vulnerability exists in the AX2 Pro home router produced by Shenzhen Tenda Technology Co., Ltd. (Jixiang Tenda) v.DI_7003G-19.12.24A1V16.03.29.50;V16.03.29.50;V16.03.29.50. An attacker can exploit thi...Show more |
Plenti, a static site generator, has an arbitrary file write vulnerability in versions prior to 0.7.2. The `/postLocal` endpoint is vulnerable to an arbitrary file write vulnerability when a plenti user serves their webs...Show more |
EnGenius ENH1350EXT A8J-ENH1350EXT devices through 3.9.3.2_c1.9.51 allow (blind) OS Command Injection via shell metacharacters to the Ping or Speed Test utility. During the time of initial setup, the device creates an op...Show more |
The package Snyk CLI before 1.1294.0 is vulnerable to Code Injection when scanning an untrusted Gradle project. The vulnerability can be triggered if Snyk test is run inside the untrusted project due to the improper hand...Show more |
The package Snyk CLI before 1.1294.0 is vulnerable to Code Injection when scanning an untrusted PHP project. The vulnerability can be triggered if Snyk test is run inside the untrusted project due to the improper handlin...Show more |
1Cisco 1Secure Firewall Management Center Jun 17, 2026 Oct 23, 2024 N/A· v4 9.9 CRITICAL· v3 N/A· v2 A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to execute arb...Show more |
1Cisco 1Secure Firewall Management Center Jun 17, 2026 Oct 23, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A vulnerability in the cluster backup feature of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to execute arbitrary c...Show more |
1Siemens 2Intermesh 7177 Hybrid 2.0 Subscriber Intermesh 7707 Fire Subscriber FirmwareJun 17, 2026 Oct 23, 2024 10.0 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fire Subscriber (All versions < V7.2.12 only if the IP interface is enabled (which is not the default c...Show more |
1Wellchoose 1Administrative Management System Jun 17, 2026 Oct 21, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 Administrative Management System from Wellchoose has an OS Command Injection vulnerability, allowing remote attackers with regular privileges to inject and execute arbitrary OS commands. |
The wireless router WRTM326 from SECOM does not properly validate a specific parameter. An unauthenticated remote attacker could execute arbitrary system commands by sending crafted requests. |
SECOM WRTR-304GN-304TW-UPSC does not properly filter user input in the specific functionality. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device...Show more |
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Ninja Team Click to Chat – WP Support All-in-One Floating Widget support-chat allows Stored XSS.This issue affec...Show more |
1Dlink 2Dir 878 Firmware Dir 882 FirmwareJun 17, 2026 Oct 17, 2024 N/A· v4 8.0 HIGH· v3 N/A· v2 D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the SubnetMask parameter in the SetGuestZoneRouterSettings function. This vulnerability allows attacke...Show more |
1Dlink 2Dir 878 Firmware Dir 882 FirmwareJun 17, 2026 Oct 17, 2024 N/A· v4 8.0 HIGH· v3 N/A· v2 D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the VLANID:1/VID parameter in the SetVLANSettings function. This vulnerability allows attackers to exe...Show more |
1Dlink 2Dir 878 Firmware Dir 882 FirmwareJun 17, 2026 Oct 17, 2024 N/A· v4 8.0 HIGH· v3 N/A· v2 D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the VLANID:0/VID parameter in the SetVLANSettings function. This vulnerability allows attackers to exe...Show more |
1Dlink 2Dir 878 Firmware Dir 882 FirmwareJun 17, 2026 Oct 17, 2024 N/A· v4 8.0 HIGH· v3 N/A· v2 D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the VLANID:2/VID parameter in the SetVLANSettings function. This vulnerability allows attackers to exe...Show more |
1Dlink 2Dir 878 Firmware Dir 882 FirmwareJun 17, 2026 Oct 17, 2024 N/A· v4 8.0 HIGH· v3 N/A· v2 D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain a command injection vulnerability via the key parameter in the SetWLanRadioSecurity function. This vulnerability allows attackers to execute...Show more |
1Dlink 2Dir 878 Firmware Dir 882 FirmwareJun 17, 2026 Oct 17, 2024 N/A· v4 8.0 HIGH· v3 N/A· v2 D-Link DIR_882_FW130B06 and DIR_878 DIR_878_FW130B08 were discovered to contain multiple command injection vulnerabilities via the ExternalPort, InternalPort, ProtocolNumber, and LocalIPAddress parameters in the SetVirtu...Show more |