CWE-78
5,964 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CVEs (5,964)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
PaddlePaddle before 2.5.0 has a command injection in fs.py. This resulted in the ability to execute arbitrary commands on the operating system.
|
Improper Neutralization of commands allowed to be executed via OTRS System Configuration e.g. SchedulerCronTaskModule using UnitTests modules allows any authenticated attacker with admin privileges local execution of Cod...Show more |
vm2 is an open source vm/sandbox for Node.js. In vm2 for versions up to and including 3.9.19, Node.js custom inspect function allows attackers to escape the sandbox and run arbitrary code. This may result in Remote Code...Show more |
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in HGiga iSherlock 4.5 (iSherlock-user modules), HGiga iSherlock 5.5 (iSherlock-user modules) allows OS Command Inj...Show more |
1Panel is an open source Linux server operation and maintenance management panel. An OS command injection vulnerability exists in 1Panel firewall functionality. A specially-crafted HTTP request can lead to arbitrary comm...Show more |
1Kratosdefense 1Ngc Indoor Unit Firmware Jun 17, 2026 Jul 18, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A remotely exploitable command injection vulnerability was found on the Kratos NGC-IDU 9.1.0.4. An attacker can execute arbitrary Linux commands as root by sending crafted TCP requests to the device. |
1Ons 1Ras Collection Instrument Jun 17, 2026 Jul 18, 2023 N/A· v4 9.8 CRITICAL· v3 5.2 MEDIUM· v2 A vulnerability was found in ONS Digital RAS Collection Instrument up to 2.0.27 and classified as critical. Affected by this issue is the function jobs of the file .github/workflows/comment.yml. The manipulation of the a...Show more |
1Zyxel 24Nxc2500 Firmware Nxc5500 FirmwareUsg 20w Vpn Firmware+21 moreJun 17, 2026 Jul 17, 2023 N/A· v4 8.0 HIGH· v3 N/A· v2 A command injection vulnerability in the access point (AP) management feature of the Zyxel ATP series firmware versions 5.00 through 5.36 Patch 2, USG FLEX series firmware versions 5.00 through 5.36 Patch 2, USG FLEX 50...Show more |
1Zyxel 15Usg 2200 Vpn Firmware Usg Flex 100 FirmwareUsg Flex 100w Firmware+12 moreJun 17, 2026 Jul 17, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 A command injection vulnerability in the Free Time WiFi hotspot feature of the Zyxel USG FLEX series firmware versions 4.50 through 5.36 Patch 2 and VPN series firmware versions 4.20 through 5.36 Patch 2, could allow an...Show more |
1Zyxel 22Usg 20w Vpn Firmware Usg 2200 Vpn FirmwareUsg Flex 100 Firmware+19 moreJun 17, 2026 Jul 17, 2023 N/A· v4 8.0 HIGH· v3 N/A· v2 A command injection vulnerability in the hotspot management feature of the Zyxel ATP series firmware versions 4.60 through 5.36 Patch 2, USG FLEX series firmware versions 4.60 through 5.36 Patch 2, USG FLEX 50(W) series...Show more |
1Zyxel 22Usg 20w Vpn Firmware Usg 2200 Vpn FirmwareUsg Flex 100 Firmware+19 moreJun 17, 2026 Jul 17, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 A command injection vulnerability in the configuration parser of the Zyxel ATP series firmware versions 5.10 through 5.36 Patch 2, USG FLEX series firmware versions 5.00 through 5.36 Patch 2, USG FLEX 50(W) series firmw...Show more |
1Zyxel 22Usg 20w Vpn Firmware Usg 2200 Vpn FirmwareUsg Flex 100 Firmware+19 moreJun 17, 2026 Jul 17, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 The configuration parser fails to sanitize user-controlled input in the Zyxel ATP series firmware versions 5.10 through 5.36, USG FLEX series firmware versions 5.00 through 5.36, USG FLEX 50(W) series firmware versions...Show more |
The web interface on the RIGOL MSO5000 digital oscilloscope with firmware 00.01.03.00.03 allows remote attackers to execute arbitrary code via shell metacharacters in pass1 to the webcontrol changepwd.cgi application. |
1Elecom 5Wrc 1167febk A Firmware Wrc 1167febk S FirmwareWrc 1167gebk S Firmware+2 moreJun 17, 2026 Jul 13, 2023 N/A· v4 8.0 HIGH· v3 N/A· v2 OS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent authenticated attacker to execute an arbitrary OS command with a root privilege by sending a specially crafted request. Affected...Show more |
1Sonicwall 2Analytics Global Management SystemJun 17, 2026 Jul 13, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SonicWall GMS, SonicWall Analytics enables an authenticated attacker to execute arbitrary code with root privile...Show more |
Improper input validation in the Zoom Desktop Client for Windows before version 5.15.0 may allow an unauthorized user to enable an escalation of privilege via network access. |
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiWeb version 7.0.1 and below, 6.4 all versions, version 6.3.18 and below may allow a privileged...Show more |
Due to programming error in function module and report, IS-OIL component in SAP ECC and SAP S/4HANA allows an authenticated attacker to inject an arbitrary operating system command into an unprotected parameter in a comm...Show more |
1Ruijienetworks 1Bcr810w Firmware Jun 17, 2026 Jul 10, 2023 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 A vulnerability was found in Ruijie BCR810W 2.5.10. It has been rated as critical. This issue affects some unknown processing of the component Tracert Page. The manipulation leads to os command injection. The attack may...Show more |
A vulnerability was found in kodbox 1.26. It has been declared as critical. This vulnerability affects the function Execute of the file webconsole.php.txt of the component WebConsole Plug-In. The manipulation leads to os...Show more |