CWE-78
5,964 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CVEs (5,964)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Fedoraproject ImagemagickRedhat4Enterprise Linux Extra Packages For Enterprise LinuxFedora+1 moreJun 17, 2026 May 30, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured. |
1Honeywell 1Onewireless Network Wireless Device Manager Firmware Jun 17, 2026 May 30, 2023 N/A· v4 6.8 MEDIUM· v3 N/A· v2 An attacker having physical access to WDM can plug USB device to gain access and execute unwanted commands. A malicious user could enter a system command along with a backup configuration, which could result in the execu...Show more |
1Zyxel 3Nas326 Firmware Nas540 FirmwareNas542 FirmwareJun 17, 2026 May 30, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2 The post-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.13)C0 could allow an authenticated attacker with administrator privileges to execute some operating system...Show more |
Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation: <?PHP instead of <?php in injected data. |
All versions of the package bwm-ng are vulnerable to Command Injection due to improper input sanitization in the 'check' function in the bwm-ng.js file. **Note:** To execute the code snippet and potentially exploit th...Show more |
1Keep Module Latest Project 1Keep Module Latest Jun 17, 2026 May 27, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 All versions of the package keep-module-latest are vulnerable to Command Injection due to missing input sanitization or other checks and sandboxes being employed to the installModule function. **Note:** To execute the...Show more |
All versions of the package n158 are vulnerable to Command Injection due to improper input sanitization in the 'module.exports' function. **Note:** To execute the code snippet and potentially exploit the vulnerability,...Show more |
NextCloud Cookbook is a recipe library app. Prior to commit a46d9855 on the `master` branch and commit 489bb744 on the `main-0.9.x` branch, the `pull-checks.yml` workflow is vulnerable to command injection attacks becaus...Show more |
An OS Command Injection vulnerability in Parks Fiberlink 210 firmware version V2.1.14_X000 was found via the /boaform/admin/formPing target_addr parameter. |
1Dell 1Vxrail Hyperconverged Infrastructure Jun 17, 2026 May 23, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Dell VxRail versions earlier than 7.0.450, contain(s) an OS command injection vulnerability in VxRail Manager. A local authenticated attacker could potentially exploit this vulnerability, leading to the execution of arb...Show more |
1Dell 1Vxrail Hyperconverged Infrastructure Jun 17, 2026 May 23, 2023 N/A· v4 8.2 HIGH· v3 N/A· v2 Dell VxRail, versions prior to 7.0.450, contains an OS command injection Vulnerability in DCManager command-line utility. A local high privileged attacker could potentially exploit this vulnerability, leading to the exe...Show more |
Beekeeper Studio versions prior to 3.9.9 allows a remote authenticated attacker to execute arbitrary JavaScript code with the privilege of the application on the PC where the affected product is installed. As a result, a...Show more |
1Inaba 4Ac Wapu 300 P Firmware Ac Wapu 300 FirmwareAc Wapum 300 P Firmware+1 moreJun 17, 2026 May 23, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2 Wi-Fi AP UNIT AC-PD-WAPU v1.05_B04 and earlier, AC-PD-WAPUM v1.05_B04 and earlier, AC-PD-WAPU-P v1.05_B04P and earlier, AC-PD-WAPUM-P v1.05_B04P and earlier, AC-WAPU-300 v1.00_B07 and earlier, AC-WAPU-300-P v1.00_B08P an...Show more |
1Contec 2Sv Cpt Mc310 Firmware Sv Cpt Mc310f FirmwareJun 17, 2026 May 23, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 OS command injection vulnerability in the mail setting page of SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10 and SV-CPT-MC310F versions prior to Ver.8.10 allows remote authenticated attackers to execute an ar...Show more |
1Contec 2Sv Cpt Mc310 Firmware Sv Cpt Mc310f FirmwareJun 17, 2026 May 23, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 OS command injection vulnerability in the download page of SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10 and SV-CPT-MC310F versions prior to Ver.8.10 allows a remote authenticated attacker to execute an arbit...Show more |
1Teltonika Networks 18Rut200 Firmware Rut240 FirmwareRut241 Firmware+15 moreJun 17, 2026 May 22, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Versions 00.07.00 through 00.07.03 of Teltonika’s RUT router firmware contain an operating system (OS) command injection vulnerability in a Lua service. An attacker could exploit a parameter in the vulnerable function t...Show more |
A command injection vulnerability exists in the administrative web portal in TP-Link Archer VR1600V devices running firmware Versions <= 0.1.0. 0.9.1 v5006.0 Build 220518 Rel.32480n which allows remote attackers, authent...Show more |
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit th...Show more |
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit th...Show more |
3Debian FedoraprojectLinuxfoundation3Cups Filters Debian LinuxFedoraJun 17, 2026 May 17, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 cups-filters contains backends, filters, and other software required to get the cups printing service working on operating systems other than macos. If you use the Backend Error Handler (beh) to create an accessible netw...Show more |