CWE-78
6,747 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CVEs (6,747)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Softnext Mail SQR Expert is an email management platform, it has insufficient filtering for a special character within a spcific function. A remote attacker authenticated as a localhost can exploit this vulnerability to...Show more |
1Dell 1Powerprotect Data Domain Management Center Jun 17, 2026 Dec 14, 2023 N/A· v4 6.7 MEDIUM· v3 N/A· v2 Dell PowerProtect DD, versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 on DDMC contain an OS command injection vulnerability in an admin operation. A local high privileged attacker could potentially e...Show more |
1Dell 5Apex Protection Storage Emc Data Domain OsPowerprotect Data Domain+2 moreJun 17, 2026 Dec 14, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2 Dell PowerProtect DD, versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an OS command injection vulnerability in administrator CLI. A remote high privileged attacker could potentially exploit t...Show more |
1Dell 3Powermax Os Solutions Enabler Virtual ApplianceUnisphere For Powermax Virtual ApplianceJun 17, 2026 Dec 14, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2 Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability. A remote malicious user with high privileges could potentially exploit this vulnerability leading to the execution of arbitrary OS...Show more |
1Dell 3Powermax Os Solutions Enabler Virtual ApplianceUnisphere For Powermax Virtual ApplianceJun 17, 2026 Dec 14, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2 Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability. A remote malicious user with high privileges could potentially exploit this vulnerability leading to the execution of arbitrary OS...Show more |
1Dell 3Powermax Os Solutions Enabler Virtual ApplianceUnisphere For Powermax Virtual ApplianceJun 17, 2026 Dec 14, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2 Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability. A remote malicious user with high privileges could potentially exploit this vulnerability leading to the execution of arbitrary OS...Show more |
1Dell 3Powermax Os Solutions Enabler Virtual ApplianceUnisphere For Powermax Virtual ApplianceJun 17, 2026 Dec 14, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2 Dell vApp Manager, versions prior to 9.2.4.x contain a command injection vulnerability. A remote malicious user with high privileges could potentially exploit this vulnerability leading to the execution of arbitrary OS...Show more |
1Dell 5Apex Protection Storage Emc Data Domain OsPowerprotect Data Domain+2 moreJun 17, 2026 Dec 14, 2023 N/A· v4 6.7 MEDIUM· v3 N/A· v2 Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an OS command injection vulnerability in administrator CLI. A local high privileged attacker could potentially exploit...Show more |
1Dell 5Apex Protection Storage Emc Data Domain OsPowerprotect Data Domain+2 moreJun 17, 2026 Dec 14, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Dell PowerProtect DD, versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an OS command injection vulnerability in the CLI. A local low privileged attacker could potentially exploit this vulnerab...Show more |
An OS command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to disrupt system processes and potentially execute arbitrary code with limited privileges on the firewal...Show more |
An OS command injection vulnerability in the XML API of Palo Alto Networks PAN-OS software enables an authenticated API user to disrupt system processes and potentially execute arbitrary code with limited privileges on t...Show more |
Dasan Networks - W-Web versions 1.22-1.27 - CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
|
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 allows attacker to execute unauthorized code or commands via specifically craf...Show more |
An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the command line interpreter of FortiTester 2.3.0 through 7.2.3 may allow an authenticated attacker to execute unauthorized...Show more |
In GL.iNET GL-AR300M routers with firmware v4.3.7, it is possible to inject arbitrary shell commands through a crafted package name in the package information functionality. |
1Siemens 206gk5615 0aa00 2aa2 Firmware 6gk5615 0aa01 2aa2 Firmware6gk5804 0ap00 2aa2 Firmware+17 moreJun 17, 2026 Dec 12, 2023 N/A· v4 6.7 MEDIUM· v3 N/A· v2 A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V7.2.2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V7.2.2), SCALANCE M804PB (6GK5804-0AP00-2...Show more |
1Siemens 206gk5615 0aa00 2aa2 Firmware 6gk5615 0aa01 2aa2 Firmware6gk5804 0ap00 2aa2 Firmware+17 moreJun 17, 2026 Dec 12, 2023 N/A· v4 6.7 MEDIUM· v3 N/A· v2 A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.0), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V8.0), SCALANCE M804PB (6GK5804-0AP00-2AA2)...Show more |
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 2). The radius configuration mechanism of affected products does not correctly check uploaded certificates. A malicious admin could upload...Show more |
1Elecom 3Wrc X3000gs Firmware Wrc X3000gsa FirmwareWrc X3000gsn FirmwareJun 17, 2026 Dec 12, 2023 N/A· v4 6.8 MEDIUM· v3 N/A· v2 OS command injection vulnerability in WRC-X3000GSN v1.0.2, WRC-X3000GS v1.0.24 and earlier, and WRC-X3000GSA v1.0.24 and earlier allows a network-adjacent attacker with an administrative privilege to execute an arbitrary...Show more |
A Huawei data communication product has a command injection vulnerability. Successful exploitation of this vulnerability may allow attackers to gain higher privileges. |