CWE-78
6,748 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CVEs (6,748)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
ASUS RT-AC86U does not filter special characters for parameters in specific web URLs. A remote attacker with normal user privileges can exploit this vulnerability to perform command injection attack to execute arbitrary...Show more |
Hitron CODA-5310 has insufficient filtering for specific parameters in the connection test function. A remote attacker authenticated as an administrator, can use the management page to perform command injection attacks,...Show more |
Brook is a cross-platform programmable network tool. The `tproxy` server is vulnerable to a drive-by command injection. An attacker may fool a victim into visiting a malicious web page which will trigger requests to the...Show more |
Dell NetWorker 19.6.1.2, contains an OS command injection Vulnerability in the NetWorker client. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS c...Show more |
3Fedoraproject ImagemagickRedhat4Enterprise Linux Extra Packages For Enterprise LinuxFedora+1 moreJun 17, 2026 May 30, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured. |
1Honeywell 1Onewireless Network Wireless Device Manager Firmware Jun 17, 2026 May 30, 2023 N/A· v4 6.8 MEDIUM· v3 N/A· v2 An attacker having physical access to WDM can plug USB device to gain access and execute unwanted commands. A malicious user could enter a system command along with a backup configuration, which could result in the execu...Show more |
1Zyxel 3Nas326 Firmware Nas540 FirmwareNas542 FirmwareJun 17, 2026 May 30, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2 The post-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.13)C0 could allow an authenticated attacker with administrator privileges to execute some operating system...Show more |
Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation: <?PHP instead of <?php in injected data. |
All versions of the package bwm-ng are vulnerable to Command Injection due to improper input sanitization in the 'check' function in the bwm-ng.js file. **Note:** To execute the code snippet and potentially exploit th...Show more |
1Keep Module Latest Project 1Keep Module Latest Jun 17, 2026 May 27, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 All versions of the package keep-module-latest are vulnerable to Command Injection due to missing input sanitization or other checks and sandboxes being employed to the installModule function. **Note:** To execute the...Show more |
All versions of the package n158 are vulnerable to Command Injection due to improper input sanitization in the 'module.exports' function. **Note:** To execute the code snippet and potentially exploit the vulnerability,...Show more |
NextCloud Cookbook is a recipe library app. Prior to commit a46d9855 on the `master` branch and commit 489bb744 on the `main-0.9.x` branch, the `pull-checks.yml` workflow is vulnerable to command injection attacks becaus...Show more |
An OS Command Injection vulnerability in Parks Fiberlink 210 firmware version V2.1.14_X000 was found via the /boaform/admin/formPing target_addr parameter. |
1Dell 1Vxrail Hyperconverged Infrastructure Jun 17, 2026 May 23, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Dell VxRail versions earlier than 7.0.450, contain(s) an OS command injection vulnerability in VxRail Manager. A local authenticated attacker could potentially exploit this vulnerability, leading to the execution of arb...Show more |
1Dell 1Vxrail Hyperconverged Infrastructure Jun 17, 2026 May 23, 2023 N/A· v4 8.2 HIGH· v3 N/A· v2 Dell VxRail, versions prior to 7.0.450, contains an OS command injection Vulnerability in DCManager command-line utility. A local high privileged attacker could potentially exploit this vulnerability, leading to the exe...Show more |
Beekeeper Studio versions prior to 3.9.9 allows a remote authenticated attacker to execute arbitrary JavaScript code with the privilege of the application on the PC where the affected product is installed. As a result, a...Show more |
1Inaba 4Ac Wapu 300 P Firmware Ac Wapu 300 FirmwareAc Wapum 300 P Firmware+1 moreJun 17, 2026 May 23, 2023 N/A· v4 7.2 HIGH· v3 N/A· v2 Wi-Fi AP UNIT AC-PD-WAPU v1.05_B04 and earlier, AC-PD-WAPUM v1.05_B04 and earlier, AC-PD-WAPU-P v1.05_B04P and earlier, AC-PD-WAPUM-P v1.05_B04P and earlier, AC-WAPU-300 v1.00_B07 and earlier, AC-WAPU-300-P v1.00_B08P an...Show more |
1Contec 2Sv Cpt Mc310 Firmware Sv Cpt Mc310f FirmwareJun 17, 2026 May 23, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 OS command injection vulnerability in the mail setting page of SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10 and SV-CPT-MC310F versions prior to Ver.8.10 allows remote authenticated attackers to execute an ar...Show more |
1Contec 2Sv Cpt Mc310 Firmware Sv Cpt Mc310f FirmwareJun 17, 2026 May 23, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 OS command injection vulnerability in the download page of SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10 and SV-CPT-MC310F versions prior to Ver.8.10 allows a remote authenticated attacker to execute an arbit...Show more |
1Teltonika Networks 18Rut200 Firmware Rut240 FirmwareRut241 Firmware+15 moreJun 17, 2026 May 22, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Versions 00.07.00 through 00.07.03 of Teltonika’s RUT router firmware contain an operating system (OS) command injection vulnerability in a Lua service. An attacker could exploit a parameter in the vulnerable function t...Show more |