← Back
CWE-78

6,747 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

JSON object

Loading...

CVEs (6,747)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Rocketchat
1Rocket.chat
Jun 17, 2026
Dec 23, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A command injection vulnerability exists in Rocket.Chat-Desktop <3.8.14 that could allow an attacker to pass a malicious url of openInternalVideoChatWindow to shell.openExternal(), which may lead to remote code execution...Show more
A command injection vulnerability exists in Rocket.Chat-Desktop <3.8.14 that could allow an attacker to pass a malicious url of openInternalVideoChatWindow to shell.openExternal(), which may lead to remote code execution (internalVideoChatWindow.ts#L17). To exploit the vulnerability, the internal video chat window must be disabled or a Mac App Store build must be used (internalVideoChatWindow.ts#L14). The vulnerability may be exploited by an XSS attack because the function openInternalVideoChatWindow is exposed in the Rocket.Chat-Desktop-API.Show less
1Activitywatch
1Activitywatch
Jun 17, 2026
Dec 23, 2022
N/A· v4
9.6 CRITICAL· v3
N/A· v2
Activity Watch is a free and open-source automated time tracker. Versions prior to 0.11.0 allow an attacker to execute arbitrary commands on any macOS machine with ActivityWatch running. The attacker can exploit this vul...Show more
Activity Watch is a free and open-source automated time tracker. Versions prior to 0.11.0 allow an attacker to execute arbitrary commands on any macOS machine with ActivityWatch running. The attacker can exploit this vulnerability by having the user visiting a website with the page title set to a malicious string. An attacker could use another application to accomplish the same, but the web browser is the most likely attack vector. This issue is patched in version 0.11.0. As a workaround, users can run the latest version of aw-watcher-window from source, or manually patch the `printAppTitle.scpt` file.Show less
1Dataprobe
12Iboot Pdu4 N20 Firmware
Iboot Pdu4a N15 FirmwareIboot Pdu4a N20 Firmware+9 more
Jun 17, 2026
Dec 21, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where a specific function does not sanitize the input provided by the user, which may expose the affected to an OS command injection vulnerab...Show more
Dataprobe iBoot-PDU FW versions prior to 1.42.06162022 contain a vulnerability where a specific function does not sanitize the input provided by the user, which may expose the affected to an OS command injection vulnerability. Show less
1Search
1Docconv
Jun 17, 2026
Dec 21, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A vulnerability was found in docconv up to 1.2.0. It has been declared as critical. This vulnerability affects the function ConvertPDFImages of the file pdf_ocr.go. The manipulation of the argument path leads to os comma...Show more
A vulnerability was found in docconv up to 1.2.0. It has been declared as critical. This vulnerability affects the function ConvertPDFImages of the file pdf_ocr.go. The manipulation of the argument path leads to os command injection. The attack can be initiated remotely. Upgrading to version 1.2.1 is able to address this issue. The name of the patch is b19021ade3d0b71c89d35cb00eb9e589a121faa5. It is recommended to upgrade the affected component. VDB-216502 is the identifier assigned to this vulnerability.Show less
1Abacus Ext Cmdline Project
1Abacus Ext Cmdline
Jun 17, 2026
Dec 21, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
All versions of package abacus-ext-cmdline are vulnerable to Command Injection via the execute function due to improper user-input sanitization.
2Debian
Exuberant Ctags Project
2Debian Linux
Exuberant Ctags
Jun 17, 2026
Dec 20, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
A flaw was found in Exuberant Ctags in the way it handles the "-o" option. This option specifies the tag filename. A crafted tag filename specified in the command line or in the configuration file results in arbitrary co...Show more
A flaw was found in Exuberant Ctags in the way it handles the "-o" option. This option specifies the tag filename. A crafted tag filename specified in the command line or in the configuration file results in arbitrary command execution because the externalSortTags() in sort.c calls the system(3) function in an unsafe way.Show less
1Tenda
1F1203 Firmware
Jun 17, 2026
Dec 20, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Tenda F1203 V2.0.1.6 was discovered to contain a command injection vulnerability via the mac parameter at /goform/WriteFacMac.
1Pfsense
1Pfblockerng
Jun 17, 2026
Dec 20, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
pfSense pfBlockerNG through 2.1.4_27 allows remote attackers to execute arbitrary OS commands as root via the HTTP Host header, a different vulnerability than CVE-2022-31814.
1Baijiacms Project
1Baijiacms
Jun 17, 2026
Dec 20, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
A Remote Code Execution (RCE) vulnerability was found in includes/baijiacms/common.inc.php in baijiacms v4.
1P4 Project
1P4
Jun 17, 2026
Dec 20, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The package p4 before 0.0.7 are vulnerable to Command Injection via the run() function due to improper input sanitization
1Contec
1Conprosys Hmi System
Jun 17, 2026
Dec 19, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
CONPROSYS HMI System (CHS) Ver.3.4.4?and earlier allows a remote unauthenticated attacker to execute an arbitrary OS command on the server where the product is running by sending a specially crafted request.
1Buffalo
10Wex 1800ax4 Firmware
Wex 1800ax4ea FirmwareWsr 2533dhp2 Firmware+7 more
Jun 17, 2026
Dec 19, 2022
N/A· v4
6.8 MEDIUM· v3
N/A· v2
OS command injection vulnerability in Buffalo network devices allows a network-adjacent attacker with an administrative privilege to execute an arbitrary OS command if a specially crafted request is sent to a specific CG...Show more
OS command injection vulnerability in Buffalo network devices allows a network-adjacent attacker with an administrative privilege to execute an arbitrary OS command if a specially crafted request is sent to a specific CGI program.Show less
1Buffalo
11Wcr 1166ds Firmware
Wsr 2533dhp2 FirmwareWsr 2533dhp3 Firmware+8 more
Jun 17, 2026
Dec 19, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
OS command injection vulnerability in Buffalo network devices allows an network-adjacent attacker to execute an arbitrary OS command if a specially crafted request is sent to the management page.
1Paxtechnology
1Paydroid
Jun 17, 2026
Dec 16, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow an attacker to gain root access through command injection in systool client. The attacker must have shell access to the device in order to exploit t...Show more
PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow an attacker to gain root access through command injection in systool client. The attacker must have shell access to the device in order to exploit this vulnerability.Show less
1Paxtechnology
1Paydroid
Jun 17, 2026
Dec 16, 2022
N/A· v4
6.8 MEDIUM· v3
N/A· v2
PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow the execution of specific command injections on selected binaries in the ADB daemon shell service. The attacker must have physical USB access to the...Show more
PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow the execution of specific command injections on selected binaries in the ADB daemon shell service. The attacker must have physical USB access to the device in order to exploit this vulnerability.Show less
1Netgear
1Rax30 Firmware
Jun 17, 2026
Dec 16, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
The default console presented to users over telnet (when enabled) is restricted to a subset of commands. Commands issued at this console, however, appear to be fed directly into a system call or other similar function. T...Show more
The default console presented to users over telnet (when enabled) is restricted to a subset of commands. Commands issued at this console, however, appear to be fed directly into a system call or other similar function. This allows any authenticated user to execute arbitrary commands on the device.Show less
1Netgear
6Nighthawk Ax11000 Firmware
Nighthawk Ax1800 FirmwareNighthawk Ax2400 Firmware+3 more
Jun 17, 2026
Dec 16, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
The “puhttpsniff” service, which runs by default, is susceptible to command injection due to improperly sanitized user input. An unauthenticated attacker on the same network segment as the router can execute arbitrary co...Show more
The “puhttpsniff” service, which runs by default, is susceptible to command injection due to improperly sanitized user input. An unauthenticated attacker on the same network segment as the router can execute arbitrary commands on the device without authentication.Show less
1Totolink
1A7100ru Firmware
Jun 17, 2026
Dec 15, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the wscDisabled parameter in the setting/setWiFiWpsCfg function.
1Totolink
1A7100ru Firmware
Jun 17, 2026
Dec 15, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the wscDisabled parameter in the setting/setWiFiSignalCfg function.
1Cycle Import Check Project
1Cycle Import Check
Jun 17, 2026
Dec 14, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The package cycle-import-check before 1.3.2 are vulnerable to Command Injection via the writeFileToTmpDirAndOpenIt function due to improper user-input sanitization.