CWE-78
5,954 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CVEs (5,954)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Dell 2Emc Avamar Server Emc Integrated Data Protection ApplianceNov 21, 2024 Jan 14, 2021 N/A· v4 10.0 CRITICAL· v3 10.0 HIGH· v2 DELL EMC Avamar Server, versions 19.1, 19.2, 19.3, contain an OS Command Injection Vulnerability in Fitness Analyzer. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the executi...Show more |
An OS command injection vulnerability in FortiDeceptor 3.1.0, 3.0.1, 3.0.0 may allow a remote authenticated attacker to execute arbitrary commands on the system by exploiting a command injection vulnerability on the Cust...Show more |
1Cisco 5Application Extension Platform Rv110w FirmwareRv130 Vpn Router Firmware+2 moreNov 21, 2024 Jan 13, 2021 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to inject arbitrary commands that are execute...Show more |
1Cisco 5Application Extension Platform Rv110w FirmwareRv130 Vpn Router Firmware+2 moreNov 21, 2024 Jan 13, 2021 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to inject arbitrary commands that are execute...Show more |
1Cisco 5Application Extension Platform Rv110w FirmwareRv130 Vpn Router Firmware+2 moreNov 21, 2024 Jan 13, 2021 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to inject arbitrary commands that are execute...Show more |
1Cisco 5Application Extension Platform Rv110w FirmwareRv130 Vpn Router Firmware+2 moreNov 21, 2024 Jan 13, 2021 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to inject arbitrary commands that are execute...Show more |
1Cisco 5Application Extension Platform Rv110w FirmwareRv130 Vpn Router Firmware+2 moreNov 21, 2024 Jan 13, 2021 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to inject arbitrary commands that are execute...Show more |
An issue was discovered in the Manage Plugins page in Nagios XI before 5.8.0. Because the line-ending conversion feature is mishandled during a plugin upload, a remote, authenticated admin user can execute operating-syst...Show more |
1Nec 2Univerge Sv8500 Firmware Univerge Sv9500 FirmwareNov 21, 2024 Jan 13, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 UNIVERGE SV9500 series from V1 to V7and SV8500 series from S6 to S8 allows an attacker to execute arbitrary OS commands or cause a denial-of-service (DoS) condition by sending a specially crafted request to a specific UR...Show more |
2Clusterlabs Debian2Crmsh Debian LinuxNov 21, 2024 Jan 12, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An issue was discovered in ClusterLabs crmsh through 4.2.1. Local attackers able to call "crm history" (when "crm" is run) were able to execute commands via shell code injection to the crm history commandline, potentiall...Show more |
An issue was discovered in ClusterLabs Hawk 2.x through 2.3.0-x. There is a Ruby shell code injection issue via the hawk_remember_me_id parameter in the login_from_cookie cookie. The user logout routine could be used by...Show more |
A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this...Show more |
A vulnerability in SonicWall SMA100 appliance allow an authenticated management-user to perform OS command injection using HTTP POST parameters. This vulnerability affected SMA100 Appliance version 10.2.0.2-20sv and earl...Show more |
This affects all versions of package buns. The injection point is located in line 678 in index file lib/index.js in the exported function install(requestedModule). |
1Ts Process Promises Project 1Ts Process Promises Nov 21, 2024 Jan 8, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 This affects all versions of package ts-process-promises. The injection point is located in line 45 in main entry of package in lib/process-promises.js. The vulnerability is demonstrated with the following PoC: |
EVOLUCARE ECSIMAGING (aka ECS Imaging) through 6.21.5 has an OS Command Injection vulnerability via shell metacharacters and an IFS manipulation. The parameter "file" on the webpage /showfile.php can be exploited to gain...Show more |
Multiple vulnerabilities in Cisco Jabber for Windows, Jabber for MacOS, and Jabber for mobile platforms could allow an attacker to execute arbitrary programs on the underlying operating system (OS) with elevated privileg...Show more |
1Tp Link 1Tl Wr840n Firmware Nov 21, 2024 Jan 6, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 oal_ipt_addBridgeIsolationRules on TP-Link TL-WR840N 6_EU_0.9.1_4.16 devices allows OS command injection because a raw string entered from the web interface (an IP address field) is used directly for a call to the system...Show more |
Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. In Vela compiler before version 0.6.1 there is a vulnerability which allows exposure of server configuration. It impa...Show more |
1Hgiga 2Msr45 Isherlock User Ssr45 Isherlock UserNov 21, 2024 Dec 31, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 HGiga MailSherlock does not validate specific parameters properly. Attackers can use the vulnerability to launch Command inject attacks remotely and execute arbitrary commands of the system. |