CWE-78
5,953 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CVEs (5,953)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Totolink 13A3002r Firmware A3002ru V1 FirmwareA3002ru V2 Firmware+10 moreNov 21, 2024 Dec 9, 2020 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 TOTOLINK A3002RU-V2.0.0 B20190814.1034 allows authenticated remote users to modify the system's 'Run Command'. An attacker can use this functionality to execute arbitrary OS commands on the router. |
1Sap 2Business Warehouse Bw/4hanaNov 21, 2024 Dec 9, 2020 N/A· v4 9.1 CRITICAL· v3 9.0 HIGH· v2 SAP Business Warehouse, versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 782, and SAP BW4HANA, versions - 100, 200 allows an attacker authenticated with (high) developer privileges to submit a crafted re...Show more |
Zeroshell 3.9.3 contains a command injection vulnerability in the /cgi-bin/kerbynet StartSessionSubmit parameter that could allow an unauthenticated attacker to execute a system command by using shell metacharacters and...Show more |
1Vsolcn 5V1600d Mini Firmware V1600d4l FirmwareV1600d Firmware+2 moreNov 21, 2024 Nov 29, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600D4L V1.01.49, V1600D-MINI V1.01.48, V1600G1 V2.0.7 and V1.9.7, and V1600G2 V1.1.4 OLT devices. Command injection can occur in "upload tftp syslog" and "...Show more |
1Systeminformation 1Systeminformation Nov 21, 2024 Nov 27, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 npm package systeminformation before version 4.30.5 is vulnerable to Prototype Pollution leading to Command Injection. The issue was fixed with a rewrite of shell sanitations to avoid prototyper pollution problems. The i...Show more |
1Systeminformation 1Systeminformation Nov 21, 2024 Nov 26, 2020 N/A· v4 7.3 HIGH· v3 7.5 HIGH· v2 This affects the package systeminformation before 4.30.2. The attacker can overwrite the properties and functions of an object, which can lead to executing OS commands. |
2Cdata Cdatatec2972408a Firmware 9008a Firmware9016a Firmware+26 moreNov 21, 2024 Nov 24, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 97168P, FD1002S, FD1104, FD1104B, FD1104S, FD1104SN, FD1108S, FD1204S-R2, FD1204SN, FD1204SN-R2, FD1208S...Show more |
1Vmware 5Cloud Foundation Identity ManagerIdentity Manager Connector+2 moreOct 30, 2025 Nov 23, 2020 N/A· v4 9.1 CRITICAL· v3 9.0 HIGH· v2 VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability. |
A vulnerability in the web-based management interface of Cisco DNA Spaces Connector could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insuffi...Show more |
1Trendmicro 1Interscan Web Security Virtual Appliance Nov 21, 2024 Nov 18, 2020 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 A command injection vulnerability in ModifyVLANItem of Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an authenticated, remote attacker to send specially crafted HTTP messages and execute arbitr...Show more |
1Trendmicro 1Interscan Web Security Virtual Appliance Nov 21, 2024 Nov 18, 2020 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 A command injection vulnerability in AddVLANItem of Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an authenticated, remote attacker to send specially crafted HTTP messages and execute arbitrary...Show more |
A vulnerability in the log subscription subsystem of Cisco AsyncOS for the Cisco Secure Web Appliance (formerly Web Security Appliance) could allow an authenticated, local attacker to perform command injection and elevat...Show more |
httpd on TP-Link TL-WPA4220 devices (versions 2 through 4) allows remote authenticated users to execute arbitrary OS commands by sending crafted POST requests to the endpoint /admin/powerline. Fixed version: TL-WPA4220(E...Show more |
5Apache DebianNetapp+2 more15Activemq Banking Cash ManagementBanking Corporate Lending Process Management+12 moreMay 23, 2025 Nov 16, 2020 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on b...Show more |
Privilege escalation of an authenticated user to root in Citrix SD-WAN center versions before 11.2.2, 11.1.2b and 10.2.8. |
1Citrix 1Virtual Apps And Desktops Nov 21, 2024 Nov 16, 2020 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 An unprivileged Windows user on the VDA or an SMB user can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285871 and CTX285872, 7.15 LTSR CU6 hotfix CTX285341 and CT...Show more |
If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. QTS versions prior to 4.4.3.1421 on build 20200907. |
If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. QTS versions prior to 4.4.3.1421 on build 20200907. |
1Couchbase 1Couchbase Server Nov 21, 2024 Nov 12, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Exposed Erlang Cookie could lead to Remote Command Execution (RCE) attack. Communication between Erlang nodes is done by exchanging a shared secret (aka "magic cookie"). There are cases where the magic cookie is included...Show more |
An OS command injection and memory corruption vulnerability in the PAN-OS management web interface that allows authenticated administrators to disrupt system processes and potentially execute arbitrary code and OS comman...Show more |