CWE-78
6,737 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CVEs (6,737)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The affected On-Premise cnMaestro is vulnerable to an arbitrary file-write through improper limitation of a pathname to a restricted directory inside a specific route. If an attacker supplied path traversal charters (../...Show more |
The affected On-Premise cnMaestro allows an unauthenticated attacker to access the cnMaestro server and execute arbitrary code in the privileges of the web server. This lack of validation could allow an attacker to appen...Show more |
cnMaestro is vulnerable to a local privilege escalation. By default, a user does not have root privileges. However, a user can run scripts as sudo, which could allow an attacker to gain root privileges when running user...Show more |
1Fidelissecurity 2Deception NetworkJun 17, 2026 May 17, 2022 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface using the “update_checkfile” value for the “filename” parameter. The vulnerability could allow...Show more |
1Fidelissecurity 2Deception NetworkJun 17, 2026 May 17, 2022 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface using the “check_vertica_upgrade” value for the “cpIp” parameter. The vulnerability could allow...Show more |
1Fidelissecurity 2Deception NetworkJun 17, 2026 May 17, 2022 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface using the “feed_comm_test” value for the “feed” parameter. The vulnerability could allow a spec...Show more |
1Fidelissecurity 2Deception NetworkJun 17, 2026 May 17, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Vulnerability in rconfig “remote_text_file” enables an attacker with user level access to the CLI to inject user level commands into Fidelis Network and Deception CommandPost, Collector, Sensor, and Sandbox components as...Show more |
1Fidelissecurity 2Deception NetworkJun 17, 2026 May 17, 2022 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 Vulnerability in rconfig “cert_utils” enables an attacker with user level access to the CLI to inject root level commands into Fidelis Network and Deception CommandPost, Collector, Sensor, and Sandbox components as well...Show more |
1Fidelissecurity 2Deception NetworkJun 17, 2026 May 17, 2022 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 Vulnerability in rconfig “date” enables an attacker with user level access to the CLI to inject root level commands into Fidelis Network and Deception CommandPost, Collector, Sensor, and Sandbox components as well as nei...Show more |
1Arubanetworks 1Clearpass Policy Manager Jun 17, 2026 May 17, 2022 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to C...Show more |
1Arubanetworks 1Clearpass Policy Manager Jun 17, 2026 May 17, 2022 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to C...Show more |
1Arubanetworks 1Clearpass Policy Manager Jun 17, 2026 May 16, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to C...Show more |
1Arubanetworks 1Clearpass Policy Manager Jun 17, 2026 May 16, 2022 N/A· v4 9.1 CRITICAL· v3 9.0 HIGH· v2 A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to C...Show more |
1Arubanetworks 1Clearpass Policy Manager Jun 17, 2026 May 16, 2022 N/A· v4 9.1 CRITICAL· v3 9.0 HIGH· v2 A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to C...Show more |
1Arubanetworks 1Clearpass Policy Manager Jun 17, 2026 May 16, 2022 N/A· v4 9.1 CRITICAL· v3 9.0 HIGH· v2 A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to C...Show more |
1Arubanetworks 1Clearpass Policy Manager Jun 17, 2026 May 16, 2022 N/A· v4 9.1 CRITICAL· v3 9.0 HIGH· v2 A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to C...Show more |
1Arubanetworks 1Clearpass Policy Manager Jun 17, 2026 May 16, 2022 N/A· v4 9.1 CRITICAL· v3 9.0 HIGH· v2 A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to C...Show more |
1Arubanetworks 1Clearpass Policy Manager Jun 17, 2026 May 16, 2022 N/A· v4 9.1 CRITICAL· v3 9.0 HIGH· v2 A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to C...Show more |
1Feminer Wms Project 1Feminer Wms Jun 17, 2026 May 16, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A remote command execution (RCE) vulnerability was found in FeMiner wms V1.0 in /wms/src/system/datarec.php. The $_POST[r_name] is directly passed into the $mysqlstr and is executed by exec. |
Certain Anaconda3 2021.05 are affected by OS command injection. When a user installs Anaconda, an attacker can create a new file and write something in usercustomize.py. When the user opens the terminal or activates Anac...Show more |