CWE-78
5,953 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CVEs (5,953)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Microsoft 2Windows 10 Windows Server 2016Nov 21, 2024 Nov 11, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Win32k Elevation of Privilege Vulnerability |
tdpServer on TP-Link Archer A7 AC1750 devices before 201029 allows remote attackers to execute arbitrary code via the slave_mac parameter. NOTE: this issue exists because of an incomplete fix for CVE-2020-10882 in which...Show more |
1Cisco 1Integrated Management Controller Nov 21, 2024 Nov 6, 2020 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A vulnerability in the web UI of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to inject arbitrary code and execute arbitrary commands at the underlying operating system level...Show more |
4Debian FedoraprojectOpensuse+1 more4Debian Linux FedoraLeap+1 moreNov 7, 2025 Nov 6, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection. |
1Fruitywifi Project 1Fruitywifi Nov 21, 2024 Nov 5, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A remote code execution vulnerability is identified in FruityWifi through 2.4. Due to improperly escaped shell metacharacters obtained from the POST request at the page_config_adv.php page, it is possible to perform remo...Show more |
If exploited, this command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Music Station versions prior to 5.1.13; versions prior to 5.2.9; versio...Show more |
MailGates and MailAudit products contain Command Injection flaw, which can be used to inject and execute system commands from the cgi parameter after attackers obtain the user’s access token. |
An issue was discovered in EyesOfNetwork 5.3 through 5.3-8. An authenticated web user with sufficient privileges could abuse the AutoDiscovery module to run arbitrary OS commands via the nmap_binary parameter to lilac/au...Show more |
1Westerndigital 1My Cloud Firmware Nov 21, 2024 Oct 29, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An issue was discovered on Western Digital My Cloud NAS devices before 5.04.114. They allow remote code execution with resultant escalation of privileges. |
If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201...Show more |
1Winstonprivacy 1Winston Firmware Nov 21, 2024 Oct 28, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Winston 1.5.4 devices are vulnerable to command injection via the API. |
osCommerce Phoenix CE before 1.0.5.4 allows OS command injection remotely. Within admin/mail.php, a from POST parameter can be passed to the application. This affects the PHP mail function, and the sendmail -f option. |
1Westerndigital 1My Cloud Firmware Nov 21, 2024 Oct 27, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Addressed remote code execution vulnerability in DsdkProxy.php due to insufficient sanitization and insufficient validation of user input in Western Digital My Cloud NAS devices prior to 5.04.114 |
1Westerndigital 1My Cloud Firmware Nov 21, 2024 Oct 27, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Addressed remote code execution vulnerability in cgi_api.php that allowed escalation of privileges in Western Digital My Cloud NAS devices prior to 5.04.114. |
1Westerndigital 1My Cloud Firmware Nov 21, 2024 Oct 27, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Addressed remote code execution vulnerability in reg_device.php due to insufficient validation of user input.in Western Digital My Cloud Devices prior to 5.4.1140. |
Ruckus through 1.5.1.0.21 is affected by remote command injection. An authenticated user can submit a query to the API (/service/v1/createUser endpoint), injecting arbitrary commands that will be executed as root user vi...Show more |
1Git Tag Annotation Action Project 1Git Tag Annotation Action Nov 21, 2024 Oct 26, 2020 N/A· v4 9.6 CRITICAL· v3 6.5 MEDIUM· v2 In the git-tag-annotation-action (open source GitHub Action) before version 1.0.1, an attacker can execute arbitrary (*) shell commands if they can control the value of [the `tag` input] or manage to alter the value of [...Show more |
In lookatme (python/pypi package) versions prior to 2.3.0, the package automatically loaded the built-in "terminal" and "file_loader" extensions. Users that use lookatme to render untrusted markdown may have malicious sh...Show more |
1Systeminformation 1Systeminformation Nov 21, 2024 Oct 26, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 This affects the package systeminformation before 4.27.11. This package is vulnerable to Command Injection. The attacker can concatenate curl's parameters to overwrite Javascript files and then execute any OS commands. |
1Cisco 1Firepower Extensible Operating System Nov 21, 2024 Oct 21, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges. The vulnerability is due to insufficient input validatio...Show more |