← Back
CWE-78

6,732 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

JSON object

Loading...

CVEs (6,732)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Reolink
1Rlc 410w Firmware
Jun 17, 2026
Jan 28, 2022
N/A· v4
7.2 HIGH· v3
7.5 HIGH· v2
An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2], based on DDNS type, the ddns->domain variable, that has the value of the d...Show more
An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2], based on DDNS type, the ddns->domain variable, that has the value of the domain parameter provided through the SetDdns API, is not validated properly. This would lead to an OS command injection. An attacker can send an HTTP request to trigger this vulnerability.Show less
1Liferay
1Liferay Portal
Jun 17, 2026
Jan 28, 2022
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
Liferay Portal Server tested on 7.3.5 GA6, 7.2.0 GA1 is affected by OS Command Injection. An administrator user can inject commands through the Gogo Shell module to execute any OS command on the Liferay Portal Sever. NOT...Show more
Liferay Portal Server tested on 7.3.5 GA6, 7.2.0 GA1 is affected by OS Command Injection. An administrator user can inject commands through the Gogo Shell module to execute any OS command on the Liferay Portal Sever. NOTE: The developer disputes this as a vulnerability since it is a feature for administrators to access and execute commands in Gogo Shell and therefore not a design flaShow less
1Liferay
1Liferay Portal
Jun 17, 2026
Jan 28, 2022
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
Liferay Portal Server tested on 7.3.5 GA6, 7.2.0 GA1 is affected by OS Command Injection. An administrator user can inject Groovy script to execute any OS command on the Liferay Portal Sever. NOTE: The developer disputes...Show more
Liferay Portal Server tested on 7.3.5 GA6, 7.2.0 GA1 is affected by OS Command Injection. An administrator user can inject Groovy script to execute any OS command on the Liferay Portal Sever. NOTE: The developer disputes this as a vulnerability since it is a feature for administrators to run groovy scripts and therefore not a design flaw.Show less
1Gerapy
1Gerapy
Jun 17, 2026
Jan 26, 2022
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Gerapy is a distributed crawler management framework. Prior to version 0.9.9, an authenticated user could execute arbitrary commands. This issue is fixed in version 0.9.9. There are no known workarounds.
1Dell
1Emc Unity Operating Environment
Jun 17, 2026
Jan 25, 2022
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authenticated remote code execution vulnerability. A remote malicious user with privileges may exploit this vulnerability to execute commands on the syste...Show more
Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authenticated remote code execution vulnerability. A remote malicious user with privileges may exploit this vulnerability to execute commands on the system.Show less
1Dell
1Emc Unity Operating Environment
Jun 17, 2026
Jan 25, 2022
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authenticated remote code execution vulnerability. A remote malicious user with privileges may exploit this vulnerability to execute commands on the syste...Show more
Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authenticated remote code execution vulnerability. A remote malicious user with privileges may exploit this vulnerability to execute commands on the system.Show less
2Debian
Freecadweb
2Debian Linux
Freecad
Jun 17, 2026
Jan 25, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
The Path Sanity Check script of FreeCAD 0.19 is vulnerable to OS command injection, allowing an attacker to execute arbitrary commands via a crafted FCStd document.
2Debian
Freecadweb
2Debian Linux
Freecad
Jun 17, 2026
Jan 25, 2022
N/A· v4
7.8 HIGH· v3
7.6 HIGH· v2
Improper sanitization in the invocation of ODA File Converter from FreeCAD 0.19 allows an attacker to inject OS commands via a crafted filename.
1Exiftool Project
1Exiftool
Jun 17, 2026
Jan 25, 2022
N/A· v4
7.8 HIGH· v3
7.6 HIGH· v2
lib/Image/ExifTool.pm in ExifTool before 12.38 mishandles a $file =~ /\|$/ check, leading to command injection.
1Dell
3Emc Unity Operating Environment
Emc Unity Xt Operating EnvironmentEmc Unityvsa Operating Environment
Jun 17, 2026
Jan 24, 2022
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
Dell EMC Unity, Dell EMC UnityVSA and Dell EMC Unity XT versions prior to 5.1.2.0.5.007 contain an operating system (OS) command injection Vulnerability. A locally authenticated user with high privileges may potentially...Show more
Dell EMC Unity, Dell EMC UnityVSA and Dell EMC Unity XT versions prior to 5.1.2.0.5.007 contain an operating system (OS) command injection Vulnerability. A locally authenticated user with high privileges may potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the Unity underlying OS, with the privileges of the vulnerable application. Exploitation may lead to an elevation of privilege.Show less
1Quickbox
1Quickbox
Jun 17, 2026
Jan 24, 2022
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
In QuickBox Pro v2.5.8 and below, the config.php file has a variable which takes a GET parameter value and parses it into a shell_exec(''); function without properly sanitizing any shell arguments, therefore remote code...Show more
In QuickBox Pro v2.5.8 and below, the config.php file has a variable which takes a GET parameter value and parses it into a shell_exec(''); function without properly sanitizing any shell arguments, therefore remote code execution is possible. Additionally, as the media server is running as root by default attackers can use the sudo command within this shell_exec(''); function, which allows for privilege escalation by means of RCE.Show less
1Mcafee
1Agent
Jun 17, 2026
Jan 19, 2022
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
A command Injection Vulnerability in McAfee Agent (MA) for Windows prior to 5.7.5 allows local users to inject arbitrary shell code into the file cleanup.exe. The malicious clean.exe file is placed into the relevant fold...Show more
A command Injection Vulnerability in McAfee Agent (MA) for Windows prior to 5.7.5 allows local users to inject arbitrary shell code into the file cleanup.exe. The malicious clean.exe file is placed into the relevant folder and executed by running the McAfee Agent deployment feature located in the System Tree. An attacker may exploit the vulnerability to obtain a reverse shell which can lead to privilege escalation to obtain root privileges.Show less
1Ibm
1Filenet Content Manager
Jun 17, 2026
Jan 17, 2022
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
IBM FileNet Content Manager 5.5.4, 5.5.6, and 5.5.7 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 212346.
1Owncloud
1Files Antivirus
Jun 17, 2026
Jan 15, 2022
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
The files_antivirus component before 1.0.0 for ownCloud allows OS Command Injection via the administration settings.
1Chinamobileltd
1An Lianbao Wf Firmware 1
Jun 17, 2026
Jan 14, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
China Mobile An Lianbao WF-1 router v1.0.1 is affected by an OS command injection vulnerability in the web interface /api/ZRUsb/pop_usb_device component.
1Westerndigital
1My Cloud Os
Jun 17, 2026
Jan 13, 2022
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
A malicious user on the same LAN could use DNS spoofing followed by a command injection attack to trick a NAS device into loading through an unsecured HTTP call. Addressed this vulnerability by disabling checks for inter...Show more
A malicious user on the same LAN could use DNS spoofing followed by a command injection attack to trick a NAS device into loading through an unsecured HTTP call. Addressed this vulnerability by disabling checks for internet connectivity using HTTP.Show less
1Jenkins
1Docker Commons
Jun 17, 2026
Jan 12, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Jenkins Docker Commons Plugin 1.17 and earlier does not sanitize the name of an image or a tag, resulting in an OS command execution vulnerability exploitable by attackers with Item/Configure permission or able to contro...Show more
Jenkins Docker Commons Plugin 1.17 and earlier does not sanitize the name of an image or a tag, resulting in an OS command execution vulnerability exploitable by attackers with Item/Configure permission or able to control the contents of a previously configured job's SCM repository.Show less
2Fedoraproject
Pypa
2Fedora
Pipenv
Jun 17, 2026
Jan 10, 2022
N/A· v4
8.6 HIGH· v3
9.3 HIGH· v2
pipenv is a Python development workflow tool. Starting with version 2018.10.9 and prior to version 2022.1.8, a flaw in pipenv's parsing of requirements files allows an attacker to insert a specially crafted string inside...Show more
pipenv is a Python development workflow tool. Starting with version 2018.10.9 and prior to version 2022.1.8, a flaw in pipenv's parsing of requirements files allows an attacker to insert a specially crafted string inside a comment anywhere within a requirements.txt file, which will cause victims who use pipenv to install the requirements file to download dependencies from a package index server controlled by the attacker. By embedding malicious code in packages served from their malicious index server, the attacker can trigger arbitrary remote code execution (RCE) on the victims' systems. If an attacker is able to hide a malicious `--index-url` option in a requirements file that a victim installs with pipenv, the attacker can embed arbitrary malicious code in packages served from their malicious index server that will be executed on the victim's host during installation (remote code execution/RCE). When pip installs from a source distribution, any code in the setup.py is executed by the install process. This issue is patched in version 2022.1.8. The GitHub Security Advisory contains more information about this vulnerability.Show less
1Mirantis
1Lens
Jun 17, 2026
Jan 10, 2022
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
In Lens prior to 5.3.4, custom helm chart configuration creates helm commands from string concatenation of provided arguments which are then executed in the user's shell. Arguments can be provided which cause arbitrary s...Show more
In Lens prior to 5.3.4, custom helm chart configuration creates helm commands from string concatenation of provided arguments which are then executed in the user's shell. Arguments can be provided which cause arbitrary shell commands to run on the system.Show less
1Teclib Edition
1Addressing
Jun 17, 2026
Jan 5, 2022
N/A· v4
9.9 CRITICAL· v3
9.0 HIGH· v2
GLPI is an open source IT Asset Management, issue tracking system and service desk system. The GLPI addressing plugin in versions < 2.9.1 suffers from authenticated Remote Code Execution vulnerability, allowing access to...Show more
GLPI is an open source IT Asset Management, issue tracking system and service desk system. The GLPI addressing plugin in versions < 2.9.1 suffers from authenticated Remote Code Execution vulnerability, allowing access to the server's underlying operating system using command injection abuse of functionality. There is no workaround for this issue and users are advised to upgrade or to disable the addressing plugin.Show less