CWE-78
6,732 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CVEs (6,732)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2], based on DDNS type, the ddns->domain variable, that has the value of the d...Show more |
Liferay Portal Server tested on 7.3.5 GA6, 7.2.0 GA1 is affected by OS Command Injection. An administrator user can inject commands through the Gogo Shell module to execute any OS command on the Liferay Portal Sever. NOT...Show more |
Liferay Portal Server tested on 7.3.5 GA6, 7.2.0 GA1 is affected by OS Command Injection. An administrator user can inject Groovy script to execute any OS command on the Liferay Portal Sever. NOTE: The developer disputes...Show more |
Gerapy is a distributed crawler management framework. Prior to version 0.9.9, an authenticated user could execute arbitrary commands. This issue is fixed in version 0.9.9. There are no known workarounds. |
1Dell 1Emc Unity Operating Environment Jun 17, 2026 Jan 25, 2022 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authenticated remote code execution vulnerability. A remote malicious user with privileges may exploit this vulnerability to execute commands on the syste...Show more |
1Dell 1Emc Unity Operating Environment Jun 17, 2026 Jan 25, 2022 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authenticated remote code execution vulnerability. A remote malicious user with privileges may exploit this vulnerability to execute commands on the syste...Show more |
2Debian Freecadweb2Debian Linux FreecadJun 17, 2026 Jan 25, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 The Path Sanity Check script of FreeCAD 0.19 is vulnerable to OS command injection, allowing an attacker to execute arbitrary commands via a crafted FCStd document. |
2Debian Freecadweb2Debian Linux FreecadJun 17, 2026 Jan 25, 2022 N/A· v4 7.8 HIGH· v3 7.6 HIGH· v2 Improper sanitization in the invocation of ODA File Converter from FreeCAD 0.19 allows an attacker to inject OS commands via a crafted filename. |
lib/Image/ExifTool.pm in ExifTool before 12.38 mishandles a $file =~ /\|$/ check, leading to command injection. |
1Dell 3Emc Unity Operating Environment Emc Unity Xt Operating EnvironmentEmc Unityvsa Operating EnvironmentJun 17, 2026 Jan 24, 2022 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 Dell EMC Unity, Dell EMC UnityVSA and Dell EMC Unity XT versions prior to 5.1.2.0.5.007 contain an operating system (OS) command injection Vulnerability. A locally authenticated user with high privileges may potentially...Show more |
In QuickBox Pro v2.5.8 and below, the config.php file has a variable which takes a GET parameter value and parses it into a shell_exec(''); function without properly sanitizing any shell arguments, therefore remote code...Show more |
A command Injection Vulnerability in McAfee Agent (MA) for Windows prior to 5.7.5 allows local users to inject arbitrary shell code into the file cleanup.exe. The malicious clean.exe file is placed into the relevant fold...Show more |
IBM FileNet Content Manager 5.5.4, 5.5.6, and 5.5.7 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 212346. |
The files_antivirus component before 1.0.0 for ownCloud allows OS Command Injection via the administration settings. |
1Chinamobileltd 1An Lianbao Wf Firmware 1 Jun 17, 2026 Jan 14, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 China Mobile An Lianbao WF-1 router v1.0.1 is affected by an OS command injection vulnerability in the web interface /api/ZRUsb/pop_usb_device component. |
A malicious user on the same LAN could use DNS spoofing followed by a command injection attack to trick a NAS device into loading through an unsecured HTTP call. Addressed this vulnerability by disabling checks for inter...Show more |
Jenkins Docker Commons Plugin 1.17 and earlier does not sanitize the name of an image or a tag, resulting in an OS command execution vulnerability exploitable by attackers with Item/Configure permission or able to contro...Show more |
2Fedoraproject Pypa2Fedora PipenvJun 17, 2026 Jan 10, 2022 N/A· v4 8.6 HIGH· v3 9.3 HIGH· v2 pipenv is a Python development workflow tool. Starting with version 2018.10.9 and prior to version 2022.1.8, a flaw in pipenv's parsing of requirements files allows an attacker to insert a specially crafted string inside...Show more |
In Lens prior to 5.3.4, custom helm chart configuration creates helm commands from string concatenation of provided arguments which are then executed in the user's shell. Arguments can be provided which cause arbitrary s...Show more |
GLPI is an open source IT Asset Management, issue tracking system and service desk system. The GLPI addressing plugin in versions < 2.9.1 suffers from authenticated Remote Code Execution vulnerability, allowing access to...Show more |