CWE-78
6,732 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CVEs (6,732)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Gryphonconnect 1Gryphon Tower Firmware Jun 17, 2026 Dec 9, 2021 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 An unauthenticated command injection vulnerability exists in the parameters of operation 3 in the controller_server service on Gryphon Tower routers. An unauthenticated remote attacker on the same network can execute com...Show more |
1Gryphonconnect 1Gryphon Tower Firmware Jun 17, 2026 Dec 9, 2021 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 An unauthenticated command injection vulnerability exists in multiple parameters in the Gryphon Tower router’s web interface at /cgi-bin/luci/rc. An unauthenticated remote attacker on the same network can execute command...Show more |
A violation of secure design principles in Fortinet Meru AP version 8.6.1 and below, version 8.5.5 and below allows attacker to execute unauthorized code or commands via crafted cli commands. |
1Bosch 4Bosch Video Management System Video Recording ManagerVideojet Decoder 7513 Firmware+1 moreJun 17, 2026 Dec 8, 2021 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 A crafted configuration packet sent by an authenticated administrative user can be used to execute arbitrary commands in system context. This issue also affects installations of the VRM, DIVAR IP, BVMS with VRM installed...Show more |
Multiple command injection vulnerabilities in the command line interpreter of FortiWeb versions 6.4.1, 6.4.0, 6.3.0 through 6.3.15, 6.2.0 through 6.2.6, and 6.1.0 through 6.1.2 may allow an authenticated attacker to exec...Show more |
Multiple improper neutralization of special elements used in a command vulnerabilities [CWE-77] in FortiWeb management interface 6.4.1 and below, 6.3.15 and below, 6.2.5 and below may allow an authenticated attacker to e...Show more |
1Sonicwall 5Sma 200 Firmware Sma 210 FirmwareSma 400 Firmware+2 moreJun 17, 2026 Dec 8, 2021 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A post-authentication remote command injection vulnerability in SonicWall SMA100 allows a remote authenticated attacker to execute OS system commands in the appliance. This vulnerability affected SMA 200, 210, 400, 410 a...Show more |
1Sonicwall 5Sma 200 Firmware Sma 210 FirmwareSma 400 Firmware+2 moreJun 17, 2026 Dec 8, 2021 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 Improper neutralization of special elements in the SMA100 management interface '/cgi-bin/viewcert' POST http method allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user. This vulnerabili...Show more |
Git-it through 4.4.0 allows OS command injection at the Branches Aren't Just For Birds challenge step. During the verification process, it attempts to run the reflog command followed by the current branch name (which is...Show more |
1Github Todos Project 1Github Todos Jun 17, 2026 Dec 7, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 naholyr github-todos 3.1.0 is vulnerable to command injection. The range argument for the _hook subcommand is concatenated without any validation, and is directly used by the exec function. |
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Multiple functions in the bpserverd daemon were vulnerable to arbitrary remote code execution as root. The vulnerability was caused by untrusted...Show more |
1Elecom 14Edwrc 2533gst2 Firmware Wrc 1167gst2 FirmwareWrc 1167gst2a Firmware+11 moreJun 17, 2026 Dec 1, 2021 N/A· v4 8.0 HIGH· v3 7.7 HIGH· v2 OS command injection vulnerability in ELECOM routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior, WRC-2533GS2-B firmware v1.52 and prior, WRC-253...Show more |
1Elecom 14Edwrc 2533gst2 Firmware Wrc 1167gst2 FirmwareWrc 1167gst2a Firmware+11 moreJun 17, 2026 Dec 1, 2021 N/A· v4 8.0 HIGH· v3 7.7 HIGH· v2 ELECOM LAN routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior, WRC-2533GS2-B firmware v1.52 and prior, WRC-2533GS2-W firmware v1.52 and prior, W...Show more |
1Elecom 2Wrh 733gbk Firmware Wrh 733gwh FirmwareJun 17, 2026 Dec 1, 2021 N/A· v4 6.8 MEDIUM· v3 5.2 MEDIUM· v2 ELECOM LAN routers (WRH-733GBK firmware v1.02.9 and prior and WRH-733GWH firmware v1.02.9 and prior) allows a network-adjacent attacker with an administrator privilege to execute arbitrary OS commands via unspecified vec...Show more |
1Elecom 2Wrh 733gbk Firmware Wrh 733gwh FirmwareJun 17, 2026 Dec 1, 2021 N/A· v4 6.8 MEDIUM· v3 5.2 MEDIUM· v2 ELECOM LAN routers (WRH-733GBK firmware v1.02.9 and prior and WRH-733GWH firmware v1.02.9 and prior) allows a network-adjacent attacker with an administrator privilege to execute arbitrary OS commands via unspecified vec...Show more |
An issue was discovered on Victure WR1200 devices through 1.0.3. A command injection vulnerability was found within the web interface of the device, allowing an attacker with valid credentials to inject arbitrary shell c...Show more |
This issue was discovered when the ipTIME C200 IP Camera was synchronized with the ipTIME NAS. It is necessary to extract value for ipTIME IP camera because the ipTIME NAS send ans setCookie('[COOKIE]') . The value is tr...Show more |
# Vulnerability in `pygmalion`, `pygmalion-virtualenv` and `refined` themes **Description**: these themes use `print -P` on user-supplied strings to print them to the terminal. All of them do that on git information, par...Show more |
# Vulnerability in `rand-quote` and `hitokoto` plugins **Description**: the `rand-quote` and `hitokoto` fetch quotes from quotationspage.com and hitokoto.cn respectively, do some process on them and then use `print -P` t...Show more |
# Vulnerability in `title` function **Description**: the `title` function defined in `lib/termsupport.zsh` uses `print` to set the terminal title to a user-supplied string. In Oh My Zsh, this function is always used secu...Show more |