CWE-78
6,722 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CVEs (6,722)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Mimosa 3B5 Firmware B5c FirmwareC5c FirmwareJun 17, 2026 Jul 20, 2021 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 The web console for Mimosa B5, B5c, and C5x firmware through 2.8.0.2 allows authenticated command injection in the Throughput, WANStats, PhyStats, and QosStats API classes. An attacker with access to a web console accoun...Show more |
An instance of improper neutralization of special elements in the sniffer module of FortiSandbox before 3.2.2 may allow an authenticated administrator to execute commands on the underlying system's shell via altering the...Show more |
1Dell 1Emc Openmanage Enterprise Modular Jun 17, 2026 Jul 19, 2021 N/A· v4 9.1 CRITICAL· v3 9.0 HIGH· v2 Dell EMC OpenManage Enterprise-Modular (OME-M) versions prior to 1.10.00 contain a command injection vulnerability. A remote authenticated malicious user with high privileges could potentially exploit the vulnerability t...Show more |
Dell EMC PowerStore versions prior to 1.0.3.0.5.006 contain an OS Command Injection vulnerability in PowerStore X environment . A locally authenticated attacker could potentially exploit this vulnerability, leading to th...Show more |
2Fail2ban Fedoraproject2Fail2ban FedoraJun 17, 2026 Jul 16, 2021 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 fail2ban is a daemon to ban hosts that cause multiple authentication errors. In versions 0.9.7 and prior, 0.10.0 through 0.10.6, and 0.11.0 through 0.11.2, there is a vulnerability that leads to possible remote code exec...Show more |
A code execution vulnerability exists in the Libcli Test Environment functionality of D-LINK DIR-3040 1.13B03. A specially crafted network request can lead to arbitrary command execution. An attacker can send a sequence...Show more |
A command injection vulnerability in the sandcat plugin of Caldera 2.3.1 and earlier allows authenticated attackers to execute any command or service. |
An improper neutralization of special elements used in an OS Command vulnerability in the administrative interface of FortiMail before 6.4.4 may allow an authenticated attacker to execute unauthorized commands via specif...Show more |
1Fortinet 3Fortiap Fortiap SFortiap W2Jun 17, 2026 Jul 9, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 An improper neutralization of special elements used in an OS Command vulnerability in FortiAP's console 6.4.1 through 6.4.5 and 6.2.4 through 6.2.5 may allow an authenticated attacker to execute unauthorized commands by...Show more |
1Arubanetworks 1Clearpass Policy Manager Jun 17, 2026 Jul 8, 2021 N/A· v4 6.3 MEDIUM· v3 6.5 MEDIUM· v2 A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this s...Show more |
1Arubanetworks 1Clearpass Policy Manager Jun 17, 2026 Jul 8, 2021 N/A· v4 6.3 MEDIUM· v3 6.5 MEDIUM· v2 A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this s...Show more |
1Arubanetworks 1Clearpass Policy Manager Jun 17, 2026 Jul 8, 2021 N/A· v4 6.3 MEDIUM· v3 6.5 MEDIUM· v2 A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this s...Show more |
1Arubanetworks 1Clearpass Policy Manager Jun 17, 2026 Jul 8, 2021 N/A· v4 6.3 MEDIUM· v3 6.5 MEDIUM· v2 A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this s...Show more |
1Arubanetworks 1Clearpass Policy Manager Jun 17, 2026 Jul 8, 2021 N/A· v4 6.3 MEDIUM· v3 6.5 MEDIUM· v2 A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this s...Show more |
1Arubanetworks 1Clearpass Policy Manager Jun 17, 2026 Jul 8, 2021 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this s...Show more |
1Arubanetworks 1Clearpass Policy Manager Jun 17, 2026 Jul 8, 2021 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this s...Show more |
QSAN SANOS factory reset function does not filter special parameters. Remote attackers can use this vulnerability to inject and execute arbitrary commands without permissions. The referred vulnerability has been solved w...Show more |
The QSAN SANOS setting page does not filter special parameters. Remote attackers can use this vulnerability to inject and execute arbitrary commands without permissions. The referred vulnerability has been solved with th...Show more |
OS command injection vulnerability in Init function in QSAN XEVO allows remote attackers to execute arbitrary commands without permissions. The referred vulnerability has been solved with the updated version of QSAN XEVO...Show more |
OS command injection vulnerability in Array function in QSAN XEVO allows remote unauthenticated attackers to execute arbitrary commands via status parameter. The referred vulnerability has been solved with the updated ve...Show more |