CWE-78
6,716 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CVEs (6,716)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The gnuplot package prior to version 0.1.0 for Node.js allows code execution via shell metacharacters in Gnuplot commands. |
1Dell 1Openmanage Enterprise Modular Jun 17, 2026 Apr 30, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Dell OpenManage Enterprise-Modular (OME-M) versions prior to 1.30.00 contain a security bypass vulnerability. An authenticated malicious user with low privileges may potentially exploit the vulnerability to escape from t...Show more |
1Systeminformation 1Systeminformation Jun 17, 2026 Apr 29, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 systeminformation is an open source system and OS information library for node.js. A command injection vulnerability has been discovered in versions of systeminformation prior to 5.6.4. The issue has been fixed with a pa...Show more |
1Cisco 3Adaptive Security Appliance Software Firepower Threat DefenseSecure Firewall Threat DefenseAug 11, 2026 Apr 29, 2021 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 A vulnerability in the upgrade process of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to inject commands that could be e...Show more |
1Cisco 3Adaptive Security Appliance Software Firepower Threat DefenseSecure Firewall Threat DefenseAug 11, 2026 Apr 29, 2021 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 A vulnerability in the CLI of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands on the underlyin...Show more |
1Cisco 2Firepower Threat Defense Secure Firewall Threat DefenseAug 11, 2026 Apr 29, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges on the underlying operating system of an affecte...Show more |
1Chinamobile 1An Lianbao Wf 1 Firmware Jun 17, 2026 Apr 29, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The api/ZRIGMP/set_MLD_PROXY interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the MLD_PROXY_WAN_CONNECT parameter. |
1Chinamobile 1An Lianbao Wf 1 Firmware Jun 17, 2026 Apr 29, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The api/ZRIptv/setIptvInfo interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the iptv_vlan parameter. |
1Chinamobile 1An Lianbao Wf 1 Firmware Jun 17, 2026 Apr 29, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The api/ZRIGMP/set_IGMP_PROXY interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the IGMP_PROXY_WAN_CONNECT parameter. |
1Chinamobile 1An Lianbao Wf 1 Firmware Jun 17, 2026 Apr 29, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The api/zrDm/set_ZRElink interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the bssaddr, abiaddr, devtoken, devid, elinksync, or elink...Show more |
1Chinamobile 1An Lianbao Wf 1 Firmware Jun 17, 2026 Apr 29, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The api/ZRFirmware/set_time_zone interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the zonename parameter. |
1Chinamobile 1An Lianbao Wf 1 Firmware Jun 17, 2026 Apr 29, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The api/zrDm/set_zrDm interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the dm_enable, AppKey, or Pwd parameter. |
1Chinamobile 1An Lianbao Wf 1 Firmware Jun 17, 2026 Apr 29, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The api/ZRAndlink/set_ZRAndlink interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the iandlink_proc_enable parameter. |
1Inim 6Smartliving 10100l Firmware Smartliving 10100lg3 FirmwareSmartliving 1050 Firmware+3 moreJun 17, 2026 Apr 29, 2021 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 Inim Electronics SmartLiving SmartLAN/G/SI <=6.x suffers from an authenticated remote command injection vulnerability. The issue exist due to the 'par' POST parameter not being sanitized when called with the 'testemail'...Show more |
A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s) prior to 6.9.5, 6.8.9, 6.7.14-HF1. Aruba has released patches for Aruba ClearPass Policy Manager that address...Show more |
A remote unauthorized access vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerabi...Show more |
A remote unauthorized access vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerabi...Show more |
Prisma is an open source ORM for Node.js & TypeScript. As of today, we are not aware of any Prisma users or external consumers of the `@prisma/sdk` package who are affected by this security vulnerability. This issue may...Show more |
1Meritlilin 41P2g1022 Firmware P2g1022x FirmwareP2g1052 Firmware+38 moreJun 17, 2026 Apr 28, 2021 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 The NTP Server configuration function of the IP camera device is not verified with special parameters. Remote attackers can perform a command Injection attack and execute arbitrary commands after logging in with the priv...Show more |
1Homeautomation Project 1Homeautomation Jun 17, 2026 Apr 27, 2021 N/A· v4 8.0 HIGH· v3 8.5 HIGH· v2 HomeAutomation 3.3.2 suffers from an authenticated OS command execution vulnerability using custom command v0.1 plugin. This can be exploited with a CSRF vulnerability to execute arbitrary shell commands as the web user...Show more |