CWE-78
6,716 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CVEs (6,716)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Symantec 1Security Analytics Jun 17, 2026 Apr 27, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An input validation flaw in the Symantec Security Analytics web UI 7.2 prior 7.2.7, 8.1, prior to 8.1.3-NSR3, 8.2, prior to 8.2.1-NSR2 or 8.2.2 allows a remote, unauthenticated attacker to execute arbitrary OS commands o...Show more |
1Nec 1Aterm Wg2600hs Firmware Jun 17, 2026 Apr 26, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Aterm WG2600HS firmware Ver1.5.1 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors. |
1Nec 3Aterm Wf1200cr Firmware Aterm Wg1200cr FirmwareAterm Wg2600hs FirmwareJun 17, 2026 Apr 26, 2021 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 NEC Aterm devices (Aterm WF1200CR firmware Ver1.3.2 and earlier, Aterm WG1200CR firmware Ver1.3.3 and earlier, and Aterm WG2600HS firmware Ver1.5.1 and earlier) allow authenticated attackers to execute arbitrary OS comma...Show more |
DAP-1880AC firmware version 1.21 and earlier allows a remote authenticated attacker to execute arbitrary OS commands by sending a specially crafted request to a specific CGI program. |
1Avaya 1Session Border Controller For Enterprise Jun 17, 2026 Apr 23, 2021 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A command injection vulnerability in Avaya Session Border Controller for Enterprise could allow an authenticated, remote attacker to send specially crafted messages and execute arbitrary commands with the affected system...Show more |
2Fedoraproject Saltstack2Fedora SaltJun 17, 2026 Apr 23, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 In SaltStack Salt 2016.9 through 3002.6, a command injection vulnerability exists in the snapper module that allows for local privilege escalation on a minion. The attack requires that a file is created with a pathname t...Show more |
An unvalidated REST API in the AppFormix Agent of Juniper Networks AppFormix allows an unauthenticated remote attacker to execute commands as root on the host running the AppFormix Agent, when certain preconditions are p...Show more |
Discord-Recon is a bot for the Discord chat service. Versions of Discord-Recon 0.0.3 and prior contain a vulnerability in which a remote attacker is able to overwrite any file on the system with the command results. This...Show more |
A remote code execution vulnerability in the installUpdateThemePluginAction function in index.php in WonderCMS 3.1.3, allows remote attackers to upload a custom plugin which can contain arbitrary code and obtain a webshe...Show more |
Dell PowerScale OneFS 8.1.0 - 9.1.0 contains a privilege escalation in SmartLock compliance mode that may allow compadmin to execute arbitrary commands as root. |
1Fibaro 2Home Center 2 Firmware Home Center Lite FirmwareJun 17, 2026 Apr 19, 2021 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 In Fibaro Home Center 2 and Lite devices with firmware version 4.540 and older an authenticated user can run commands as root user using a command injection vulnerability. |
This affects all versions of package killing. If attacker-controlled user input is given, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input...Show more |
1Roar Pidusage Project 1Roar Pidusage Jun 17, 2026 Apr 18, 2021 N/A· v4 7.3 HIGH· v3 7.5 HIGH· v2 This affects all versions of package roar-pidusage. If attacker-controlled user input is given to the stat function of this package on certain operating systems, it is possible for an attacker to execute arbitrary comman...Show more |
1Portkiller Project 1Portkiller Jun 17, 2026 Apr 18, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 This affects all versions of package portkiller. If (attacker-controlled) user input is given, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without i...Show more |
This affects all versions of package picotts. If attacker-controlled user input is given to the say function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec fun...Show more |
1Onion Oled Js Project 1Onion Oled Js Jun 17, 2026 Apr 18, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 This affects all versions of package onion-oled-js. If attacker-controlled user input is given to the scroll function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process...Show more |
1Ffmpegdotjs Project 1Ffmpegdotjs Jun 17, 2026 Apr 18, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 This affects all versions of package ffmpegdotjs. If attacker-controlled user input is given to the trimvideo function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_proces...Show more |
This affects all versions of package psnode. If attacker-controlled user input is given to the kill function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec fun...Show more |
1Ps Visitor Project 1Ps Visitor Jun 17, 2026 Apr 18, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 This affects all versions of package ps-visitor. If attacker-controlled user input is given to the kill function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec...Show more |
A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. We have already fixed this vu...Show more |