CWE-78
6,715 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CVEs (6,715)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An issue was discovered in Scytl sVote 2.1. An attacker can inject code that gets executed by creating an election-event and injecting a payload over an event alias, because the application calls Runtime.getRuntime().exe...Show more |
PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.2 there is a CSV Injection vulnerability possible by using shop search keywords via the admin panel. The problem is fixed i...Show more |
1Contec 1Sv Cpt Mc310 Firmware Jun 17, 2026 Feb 24, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to execute arbitrary OS commands with the web server privilege via unspecified vectors. |
1Arubanetworks 1Clearpass Policy Manager Jun 17, 2026 Feb 23, 2021 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the ClearPass web-based management interface a...Show more |
1Arubanetworks 1Clearpass Policy Manager Jun 17, 2026 Feb 23, 2021 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the ClearPass web-based management interface a...Show more |
1Arubanetworks 1Clearpass Policy Manager Jun 17, 2026 Feb 23, 2021 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the ClearPass web-based management interface a...Show more |
1Arubanetworks 1Clearpass Policy Manager Jun 17, 2026 Feb 23, 2021 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the ClearPass web-based management interface a...Show more |
1Arubanetworks 1Clearpass Policy Manager Jun 17, 2026 Feb 23, 2021 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 A remote authenticated command Injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the ClearPass CLI could allow remote authentic...Show more |
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none |
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none |
1Geojson2kml Project 1Geojson2kml Jun 17, 2026 Feb 23, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 All versions of package geojson2kml are vulnerable to Command Injection via the index.js file. PoC: var a =require("geojson2kml"); a("./","& touch JHU",function(){}) |
1Nozominetworks 2Central Management Control GuardianJun 17, 2026 Feb 22, 2021 8.6 HIGH· v4 7.2 HIGH· v3 9.0 HIGH· v2 OS Command Injection vulnerability when changing date settings or hostname using web GUI of Nozomi Networks Guardian and CMC allows authenticated administrators to perform remote code execution. This issue affects: Nozom...Show more |
On Netshield NANO 25 10.2.18 devices, /usr/local/webmin/System/manual_ping.cgi allows OS command injection (after authentication by the attacker) because the system C library function is used unsafely. |
1Amaze File Manager Project 1Amaze File Manager Jun 17, 2026 Feb 19, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Amaze File Manager before 3.5.1 allows attackers to obtain root privileges via shell metacharacters in a symbolic link. |
1Alleghenycreative 1Openrepeater Jun 17, 2026 Feb 19, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 OpenRepeater (ORP) before 2.2 allows unauthenticated command injection via shell metacharacters in the functions/ajax_system.php post_service parameter. |
1Netis Systems 2Wf2411 Firmware Wf2780 FirmwareJun 17, 2026 Feb 18, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Netis WF2780 2.3.40404 and WF2411 1.1.29629 devices allow Shell Metacharacter Injection into the ping command, leading to remote code execution. |
1Async Git Project 1Async Git Jun 17, 2026 Feb 18, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The package async-git before 1.13.2 are vulnerable to Command Injection via shell meta-characters (back-ticks). For example: git.reset('atouch HACKEDb') |
A command injection issue in dji_sys in DJI Mavic 2 Remote Controller before firmware version 01.00.0510 allows for code execution via a malicious firmware upgrade packet. |
FileZen (V3.0.0 to V4.2.7 and V5.0.0 to V5.0.2) allows a remote attacker with administrator rights to execute arbitrary OS commands via unspecified vectors. |
Accellion FTA 9_12_370 and earlier is affected by OS command execution via a crafted POST request to various admin endpoints. The fixed version is FTA_9_12_380 and later. |