← Back
CWE-78

6,715 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

JSON object

Loading...

CVEs (6,715)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Scytl
1Secure Vote
Jun 17, 2026
Feb 27, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Scytl sVote 2.1. An attacker can inject code that gets executed by creating an election-event and injecting a payload over an event alias, because the application calls Runtime.getRuntime().exe...Show more
An issue was discovered in Scytl sVote 2.1. An attacker can inject code that gets executed by creating an election-event and injecting a payload over an event alias, because the application calls Runtime.getRuntime().exec() without validation.Show less
1Prestashop
1Prestashop
Jun 17, 2026
Feb 26, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.2 there is a CSV Injection vulnerability possible by using shop search keywords via the admin panel. The problem is fixed i...Show more
PrestaShop is a fully scalable open source e-commerce solution. In PrestaShop before version 1.7.2 there is a CSV Injection vulnerability possible by using shop search keywords via the admin panel. The problem is fixed in 1.7.7.2Show less
1Contec
1Sv Cpt Mc310 Firmware
Jun 17, 2026
Feb 24, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to execute arbitrary OS commands with the web server privilege via unspecified vectors.
1Arubanetworks
1Clearpass Policy Manager
Jun 17, 2026
Feb 23, 2021
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the ClearPass web-based management interface a...Show more
A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the ClearPass web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise.Show less
1Arubanetworks
1Clearpass Policy Manager
Jun 17, 2026
Feb 23, 2021
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the ClearPass web-based management interface a...Show more
A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the ClearPass web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise.Show less
1Arubanetworks
1Clearpass Policy Manager
Jun 17, 2026
Feb 23, 2021
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the ClearPass web-based management interface a...Show more
A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the ClearPass web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise.Show less
1Arubanetworks
1Clearpass Policy Manager
Jun 17, 2026
Feb 23, 2021
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the ClearPass web-based management interface a...Show more
A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the ClearPass web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise.Show less
1Arubanetworks
1Clearpass Policy Manager
Jun 17, 2026
Feb 23, 2021
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
A remote authenticated command Injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the ClearPass CLI could allow remote authentic...Show more
A remote authenticated command Injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the ClearPass CLI could allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise.Show less
-
-
Nov 7, 2023
Feb 23, 2021
N/A· v4
N/A· v3
N/A· v2
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none
-
-
Nov 7, 2023
Feb 23, 2021
N/A· v4
N/A· v3
N/A· v2
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none
1Geojson2kml Project
1Geojson2kml
Jun 17, 2026
Feb 23, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
All versions of package geojson2kml are vulnerable to Command Injection via the index.js file. PoC: var a =require("geojson2kml"); a("./","& touch JHU",function(){})
1Nozominetworks
2Central Management Control
Guardian
Jun 17, 2026
Feb 22, 2021
8.6 HIGH· v4
7.2 HIGH· v3
9.0 HIGH· v2
OS Command Injection vulnerability when changing date settings or hostname using web GUI of Nozomi Networks Guardian and CMC allows authenticated administrators to perform remote code execution. This issue affects: Nozom...Show more
OS Command Injection vulnerability when changing date settings or hostname using web GUI of Nozomi Networks Guardian and CMC allows authenticated administrators to perform remote code execution. This issue affects: Nozomi Networks Guardian 20.0.7.3 version 20.0.7.3 and prior versions. Nozomi Networks CMC 20.0.7.3 version 20.0.7.3 and prior versions.Show less
1Netshieldcorp
1Nano 25 Firmware
Jun 17, 2026
Feb 22, 2021
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
On Netshield NANO 25 10.2.18 devices, /usr/local/webmin/System/manual_ping.cgi allows OS command injection (after authentication by the attacker) because the system C library function is used unsafely.
1Amaze File Manager Project
1Amaze File Manager
Jun 17, 2026
Feb 19, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Amaze File Manager before 3.5.1 allows attackers to obtain root privileges via shell metacharacters in a symbolic link.
1Alleghenycreative
1Openrepeater
Jun 17, 2026
Feb 19, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
OpenRepeater (ORP) before 2.2 allows unauthenticated command injection via shell metacharacters in the functions/ajax_system.php post_service parameter.
1Netis Systems
2Wf2411 Firmware
Wf2780 Firmware
Jun 17, 2026
Feb 18, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Netis WF2780 2.3.40404 and WF2411 1.1.29629 devices allow Shell Metacharacter Injection into the ping command, leading to remote code execution.
1Async Git Project
1Async Git
Jun 17, 2026
Feb 18, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The package async-git before 1.13.2 are vulnerable to Command Injection via shell meta-characters (back-ticks). For example: git.reset('atouch HACKEDb')
1Dji
1Mavic 2 Firmware
Jun 17, 2026
Feb 18, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A command injection issue in dji_sys in DJI Mavic 2 Remote Controller before firmware version 01.00.0510 allows for code execution via a malicious firmware upgrade packet.
1Soliton
1Filezen
Jun 17, 2026
Feb 17, 2021
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
FileZen (V3.0.0 to V4.2.7 and V5.0.0 to V5.0.2) allows a remote attacker with administrator rights to execute arbitrary OS commands via unspecified vectors.
1Accellion
1Fta
Jun 17, 2026
Feb 16, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Accellion FTA 9_12_370 and earlier is affected by OS command execution via a crafted POST request to various admin endpoints. The fixed version is FTA_9_12_380 and later.