CWE-78
6,714 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CVEs (6,714)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The gitlog function in src/index.ts in gitlog before 4.0.4 has a command injection vulnerability. |
An issue was discovered in Svakom Siime Eye 14.1.00000001.3.330.0.0.3.14. A command injection vulnerability resides in the HOST/IP section of the NFS settings menu in the webserver running on the device. By injecting Bas...Show more |
CMCAgent in NCR Command Center Agent 16.3 on Aloha POS/BOH servers permits the submission of a runCommand parameter (within an XML document sent to port 8089) that enables the remote, unauthenticated execution of an arbi...Show more |
The Patient Portal of OpenEMR 5.0.2.1 is affected by a Command Injection vulnerability in /interface/main/backup.php. To exploit the vulnerability, an authenticated attacker can send a POST request that executes arbitrar...Show more |
A vulnerability in a CLI command of Cisco IOS XR Software for the Cisco 8000 Series Routers and Network Convergence System 540 Series Routers running NCS540L software images could allow an authenticated, local attacker t...Show more |
1Cisco 6Rv016 Multi Wan Vpn Router Firmware Rv042 Dual Wan Vpn Router FirmwareRv042g Dual Gigabit Wan Vpn Router Firmware+3 moreJun 17, 2026 Feb 4, 2021 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to inject arbitrary commands that...Show more |
1Cisco 6Rv016 Multi Wan Vpn Router Firmware Rv042 Dual Wan Vpn Router FirmwareRv042g Dual Gigabit Wan Vpn Router Firmware+3 moreJun 17, 2026 Feb 4, 2021 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to inject arbitrary commands that...Show more |
1Cisco 6Rv016 Multi Wan Vpn Router Firmware Rv042 Dual Wan Vpn Router FirmwareRv042g Dual Gigabit Wan Vpn Router Firmware+3 moreJun 17, 2026 Feb 4, 2021 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to inject arbitrary commands that...Show more |
1Cisco 6Rv016 Multi Wan Vpn Router Firmware Rv042 Dual Wan Vpn Router FirmwareRv042g Dual Gigabit Wan Vpn Router Firmware+3 moreJun 17, 2026 Feb 4, 2021 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to inject arbitrary commands that...Show more |
1Cisco 6Rv016 Multi Wan Vpn Router Firmware Rv042 Dual Wan Vpn Router FirmwareRv042g Dual Gigabit Wan Vpn Router Firmware+3 moreJun 17, 2026 Feb 4, 2021 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to inject arbitrary commands that...Show more |
The vulnerability have been reported to affect earlier versions of QTS. If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. This issue affects: QNAP Systems Inc. Hel...Show more |
3Debian FedoraprojectMechanize Project3Debian Linux FedoraMechanizeJun 17, 2026 Feb 2, 2021 N/A· v4 8.3 HIGH· v3 7.6 HIGH· v2 Mechanize is an open-source ruby library that makes automated web interaction easy. In Mechanize from version 2.0.0 and before version 2.7.7 there is a command injection vulnerability. Affected versions of mechanize allo...Show more |
1Freediskspace Project 1Freediskproject Jun 17, 2026 Feb 2, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 This affects all versions of package freediskspace. The vulnerability arises out of improper neutralization of arguments in line 71 of freediskspace.js. |
1Belkin 1Linksys Wrt160nl Firmware Jun 17, 2026 Feb 2, 2021 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 The administration web interface on Belkin Linksys WRT160NL 1.0.04.002_US_20130619 devices allows remote authenticated attackers to execute system commands with root privileges via shell metacharacters in the ui_language...Show more |
1Dlink 2Dsr 1000n Firmware Dsr 250 FirmwareJun 17, 2026 Feb 2, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The D-Link DSR-250 (3.14) DSR-1000N (2.11B201) UPnP service contains a command injection vulnerability, which can cause remote command execution. |
D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead to remote arbitrary code execution. |
This affects the package total.js before 3.4.7. The issue occurs in the image.pipe and image.stream functions. The type parameter is used to build the command that is then executed using child_process.spawn. The issue oc...Show more |
1Ucopia 1Ucopia Wireless Appliance Jun 17, 2026 Feb 2, 2021 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 UCOPIA Wi-Fi appliances 6.0.5 allow authenticated remote attackers to escape the restricted administration shell CLI, and access a shell with admin user rights, via an unprotected less command. |
1Kill Process On Port Project 1Kill Process On Port Jun 17, 2026 Feb 1, 2021 N/A· v4 7.3 HIGH· v3 7.5 HIGH· v2 All versions of package kill-process-on-port are vulnerable to Command Injection via a.getProcessPortId. |
All versions of package launchpad are vulnerable to Command Injection via stop. |