← Back
CWE-78

6,678 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

JSON object

Loading...

CVEs (6,678)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Xinuos
1Openserver
Jun 17, 2026
Dec 18, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Xinuos (formerly SCO) Openserver v5 and v6 allows attackers to execute arbitrary commands via shell metacharacters in outputform or toclevels parameter to cgi-bin/printbook.
1Wago
5Pfc 100 Firmware
Pfc 200 FirmwareTouch Panel 600 Advanced Firmware+2 more
Jun 17, 2026
Dec 17, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The reported vulnerability allows an attacker who has network access to the device to execute code with specially crafted packets in WAGO Series PFC 100 (750-81xx/xxx-xxx), Series PFC 200 (750-82xx/xxx-xxx), Series Wago...Show more
The reported vulnerability allows an attacker who has network access to the device to execute code with specially crafted packets in WAGO Series PFC 100 (750-81xx/xxx-xxx), Series PFC 200 (750-82xx/xxx-xxx), Series Wago Touch Panel 600 Standard Line (762-4xxx), Series Wago Touch Panel 600 Advanced Line (762-5xxx), Series Wago Touch Panel 600 Marine Line (762-6xxx) with firmware versions <=FW10.Show less
1Trendmicro
1Interscan Web Security Virtual Appliance
Jun 17, 2026
Dec 17, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A command injection vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2, with the improved password hashing method enabled, could allow an unauthenticated attacker to execute certain commands by...Show more
A command injection vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2, with the improved password hashing method enabled, could allow an unauthenticated attacker to execute certain commands by providing a manipulated password.Show less
1Logrhythm
1Platform Manager
Jun 17, 2026
Dec 17, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
LogRhythm Platform Manager 7.4.9 allows Command Injection. To exploit this, an attacker can inject arbitrary program names and arguments into a WebSocket. These are forwarded to any remote server with a LogRhythm Smart R...Show more
LogRhythm Platform Manager 7.4.9 allows Command Injection. To exploit this, an attacker can inject arbitrary program names and arguments into a WebSocket. These are forwarded to any remote server with a LogRhythm Smart Response agent installed. By default, the commands are run with LocalSystem privileges.Show less
1Systeminformation
1Systeminformation
Jun 17, 2026
Dec 16, 2020
N/A· v4
8.8 HIGH· v3
7.5 HIGH· v2
In systeminformation (npm package) before version 4.31.1 there is a command injection vulnerability. The problem was fixed in version 4.31.1 with a shell string sanitation fix.
1Connection Tester Project
1Connection Tester
Jun 17, 2026
Dec 16, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
This affects the package connection-tester before 0.2.1. The injection point is located in line 15 in index.js. The following PoC demonstrates the vulnerability:
1Adremsoft
1Netcrunch
Jun 17, 2026
Dec 16, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
AdRem NetCrunch 10.6.0.4587 allows Remote Code Execution. In the NetCrunch web client, a read-only administrator can execute arbitrary code on the server running the NetCrunch server software.
1Solarwinds
1N Central
Jun 17, 2026
Dec 16, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
An issue was discovered in SolarWinds N-Central 12.3.0.670. The sudo configuration has incorrect access control because the nable web user account is effectively able to run arbitrary OS commands as root (i.e., the use o...Show more
An issue was discovered in SolarWinds N-Central 12.3.0.670. The sudo configuration has incorrect access control because the nable web user account is effectively able to run arbitrary OS commands as root (i.e., the use of root privileges is not limited to specific programs listed in the sudoers file).Show less
1Opentsdb
1Opentsdb
Jun 17, 2026
Dec 16, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A remote code execution vulnerability occurs in OpenTSDB through 2.4.0 via command injection in the yrange parameter. The yrange value is written to a gnuplot file in the /tmp directory. This file is then executed via th...Show more
A remote code execution vulnerability occurs in OpenTSDB through 2.4.0 via command injection in the yrange parameter. The yrange value is written to a gnuplot file in the /tmp directory. This file is then executed via the mygnuplot.sh shell script. (tsd/GraphHandler.java attempted to prevent command injections by blocking backticks but this is insufficient.)Show less
4Apache
DebianFedoraproject+1 more
4Debian Linux
FedoraStruts+1 more
Jun 17, 2026
Dec 16, 2020
N/A· v4
6.8 MEDIUM· v3
6.4 MEDIUM· v2
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling. The vulnerability may allow a remo...Show more
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling. The vulnerability may allow a remote attacker to delete arbitrary know files on the host as log as the executing process has sufficient rights only by manipulating the processed input stream. If you rely on XStream's default blacklist of the Security Framework, you will have to use at least version 1.4.15. The reported vulnerability does not exist running Java 15 or higher. No user is affected, who followed the recommendation to setup XStream's Security Framework with a whitelist! Anyone relying on XStream's default blacklist can immediately switch to a whilelist for the allowed types to avoid the vulnerability. Users of XStream 1.4.14 or below who still want to use XStream default blacklist can use a workaround described in more detailed in the referenced advisories.Show less
1Dlink
10Dsr 1000 Firmware
Dsr 1000ac FirmwareDsr 1000n Firmware+7 more
Jun 17, 2026
Dec 15, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
An issue was discovered on D-Link DSR-250 3.17 devices. Certain functionality in the Unified Services Router web interface could allow an authenticated attacker to execute arbitrary commands, due to a lack of validation...Show more
An issue was discovered on D-Link DSR-250 3.17 devices. Certain functionality in the Unified Services Router web interface could allow an authenticated attacker to execute arbitrary commands, due to a lack of validation of inputs provided in multipart HTTP POST requests.Show less
1Dlink
10Dsr 1000 Firmware
Dsr 1000ac FirmwareDsr 1000n Firmware+7 more
Jun 17, 2026
Dec 15, 2020
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
A lack of input validation and access controls in Lua CGIs on D-Link DSR VPN routers may result in arbitrary input being passed to system command APIs, resulting in arbitrary command execution with root privileges. This...Show more
A lack of input validation and access controls in Lua CGIs on D-Link DSR VPN routers may result in arbitrary input being passed to system command APIs, resulting in arbitrary command execution with root privileges. This affects DSR-150, DSR-250, DSR-500, and DSR-1000AC with firmware 3.14 and 3.17.Show less
1Liftoffsoftware
1Gateone
Jun 17, 2026
Dec 14, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
GateOne allows remote attackers to execute arbitrary commands via shell metacharacters in the port field when attempting an SSH connection.
1Necplatforms
1Aterm Sa3500g Firmware
Jun 17, 2026
Dec 14, 2020
N/A· v4
6.8 MEDIUM· v3
5.2 MEDIUM· v2
Aterm SA3500G firmware versions prior to Ver. 3.5.9 allows an attacker with an administrative privilege to send a specially crafted request to a specific URL, which may result in an arbitrary command execution.
1Necplatforms
1Aterm Sa3500g Firmware
Jun 17, 2026
Dec 14, 2020
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
Aterm SA3500G firmware versions prior to Ver. 3.5.9 allows an attacker on the adjacent network to send a specially crafted request to a specific URL, which may result in an arbitrary command execution.
1Corenlp Js Interface Project
1Corenlp Js Interface
Jun 17, 2026
Dec 11, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
All versions of package corenlp-js-interface are vulnerable to Command Injection via the main function.
1Corenlp Js Prefab Project
1Corenlp Js Prefab
Jun 17, 2026
Dec 11, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
This affects all versions of package corenlp-js-prefab. The injection point is located in line 10 in 'index.js.' It depends on a vulnerable package 'corenlp-js-interface.' Vulnerability can be exploited with the followin...Show more
This affects all versions of package corenlp-js-prefab. The injection point is located in line 10 in 'index.js.' It depends on a vulnerable package 'corenlp-js-interface.' Vulnerability can be exploited with the following PoC:Show less
1Askey
1Ap5100w Firmware
Jun 17, 2026
Dec 11, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Network Analysis functionality in Askey AP5100W_Dual_SIG_1.01.097 and all prior versions allows remote attackers to execute arbitrary commands via a shell metacharacter in the ping, traceroute, or route options.
1Arubanetworks
1Edgeconnect Enterprise
Jun 17, 2026
Dec 11, 2020
N/A· v4
6.8 MEDIUM· v3
8.5 HIGH· v2
The configuration backup/restore function in Silver Peak Unity ECOSTM (ECOS) appliance software was found to directly incorporate the user-controlled config filename in a subsequent shell command, allowing an attacker to...Show more
The configuration backup/restore function in Silver Peak Unity ECOSTM (ECOS) appliance software was found to directly incorporate the user-controlled config filename in a subsequent shell command, allowing an attacker to manipulate the resulting command by injecting valid OS command input. This vulnerability can be exploited by an attacker with authenticated access to the Orchestrator UI or EdgeConnect UI. This affects all ECOS versions prior to: 8.1.9.15, 8.3.0.8, 8.3.1.2, 8.3.2.0, 9.0.2.0, and 9.1.0.0.Show less
1Arubanetworks
1Edgeconnect Enterprise
Jun 17, 2026
Dec 11, 2020
N/A· v4
6.8 MEDIUM· v3
8.5 HIGH· v2
A command injection flaw identified in the nslookup API in Silver Peak Unity ECOSTM (ECOS) appliance software could allow an attacker to execute arbitrary commands with the privileges of the web server running on the Edg...Show more
A command injection flaw identified in the nslookup API in Silver Peak Unity ECOSTM (ECOS) appliance software could allow an attacker to execute arbitrary commands with the privileges of the web server running on the EdgeConnect appliance. An attacker could exploit this vulnerability to establish an interactive channel, effectively taking control of the target system. This vulnerability can be exploited by an attacker with authenticated access to the Orchestrator UI or EdgeConnect UI. This affects all ECOS versions prior to : 8.1.9.15, 8.3.0.8, 8.3.1.2, 8.3.2.0, 9.0.2.0, and 9.1.0.0.Show less