← Back
CWE-78

6,675 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

JSON object

Loading...

CVEs (6,675)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Couchbase
1Couchbase Server
Jun 17, 2026
Nov 12, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Exposed Erlang Cookie could lead to Remote Command Execution (RCE) attack. Communication between Erlang nodes is done by exchanging a shared secret (aka "magic cookie"). There are cases where the magic cookie is included...Show more
Exposed Erlang Cookie could lead to Remote Command Execution (RCE) attack. Communication between Erlang nodes is done by exchanging a shared secret (aka "magic cookie"). There are cases where the magic cookie is included in the content of the logs. An attacker can use the cookie to attach to an Erlang node and run OS level commands on the system running the Erlang node. Affects version: 6.5.1. Fix version: 6.6.0.Show less
1Paloaltonetworks
1Pan Os
Jun 17, 2026
Nov 12, 2020
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
An OS command injection and memory corruption vulnerability in the PAN-OS management web interface that allows authenticated administrators to disrupt system processes and potentially execute arbitrary code and OS comman...Show more
An OS command injection and memory corruption vulnerability in the PAN-OS management web interface that allows authenticated administrators to disrupt system processes and potentially execute arbitrary code and OS commands with root privileges. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.16; PAN-OS 9.0 versions earlier than PAN-OS 9.0.10; PAN-OS 9.1 versions earlier than PAN-OS 9.1.4; PAN-OS 10.0 versions earlier than PAN-OS 10.0.1.Show less
1Microsoft
2Windows 10
Windows Server 2016
Jun 17, 2026
Nov 11, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Win32k Elevation of Privilege Vulnerability
1Tp Link
1Ac1750 Firmware
Jun 17, 2026
Nov 8, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
tdpServer on TP-Link Archer A7 AC1750 devices before 201029 allows remote attackers to execute arbitrary code via the slave_mac parameter. NOTE: this issue exists because of an incomplete fix for CVE-2020-10882 in which...Show more
tdpServer on TP-Link Archer A7 AC1750 devices before 201029 allows remote attackers to execute arbitrary code via the slave_mac parameter. NOTE: this issue exists because of an incomplete fix for CVE-2020-10882 in which shell quotes are mishandled.Show less
1Cisco
1Integrated Management Controller
Jun 17, 2026
Nov 6, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A vulnerability in the web UI of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to inject arbitrary code and execute arbitrary commands at the underlying operating system level...Show more
A vulnerability in the web UI of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to inject arbitrary code and execute arbitrary commands at the underlying operating system level. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted commands to the web-based management interface of the affected software. A successful exploit could allow the attacker to inject and execute arbitrary commands at the underlying operating system level.Show less
4Debian
FedoraprojectOpensuse+1 more
4Debian Linux
FedoraLeap+1 more
Jun 17, 2026
Nov 6, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection.
1Fruitywifi Project
1Fruitywifi
Jun 17, 2026
Nov 5, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A remote code execution vulnerability is identified in FruityWifi through 2.4. Due to improperly escaped shell metacharacters obtained from the POST request at the page_config_adv.php page, it is possible to perform remo...Show more
A remote code execution vulnerability is identified in FruityWifi through 2.4. Due to improperly escaped shell metacharacters obtained from the POST request at the page_config_adv.php page, it is possible to perform remote code execution by an authenticated attacker. This is similar to CVE-2018-17317.Show less
1Qnap
1Music Station
Nov 21, 2024
Nov 2, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
If exploited, this command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Music Station versions prior to 5.1.13; versions prior to 5.2.9; versio...Show more
If exploited, this command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Music Station versions prior to 5.1.13; versions prior to 5.2.9; versions prior to 5.3.11.Show less
1Openfind
2Mailaudit
Mailgates
Jun 17, 2026
Nov 1, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
MailGates and MailAudit products contain Command Injection flaw, which can be used to inject and execute system commands from the cgi parameter after attackers obtain the user’s access token.
1Eyesofnetwork
1Eyesofnetwork
Jun 17, 2026
Oct 29, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
An issue was discovered in EyesOfNetwork 5.3 through 5.3-8. An authenticated web user with sufficient privileges could abuse the AutoDiscovery module to run arbitrary OS commands via the nmap_binary parameter to lilac/au...Show more
An issue was discovered in EyesOfNetwork 5.3 through 5.3-8. An authenticated web user with sufficient privileges could abuse the AutoDiscovery module to run arbitrary OS commands via the nmap_binary parameter to lilac/autodiscovery.php.Show less
1Westerndigital
1My Cloud Firmware
Jun 17, 2026
Oct 29, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An issue was discovered on Western Digital My Cloud NAS devices before 5.04.114. They allow remote code execution with resultant escalation of privileges.
1Qnap
1Qts
Aug 13, 2026
Oct 28, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201...Show more
If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; QTS 4.3.6.1218 on build 20200214; QTS 4.3.4.1190 on build 20200107; QTS 4.3.3.1161 on build 20200109; QTS 4.2.6 on build 20200109.Show less
1Winstonprivacy
1Winston Firmware
Jun 17, 2026
Oct 28, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Winston 1.5.4 devices are vulnerable to command injection via the API.
1Oscommerce
1Oscommerce
Jun 17, 2026
Oct 28, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
osCommerce Phoenix CE before 1.0.5.4 allows OS command injection remotely. Within admin/mail.php, a from POST parameter can be passed to the application. This affects the PHP mail function, and the sendmail -f option.
1Westerndigital
1My Cloud Firmware
Jun 17, 2026
Oct 27, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Addressed remote code execution vulnerability in DsdkProxy.php due to insufficient sanitization and insufficient validation of user input in Western Digital My Cloud NAS devices prior to 5.04.114
1Westerndigital
1My Cloud Firmware
Jun 17, 2026
Oct 27, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Addressed remote code execution vulnerability in cgi_api.php that allowed escalation of privileges in Western Digital My Cloud NAS devices prior to 5.04.114.
1Westerndigital
1My Cloud Firmware
Jun 17, 2026
Oct 27, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Addressed remote code execution vulnerability in reg_device.php due to insufficient validation of user input.in Western Digital My Cloud Devices prior to 5.4.1140.
1Commscope
1Ruckus Vriot
Jun 17, 2026
Oct 26, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Ruckus through 1.5.1.0.21 is affected by remote command injection. An authenticated user can submit a query to the API (/service/v1/createUser endpoint), injecting arbitrary commands that will be executed as root user vi...Show more
Ruckus through 1.5.1.0.21 is affected by remote command injection. An authenticated user can submit a query to the API (/service/v1/createUser endpoint), injecting arbitrary commands that will be executed as root user via web.py.Show less
1Git Tag Annotation Action Project
1Git Tag Annotation Action
Jun 17, 2026
Oct 26, 2020
N/A· v4
9.6 CRITICAL· v3
6.5 MEDIUM· v2
In the git-tag-annotation-action (open source GitHub Action) before version 1.0.1, an attacker can execute arbitrary (*) shell commands if they can control the value of [the `tag` input] or manage to alter the value of [...Show more
In the git-tag-annotation-action (open source GitHub Action) before version 1.0.1, an attacker can execute arbitrary (*) shell commands if they can control the value of [the `tag` input] or manage to alter the value of [the `GITHUB_REF` environment variable]. The problem has been patched in version 1.0.1. If you don't use the `tag` input you are most likely safe. The `GITHUB_REF` environment variable is protected by the GitHub Actions environment so attacks from there should be impossible. If you must use the `tag` input and cannot upgrade to `> 1.0.0` make sure that the value is not controlled by another Action.Show less
1Lookatme Project
1Lookatme
Jun 17, 2026
Oct 26, 2020
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
In lookatme (python/pypi package) versions prior to 2.3.0, the package automatically loaded the built-in "terminal" and "file_loader" extensions. Users that use lookatme to render untrusted markdown may have malicious sh...Show more
In lookatme (python/pypi package) versions prior to 2.3.0, the package automatically loaded the built-in "terminal" and "file_loader" extensions. Users that use lookatme to render untrusted markdown may have malicious shell commands automatically run on their system. This is fixed in version 2.3.0. As a workaround, the `lookatme/contrib/terminal.py` and `lookatme/contrib/file_loader.py` files may be manually deleted. Additionally, it is always recommended to be aware of what is being rendered with lookatme.Show less