CWE-78
5,947 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CVEs (5,947)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Nagios XI 5.5.6 allows local authenticated attackers to escalate privileges to root via Autodiscover_new.php. |
Nagios XI 5.5.6 allows remote authenticated attackers to execute arbitrary commands via a crafted HTTP request. |
1Fruitywifi Project 1Fruitywifi Nov 21, 2024 Nov 11, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Shell Metacharacter Injection in www/modules/save.php in FruityWifi (aka PatatasFritas/PatataWifi) through 2.4 allows remote attackers to execute arbitrary code with root privileges via a crafted mod_name parameter in a...Show more |
2Foscam Opticam4C2 Application Firmware C2 System FirmwareI5 Application Firmware+1 moreNov 21, 2024 Nov 7, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An issue was discovered on Foscam Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The ONVIF devicemgmt SetDNS method allows remote attackers to execute arbitrary OS commands via the...Show more |
2Foscam Opticam4C2 Application Firmware C2 System FirmwareI5 Application Firmware+1 moreNov 21, 2024 Nov 7, 2018 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. They allow attacker...Show more |
2Foscam Opticam4C2 Application Firmware C2 System FirmwareI5 Application Firmware+1 moreNov 21, 2024 Nov 7, 2018 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. They allow remote a...Show more |
1Yitechnology 1Yi Home Camera Firmware Nov 21, 2024 Nov 2, 2018 N/A· v4 6.8 MEDIUM· v3 4.6 MEDIUM· v2 An exploitable code execution vulnerability exists in the firmware update functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted file can cause a logic flaw and command injection, resulting in code execution....Show more |
1Netgain Systems 1Enterprise Manager Nov 21, 2024 Nov 1, 2018 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 NetGain Enterprise Manager (EM) is affected by OS Command Injection vulnerabilities in versions before 10.0.57. These vulnerabilities could allow remote authenticated attackers to inject arbitrary code, resulting in remo...Show more |
1Yitechnology 2Yi Home Yi Home Camera FirmwareNov 21, 2024 Nov 1, 2018 N/A· v4 8.0 HIGH· v3 5.4 MEDIUM· v2 An exploitable code execution vulnerability exists in the cloud OTA setup functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted SSID can cause a command injection, resulting in code execution. An attacker ca...Show more |
1Apex Publish Static Files Project 1Apex Publish Static Files Nov 21, 2024 Oct 30, 2018 N/A· v4 10.0 CRITICAL· v3 10.0 HIGH· v2 A command injection vulnerability in the apex-publish-static-files npm module version <2.0.1 which allows arbitrary shell command execution through a maliciously crafted argument. |
A command injection vulnerability in libnmapp package for versions <0.4.16 allows arbitrary commands to be executed via arguments to the range options. |
1Tenda 3Ac10 Firmware Ac7 FirmwareAc9 FirmwareNov 7, 2025 Oct 30, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9), and AC10 devices with firmware through V15.03.06.23_CN(AC10). A comma...Show more |
1Tenda 3Ac15 Firmware Ac18 FirmwareAc9 FirmwareNov 21, 2024 Oct 29, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered on Tenda AC9 V15.03.05.19(6318)_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. They allow remote code execution via shell metacharacters in the usbName field to the __fastcall f...Show more |
1Neatorobotics 1Botvac Connected Firmware Nov 21, 2024 Oct 24, 2018 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 A command injection vulnerability in the setup API in the Neato Botvac Connected 2.2.0 allows network attackers to execute arbitrary commands via shell metacharacters in the ntp field within JSON data to the /robot/initi...Show more |
1Cisco 2Webex Meetings Desktop Webex Productivity ToolsNov 21, 2024 Oct 24, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A vulnerability in the update service of Cisco Webex Meetings Desktop App for Windows could allow an authenticated, local attacker to execute arbitrary commands as a privileged user. The vulnerability is due to insuffici...Show more |
1Sv3c 1H.264 Poe Ip Camera Firmware Nov 21, 2024 Oct 19, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 SV3C L-SERIES HD CAMERA V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B devices allow OS Command Injection. |
An authenticated command injection vulnerability exists in IPFire Firewall before 2.21 Core Update 124 in backup.cgi. This allows an authenticated user with privileges for the affected page to execute arbitrary commands. |
1Dlink 4Dwr 111 Firmware Dwr 116 FirmwareDwr 512 Firmware+1 moreNov 21, 2024 Oct 17, 2018 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 An issue was discovered on D-Link DWR-116 through 1.06, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, and DWR-111 through 1.01 devices. An authenticated attacker may execute arbi...Show more |
1Linksys 2E1200 Firmware E2500 FirmwareNov 21, 2024 Oct 17, 2018 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 An exploitable operating system command injection exists in the Linksys ESeries line of routers (Linksys E1200 Firmware Version 2.0.09 and Linksys E2500 Firmware Version 3.0.04). Specially crafted entries to network conf...Show more |
1Linksys 2E1200 Firmware E2500 FirmwareNov 21, 2024 Oct 17, 2018 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 Devices in the Linksys ESeries line of routers (Linksys E1200 Firmware Version 2.0.09 and Linksys E2500 Firmware Version 3.0.04) are susceptible to OS command injection vulnerabilities due to improper filtering of data p...Show more |