← Back
CWE-78

6,672 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

JSON object

Loading...

CVEs (6,672)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Adb Driver Project
1Adb Driver
Jun 17, 2026
Apr 6, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
adb-driver through 0.1.8 is vulnerable to Command Injection.It allows execution of arbitrary commands via the command function.
1Compass Compile Project
1Compass Compile
Jun 17, 2026
Apr 6, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
compass-compile through 0.0.1 is vulnerable to Command Injection.It allows execution of arbitrary commands via tha options argument.
1Heroku Addonpool Project
1Heroku Addonpool
Jun 17, 2026
Apr 6, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
heroku-addonpool through 0.1.15 is vulnerable to Command Injection.
1Apiconnect Cli Plugins Project
1Apiconnect Cli Plugins
Jun 17, 2026
Apr 6, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
apiconnect-cli-plugins through 6.0.1 is vulnerable to Command Injection.It allows execution of arbitrary commands via the pluginUri argument.
1Node Mpv Project
1Node Mpv
Jun 17, 2026
Apr 6, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
node-mpv through 1.4.3 is vulnerable to Command Injection. It allows execution of arbitrary commands via the options argument.
1Diskusage Ng Project
1Diskusage Ng
Jun 17, 2026
Apr 6, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
diskusage-ng through 0.2.4 is vulnerable to Command Injection.It allows execution of arbitrary commands via the path argument.
1Git Add Remote Project
1Git Add Remote
Jun 17, 2026
Apr 2, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
git-add-remote through 1.0.0 is vulnerable to Command Injection. It allows execution of arbitrary commands via the name argument.
1Install Package Project
1Install Package
Jun 17, 2026
Apr 2, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
install-package through 0.4.0 is vulnerable to Command Injection. It allows execution of arbitrary commands via the options argument.
2Install Package Project
Umount Project
2Install Package
Umount
Jun 17, 2026
Apr 2, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
umount through 1.1.6 is vulnerable to Command Injection. The argument device can be controlled by users without any sanitization.
1Node Key Sender Project
1Node Key Sender
Jun 17, 2026
Apr 2, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
node-key-sender through 1.0.11 is vulnerable to Command Injection. It allows execution of arbitrary commands via the 'arrParams' argument in the 'execute()' function.
1Karma Mojo Project
1Karma Mojo
Jun 17, 2026
Apr 2, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
karma-mojo through 1.0.1 is vulnerable to Command Injection. It allows execution of arbitrary commands via the config argument.
1Op Browser Project
1Op Browser
Jun 17, 2026
Apr 2, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
op-browser through 1.0.6 is vulnerable to Command Injection. It allows execution of arbitrary commands via the url function.
1Effect Project
1Effect
Jun 17, 2026
Apr 2, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
effect through 1.0.4 is vulnerable to Command Injection. It allows execution of arbitrary command via the options argument.
1Jscover Project
1Jscover
Jun 17, 2026
Apr 2, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
jscover through 1.0.0 is vulnerable to Command Injection. It allows execution of arbitrary command via the source argument.
1Ibm
1Strongloop Nginx Controller
Jun 17, 2026
Apr 2, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
strong-nginx-controller through 1.0.2 is vulnerable to Command Injection. It allows execution of arbitrary command as part of the '_nginxCmd()' function.
1Netease
1Pomelo Monitor
Jun 17, 2026
Apr 2, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
pomelo-monitor through 0.3.7 is vulnerable to Command Injection.It allows injection of arbitrary commands as part of 'pomelo-monitor' params.
1Get Git Data Project
1Get Git Data
Jun 17, 2026
Apr 2, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
get-git-data through 1.3.1 is vulnerable to Command Injection. It is possible to inject arbitrary commands as part of the arguments provided to get-git-data.
1Zevenet
1Zen Load Balancer
Jun 17, 2026
Apr 2, 2020
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
Manage::Certificates in Zen Load Balancer 3.10.1 allows remote authenticated admins to execute arbitrary OS commands via shell metacharacters in the index.cgi cert_issuer, cert_division, cert_organization, cert_locality,...Show more
Manage::Certificates in Zen Load Balancer 3.10.1 allows remote authenticated admins to execute arbitrary OS commands via shell metacharacters in the index.cgi cert_issuer, cert_division, cert_organization, cert_locality, cert_state, cert_country, or cert_email parameter.Show less
1Ibm
2Spectrum Protect Plus
Spectrum Scale
Jun 17, 2026
Mar 31, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
IBM Spectrum Scale and IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially crafted request, an attacker could ex...Show more
IBM Spectrum Scale and IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 175419.Show less
1Ibm
2Spectrum Protect Plus
Spectrum Scale
Jun 17, 2026
Mar 31, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
IBM Spectrum Scale and IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially crafted request, an attacker could ex...Show more
IBM Spectrum Scale and IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IBM X-Force ID: 175418.Show less