CWE-78
6,666 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CVEs (6,666)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Polycom 2Hdx Video End Points Uc AplNov 21, 2024 Jan 28, 2020 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 Polycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J allows remote authenticated users to execute arbitrary commands as demonstrated by a ; (semicolon) to the ping command feature. |
The download_from_url function in OpenShift Origin allows remote attackers to execute arbitrary commands via shell metacharacters in the URL of a request to download a cart. |
Command-injection vulnerability in Huawei E587 3G Mobile Hotspot 11.203.27 allows remote attackers to execute arbitrary shell commands with root privileges due to an error in the Web UI. |
1Synacor 1Zimbra Collaboration Server Nov 21, 2024 Jan 27, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Synacor Zimbra Collaboration before 8.0.9 allows plaintext command injection during STARTTLS. |
1Totolink 8A3002ru Firmware A702r FirmwareN100re Firmware+5 moreJun 17, 2026 Jan 27, 2020 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 On certain TOTOLINK Realtek SDK based routers, an authenticated attacker may execute arbitrary OS commands via the sysCmd parameter to the boafrm/formSysCmd URI, even if the GUI (syscmd.htm) is not available. This allows...Show more |
1Bitdefender 1Box 2 Firmware Jun 17, 2026 Jan 27, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A command injection vulnerability has been discovered in the bootstrap stage of Bitdefender BOX 2, versions 2.1.47.42 and 2.1.53.45. The API method `/api/download_image` unsafely handles the production firmware URL suppl...Show more |
1Bitdefender 2Box 2 Firmware CentralJun 17, 2026 Jan 27, 2020 N/A· v4 9.8 CRITICAL· v3 9.3 HIGH· v2 A OS Command Injection vulnerability in the bootstrap stage of Bitdefender BOX 2 allows the manipulation of the `get_image_url()` function in special circumstances to inject a system command. |
A vulnerability in the WebUI of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to inject and execute arbitrary commands with vmanage user privileges on an affected system. The vulnerability is du...Show more |
Intellian Aptus Web 1.24 allows remote attackers to execute arbitrary OS commands via the Q field within JSON data to the cgi-bin/libagent.cgi URI. NOTE: a valid sid cookie for a login to the intellian default account mi...Show more |
Codecov npm module before 3.6.2 allows remote attackers to execute arbitrary commands via the "gcov-args" argument. |
A Command Injection vulnerability exists in Vivotek PT7135 IP Cameras 0300a and 0400a via the system.ntp parameter to the farseer.out binary file, which cold let a malicious user execute arbitrary code. |
In IXP EasyInstall 6.2.13723, there is Remote Code Execution via the Agent Service. An unauthenticated attacker can communicate with the Agent Service over TCP port 20051, and execute code in the NT AUTHORITY\SYSTEM cont...Show more |
1Ruckuswireless 2Unleashed Zonedirector 1200 FirmwareJun 17, 2026 Jan 23, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=import-category to admin/_cmdstat.jsp via the uploadFile attribute. |
1Ruckuswireless 2Unleashed Zonedirector 1200 FirmwareJun 17, 2026 Jan 23, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=get-platform-depends to admin/_cmdstat.jsp via the uploadFile attribute. |
Toshiba ConfigFree 8.0.38 has a CF7 File Remote Command Execution Vulnerability |
1Ruckuswireless 2Unleashed Zonedirector 1200 FirmwareJun 17, 2026 Jan 22, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=spectra-analysis to admin/_cmdstat.jsp via the mac attribute. |
1Ruckuswireless 2Unleashed Zonedirector 1200 FirmwareJun 17, 2026 Jan 22, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=packet-capture to admin/_cmdstat.jsp via the mac attribute. |
1Bibtex Ruby Project 1Bibtex Ruby Jun 17, 2026 Jan 22, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 BibTeX-ruby before 5.1.0 allows shell command injection due to unsanitized user input being passed directly to the built-in Ruby Kernel.open method through BibTeX.open. |
1Multitech 1Conduit Mtcdt Lvw2 246a Firmware Jun 17, 2026 Jan 21, 2020 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 MultiTech Conduit MTCDT-LVW2-24XX 1.4.17-ocea-13592 devices allow remote authenticated administrators to execute arbitrary OS commands by navigating to the Debug Options page and entering shell metacharacters in the inte...Show more |
1Comtech 1Stampede Fx 1010 Firmware Jun 17, 2026 Jan 20, 2020 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 Comtech Stampede FX-1010 7.4.3 devices allow remote authenticated administrators to achieve remote code execution by navigating to the Poll Routes page and entering shell metacharacters in the Router IP Address field. (I...Show more |