CWE-78
6,666 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CVEs (6,666)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Comtech 1Stampede Fx 1010 Firmware Jun 17, 2026 Jan 20, 2020 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 Comtech Stampede FX-1010 7.4.3 devices allow remote authenticated administrators to achieve remote code execution by navigating to the Fetch URL page and entering shell metacharacters in the URL field. (In some cases, au...Show more |
1Comtech 1Stampede Fx 1010 Firmware Jun 17, 2026 Jan 20, 2020 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 Comtech Stampede FX-1010 7.4.3 devices allow remote authenticated administrators to achieve remote code execution by navigating to the Diagnostics Trace Route page and entering shell metacharacters in the Target IP addre...Show more |
1Meinbergglobal 2Lantime M1000 Firmware Lantime M300 FirmwareJun 17, 2026 Jan 20, 2020 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 Meinberg Lantime M300 and M1000 devices allow attackers (with privileges to configure a device) to execute arbitrary OS commands by editing the /config/netconf.cmd script (aka Extended Network Configuration). Note: Accor...Show more |
Cacti 1.2.8 allows Remote Code Execution (by privileged users) via shell metacharacters in the Performance Boost Debug Log field of poller_automation.php. OS commands are executed when a new poller cycle begins. The atta...Show more |
1Geutebrueck 11G Cam Ebc 2110 Firmware G Cam Ebc 2111 FirmwareG Cam Efd 2240 Firmware+8 moreJun 17, 2026 Jan 17, 2020 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 Geutebruck IP Cameras G-Code(EEC-2xxx), G-Cam(EBC-21xx/EFD-22xx/ETHC-22xx/EWPC-22xx): All versions 1.12.0.25 and prior may allow a remote authenticated attacker with access to network configuration to supply system comma...Show more |
1Geutebrueck 11G Cam Ebc 2110 Firmware G Cam Ebc 2111 FirmwareG Cam Efd 2240 Firmware+8 moreJun 17, 2026 Jan 17, 2020 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 Geutebruck IP Cameras G-Code(EEC-2xxx), G-Cam(EBC-21xx/EFD-22xx/ETHC-22xx/EWPC-22xx): All versions 1.12.0.25 and prior may allow a remote authenticated user, using a specially crafted URL command, to execute commands as...Show more |
When a device using Juniper Network's Dynamic Host Configuration Protocol Daemon (JDHCPD) process on Junos OS or Junos OS Evolved which is configured in relay mode it vulnerable to an attacker sending crafted IPv6 packet...Show more |
When a device using Juniper Network's Dynamic Host Configuration Protocol Daemon (JDHCPD) process on Junos OS or Junos OS Evolved which is configured in relay mode it vulnerable to an attacker sending crafted IPv4 packet...Show more |
When a device using Juniper Network's Dynamic Host Configuration Protocol Daemon (JDHCPD) process on Junos OS or Junos OS Evolved which is configured in relay mode it vulnerable to an attacker sending crafted IPv4 packet...Show more |
Freelancy v1.0.0 allows remote command execution via the "file":"data:application/x-php;base64 substring (in conjunction with "type":"application/x-php"} to the /api/files/ URI. |
A remote code execution issue was discovered in HashBrown CMS through 1.3.3. Server/Entity/Deployer/GitDeployer.js has a Service.AppService.exec call that mishandles the URL, repository, username, and password. |
In Avast Premium Security 19.8.2393, attackers can send a specially crafted request to the local web server run by Avast Antivirus on port 27275 to support Bank Mode functionality. A flaw in the processing of a command a...Show more |
1Rasilient 1Pixelstor 5000 Firmware Jun 17, 2026 Jan 9, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 contentHostProperties.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows authenticated attackers to remotely execute code via the name parameter. |
1Rasilient 1Pixelstor 5000 Firmware Jun 17, 2026 Jan 9, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 languageOptions.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows unauthenticated attackers to remotely execute code via the lang parameter. |
netflow_get_stats in functions_netflow.php in Pandora FMS 7.0NG allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ip_src parameter in an index.php?operation/netflow/nf_liv...Show more |
1Atos 15Openscape Desk Phone Ip 35g Eco Firmware Openscape Desk Phone Ip 35g FirmwareOpenscape Desk Phone Ip 55g Firmware+12 moreNov 21, 2024 Jan 9, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Unify OpenStage / OpenScape Desk Phone IP before V3 R3.11.0 SIP has an OS command injection vulnerability in the web based management interface |
In aws-lambda versions prior to version 1.0.5, the "config.FunctioName" is used to construct the argument used within the "exec" function without any sanitization. It is possible for a user to inject arbitrary commands t...Show more |
1Devcert Sanscache Project 1Devcert Sanscache Jun 17, 2026 Jan 8, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 devcert-sanscache before 0.4.7 allows remote attackers to execute arbitrary code or cause a Command Injection via the exec function. The variable `commonName` controlled by user input is used as part of the `exec` functi...Show more |
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop Parallels Desktop version 14.1.3 (45485). An attacker must first obtain the ability to execute low-privilege...Show more |
1Git Diff Apply Project 1Git Diff Apply Jun 17, 2026 Jan 7, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In "index.js" file line 240, the run command executes the git command with a user controlled variable called remoteUrl. This affects git-diff-apply all versions prior to 0.22.2. |