CWE-78
6,666 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CVEs (6,666)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
OKER G232V1 v1.03.02.20161129 devices provide a root terminal on a UART serial interface without proper access control. This allows attackers with physical access to interrupt the boot sequence in order to execute arbitr...Show more |
An issue was discovered in rConfig 3.9.3. A remote authenticated user can directly execute system commands by sending a GET request to ajaxArchiveFiles.php because the path parameter is passed to the exec function withou...Show more |
The application login page in AKIPS Network Monitor 15.37 through 16.5 allows a remote unauthenticated attacker to execute arbitrary OS commands via shell metacharacters in the username parameter (a failed login attempt...Show more |
1Cisco 1Data Center Network Manager Jun 17, 2026 Jan 6, 2020 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker with administrative privileges on the DCNM application to inject arbit...Show more |
1Cisco 1Data Center Network Manager Jun 17, 2026 Jan 6, 2020 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 Multiple vulnerabilities in the REST and SOAP API endpoints of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker with administrative privileges on the DCNM application to inject arbit...Show more |
Access analysis CGI An-Analyzer released in 2019 June 24 and earlier allows remote authenticated attackers to execute arbitrary OS commands via the Management Page. |
1Bulbsecurity 1Smartphone Pentest Framework Nov 21, 2024 Jan 3, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Bulb Security Smartphone Pentest Framework (SPF) 0.1.2 through 0.1.4 allows remote attackers to execute arbitrary commands via shell metacharacters in the hostingPath parameter to (1) SEAttack.pl or (2) CSAttack.pl in fr...Show more |
1Bulbsecurity 1Smartphone Pentest Framework Nov 21, 2024 Jan 3, 2020 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 Bulb Security Smartphone Pentest Framework (SPF) before 0.1.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the ipAddressTB parameter to (1) remoteAttack.pl or (2) guessPassword.pl in...Show more |
1Comtech 1Stampede Fx 1010 Firmware Jun 17, 2026 Jan 2, 2020 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 Comtech Stampede FX-1010 7.4.3 devices allow remote authenticated administrators to execute arbitrary OS commands by navigating to the Diagnostics Ping page and entering shell metacharacters in the Target IP address fiel...Show more |
In Nagios XI 5.6.9, an authenticated user is able to execute arbitrary OS commands via shell metacharacters in the id parameter to schedulereport.php, in the context of the web-server user account. |
1Amazon 1Blink Xt2 Sync Module Firmware Jun 17, 2026 Dec 31, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when the device retrieves updates scripts from the internet. |
The com.unity3d.kharma protocol handler in Unity Editor 2018.3 allows remote attackers to execute arbitrary code. |
1Prasathmani 1Tiny File Manager Jun 17, 2026 Dec 30, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 In Tiny File Manager before 2.3.9, there is a remote code execution via Upload from URL and Edit/Rename files. Only authenticated users are impacted. |
1Dlink 14Dir 818lx Firmware Dir 822 FirmwareDir 823 Firmware+11 moreJun 17, 2026 Dec 30, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system commands as root, by sending a specially crafted HTTP SUBSCRIBE reque...Show more |
1Php Shellcommand Project 1Php Shellcommand Jun 17, 2026 Dec 30, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 php-shellcommand versions before 1.6.1 have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution. |
DBA-1510P firmware 1.70b009 and earlier allows an attacker to execute arbitrary OS commands via Web User Interface. |
DBA-1510P firmware 1.70b009 and earlier allows authenticated attackers to execute arbitrary OS commands via Command Line Interface (CLI). |
3Canonical DebianSa Exim Project3Debian Linux Sa EximUbuntu LinuxJun 17, 2026 Dec 22, 2019 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 sa-exim 4.2.1 allows attackers to execute arbitrary code if they can write a .cf file or a rule. This occurs because Greylisting.pm relies on eval (rather than direct parsing and/or use of the taint feature). This issue...Show more |
A Code Injection exists in treekill on Windows which allows a remote code execution when an attacker is able to control the input into the command. |
This issue was addressed with improved checks. This issue is fixed in macOS Mojave 10.14.4. A local user may be able to execute arbitrary shell commands. |