CWE-78
6,664 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CVEs (6,664)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Tecno Mobile 1Camon Iair 2+ Firmware Jun 17, 2026 Nov 14, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The Tecno Camon iAir 2 Plus Android device with a build fingerprint of TECNO/H622/TECNO-ID3k:8.1.0/O11019/E-180914V83:user/release-keys contains a pre-installed platform app with a package name of com.lovelyfont.defconta...Show more |
1Exhibitor Project 1Exhibitor Jun 17, 2026 Nov 13, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An exploitable command injection vulnerability exists in the Config editor of the Exhibitor Web UI versions 1.0.9 to 1.7.1. Arbitrary shell commands surrounded by backticks or $() can be inserted into the editor and will...Show more |
FUDForum 3.0.9 is vulnerable to Stored XSS via the nlogin parameter. This may result in remote code execution. An attacker can use a user account to fully compromise the system using a POST request. When the admin visits...Show more |
FUDForum 3.0.9 is vulnerable to Stored XSS via the User-Agent HTTP header. This may result in remote code execution. An attacker can use a user account to fully compromise the system via a GET request. When the admin vis...Show more |
A remote code execution vulnerability exists in Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 or 2.3.2-p1. An authenticated user with system data manipulation privileges can execute aribitrary code through arbi...Show more |
1Sonatype 1Nexus Repository Manager Jun 17, 2026 Nov 1, 2019 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 There is an OS Command Injection in Nexus Repository Manager <= 2.14.14 (bypass CVE-2019-5475) that could allow an attacker a Remote Code Execution (RCE). All instances using CommandLineExecutor.java with user-supplied d...Show more |
An issue was discovered in certain Oi third-party firmware that may be installed on Technicolor TD5130v2 devices. A Command Injection in the Ping module in the Web Interface in OI_Fw_V20 allows remote attackers to execut...Show more |
1Fortiguard 1Fortiextender Firmware Jun 17, 2026 Oct 31, 2019 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 An OS command injection vulnerability in FortiExtender 4.1.0 to 4.1.1, 4.0.0 and below under CLI admin console may allow unauthorized administrators to run arbitrary system level commands via specially crafted "execute d...Show more |
2Call Cc Debian2Chicken Debian LinuxNov 21, 2024 Oct 31, 2019 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 OS command injection vulnerability in the "qs" procedure from the "utils" module in Chicken before 4.9.0. |
4Debian FedoraprojectOpensuse+1 more4Debian Linux FedoraLeap+1 moreJun 17, 2026 Oct 31, 2019 N/A· v4 6.8 MEDIUM· v3 6.9 MEDIUM· v2 An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has access to a physical device. This occurs because passed through PCI devices...Show more |
2Inea Mitsubishielectric2Me Rtu Firmware Smartrtu FirmwareJun 17, 2026 Oct 28, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote OS Command Injection vulnerability allows an attacker to execute arbit...Show more |
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to search.crud.php because the catCommand parameter is passed to the exec function without filtering, wh...Show more |
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to ajaxServerSettingsChk.php because the rootUname parameter is passed to the exec function without filt...Show more |
1Youphptube 1Youphptube Encoder Jun 17, 2026 Oct 25, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. Exploitable unauthenticated command injections exist in YouPHPTube Encoder 2.3 a plugin for...Show more |
1Youphptube 1Youphptube Encoder Jun 17, 2026 Oct 25, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. Exploitable unauthenticated command injections exist in YouPHPTube Encoder 2.3 a plugin for...Show more |
1Youphptube 1Youphptube Encoder Jun 17, 2026 Oct 25, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A command injection have been found in YouPHPTube Encoder. A successful attack could allow an attacker to compromise the server. Exploitable unauthenticated command injections exist in YouPHPTube Encoder 2.3 a plugin for...Show more |
TP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow triggerPort OS Command Injection (issue 5 of 5). |
TP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow serviceName OS Command Injection (issue 4 of 5). |
TP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow portMappingProtocol OS Command Injection (issue 3 of 5). |
TP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow internalPort OS Command Injection (issue 2 of 5). |