CWE-78
6,663 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CVEs (6,663)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Cisco 2Integrated Management Controller Supervisor Unified Computing SystemJun 17, 2026 Aug 21, 2019 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to inject arbitrary commands and obtain root privileges. The vulnerabili...Show more |
1Cisco 2Integrated Management Controller Supervisor Unified Computing SystemJun 17, 2026 Aug 21, 2019 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 A vulnerability in the Redfish protocol of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to inject and execute arbitrary commands with root privileges on an affected device. T...Show more |
1Cisco 2Integrated Management Controller Supervisor Unified Computing SystemJun 17, 2026 Aug 21, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A vulnerability in the command-line interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker with read-only credentials to inject arbitrary commands that could allow them to...Show more |
1Cisco 2Integrated Management Controller Supervisor Unified Computing SystemJun 17, 2026 Aug 21, 2019 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privil...Show more |
1Cisco 2Integrated Management Controller Supervisor Unified Computing SystemJun 17, 2026 Aug 21, 2019 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privil...Show more |
1Cisco 2Integrated Management Controller Supervisor Unified Computing SystemJun 17, 2026 Aug 21, 2019 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an authenticated, remote attacker to inject arbitrary commands that are executed with root privil...Show more |
1Cisco 4Cbr 8 Firmware Remote Phy 120 FirmwareRemote Phy 220 Firmware+1 moreJun 17, 2026 Aug 21, 2019 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 A vulnerability in Cisco Remote PHY Device Software could allow an authenticated, local attacker to execute commands on the underlying Linux shell of an affected device with root privileges. The vulnerability occurs beca...Show more |
1Cisco 2Integrated Management Controller Supervisor Unified Computing SystemJun 17, 2026 Aug 21, 2019 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 A vulnerability in the Intelligent Platform Management Interface (IPMI) of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to inject arbitrary commands that are executed with ro...Show more |
1Ibm 2Datapower Gateway Mq ApplianceJun 17, 2026 Aug 20, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 IBM DataPower Gateway 2018.4.1.0 through 2018.4.1.6, 7.6.0.0 through 7.6.0.15 and IBM MQ Appliance 8.0.0.0 through 8.0.0.12, 9.1.0.0 through 9.1.0.2, and 9.1.1 through 9.1.2 could allow a local attacker to execute arbitr...Show more |
In OpenEMR 5.0.1 and earlier, an authenticated attacker can execute arbitrary commands on the host system via the Scanned Forms interface when creating a new form. |
3Canonical DebianNokogiri3Debian Linux NokogiriUbuntu LinuxJun 17, 2026 Aug 16, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A command injection vulnerability in Nokogiri v1.10.3 and earlier allows commands to be executed in a subprocess via Ruby's `Kernel.open` method. Processes are vulnerable only if the undocumented method `Nokogiri::CSS::T...Show more |
EyesOfNetwork 5.1 allows Remote Command Execution via shell metacharacters in the module/tool_all/ host field. |
do_ed_script in pch.c in GNU patch through 2.7.6 does not block strings beginning with a ! character. NOTE: this is the same commit as for CVE-2019-13638, but the ! syntax is specific to ed, and is unrelated to a shell m...Show more |
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnerability. |
A command injection vulnerability in UploadHandler.php in Vesta Control Panel 0.9.8-24 allows remote attackers to escalate from regular registered users to root. |
All versions up to V1.1.10P3T18 of ZTE ZXHN F670 product are impacted by command injection vulnerability. Due to insufficient parameter validation check, an authorized user can exploit this vulnerability to take control...Show more |
An issue was discovered on NETGEAR Nighthawk M1 (MR1100) devices before 12.06.03. System commands can be executed, via the web interface, after authentication. |
The web-based configuration interface of the TP-Link M7350 V3 with firmware before 190531 is affected by a pre-authentication command injection vulnerability. |
1Mediatek 3Mt6577 Firmware Mt6625 FirmwareMt8163 FirmwareJun 17, 2026 Aug 14, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The MediaTek Embedded Multimedia Card (eMMC) subsystem for Android on MT65xx, MT66xx, and MT8163 SoC devices allows attackers to execute arbitrary commands as root via shell metacharacters in a filename under /data, beca...Show more |
1Cisco 2Enterprise Network Function Virtualization Infrastructure Enterprise Nfv Infrastructure SoftwareAug 24, 2026 Aug 8, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to perform a command injection attack and execute arbitrary commands with root pri...Show more |