CWE-78
6,663 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CVEs (6,663)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Cisco 2Enterprise Network Function Virtualization Infrastructure Enterprise Nfv Infrastructure SoftwareAug 24, 2026 Aug 8, 2019 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to read arbitrary files on the underlying operating system (OS) of an affected device. For mor...Show more |
1Cisco 2Enterprise Network Function Virtualization Infrastructure Enterprise Nfv Infrastructure SoftwareAug 24, 2026 Aug 8, 2019 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to read arbitrary files on the underlying operating system (OS) of an affected device. For mor...Show more |
6Canonical DebianFedoraproject+3 more8Backports Sle Debian LinuxEnterprise Linux Desktop+5 moreJun 17, 2026 Aug 7, 2019 N/A· v4 7.8 HIGH· v3 5.1 MEDIUM· v2 In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to code execution with minimal user interaction. This relates to libKF5ConfigCore.so, and the mishandling of .desktop and .dir...Show more |
1Microdigital 3Mdc N2190v Firmware Mdc N4090 FirmwareMdc N4090w FirmwareJun 17, 2026 Aug 6, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 An issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. An attacker can exploit OS Command Injection in the filename parameter for remote code execution as root. This occurs in the Main...Show more |
On the Alcatel-Lucent Enterprise (ALE) 8008 Cloud Edition Deskphone VoIP phone with firmware 1.50.13, a command injection (missing input validation) issue in the password change field for the Change Password interface al...Show more |
1Polycom 1Obihai Obi1022 Firmware Jun 17, 2026 Aug 1, 2019 N/A· v4 8.0 HIGH· v3 7.7 HIGH· v2 On the Polycom Obihai Obi1022 VoIP phone with firmware 5.1.11, a command injection (missing input validation) issue in the NTP server IP address field for the "Time Service Settings web" interface allows an authenticated...Show more |
1Dlink 26600 Ap Firmware Dwl 3600ap FirmwareJun 17, 2026 Aug 1, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An issue was discovered on D-Link 6600-AP and DWL-3600AP Ax 4.2.0.14 21/03/2019 devices. There is an ability to escape to a shell in the restricted command line interface, as demonstrated by the `/bin/sh -c wget` sequenc...Show more |
1Tridactyl Project 1Tridactyl Jun 17, 2026 Jul 29, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Tridactyl before 1.16.0 allows fake key events. |
GNU patch through 2.7.6 is vulnerable to OS shell command injection that can be exploited by opening a crafted patch file that contains an ed style diff payload with shell metacharacters. The ed editor does not need to b...Show more |
1Mcafee 1Data Loss Prevention Endpoint Jun 17, 2026 Jul 24, 2019 N/A· v4 6.5 MEDIUM· v3 4.4 MEDIUM· v2 Improper Neutralization of Special Elements used in a Command ('Command Injection') in ePO extension in McAfee Data Loss Prevention (DLP) 11.x prior to 11.3.0 allows Authenticated Adminstrator to execute arbitrary code w...Show more |
PHKP including commit 88fd9cfdf14ea4b6ac3e3967feea7bcaabb6f03b is affected by: Improper Neutralization of Special Elements used in a Command ('Command Injection'). The impact is: It is possible to manipulate gpg-keys or...Show more |
Voice Builder Prior to commit c145d4604df67e6fc625992412eef0bf9a85e26b and f6660e6d8f0d1d931359d591dbdec580fef36d36 is affected by: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command I...Show more |
A command injection (missing input validation) issue in the remote phonebook configuration URI in the web interface of the Atcom A10W VoIP phone with firmware 2.6.1a2421 allows an authenticated remote attacker in the sam...Show more |
A command injection (missing input validation) issue in the IP address field for the logging server in the configuration web interface on the Akuvox R50P VoIP phone with firmware 50.0.6.156 allows an authenticated remote...Show more |
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web application mishandles a few HTTP parameters. An unauthenticated attacker can exploit this issue by in...Show more |
1Linuxfoundation 1Open Network Operating System Jun 17, 2026 Jul 19, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The Linux Foundation ONOS SDN Controller 1.15 and earlier versions is affected by: Improper Input Validation. The impact is: A remote attacker can execute arbitrary commands on the controller. The component is: apps/yang...Show more |
In qBittorrent before 4.1.7, the function Application::runExternalProgram() located in app/application.cpp allows command injection via shell metacharacters in the torrent name parameter or current tracker parameter, as...Show more |
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 6 of 6). |
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of 6). |
1Citrix 2Netscaler Sd Wan Sd WanJun 17, 2026 Jul 16, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 4 of 6). |