← Back
CWE-78

6,175 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

JSON object

Loading...

CVEs (6,175)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Symantec
1Endpoint Protection Manager
May 6, 2026
Nov 12, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP3 allows remote attackers to execute arbitrary OS commands via crafted data.
1Cisco
1Web Security Appliance
May 6, 2026
Nov 6, 2015
N/A· v4
N/A· v3
9.0 HIGH· v2
The admin web interface in Cisco AsyncOS 8.x before 8.0.8-113, 8.1.x and 8.5.x before 8.5.3-051, 8.6.x and 8.7.x before 8.7.0-171-LD, and 8.8.x before 8.8.0-085 on Web Security Appliance (WSA) devices allows remote authe...Show more
The admin web interface in Cisco AsyncOS 8.x before 8.0.8-113, 8.1.x and 8.5.x before 8.5.3-051, 8.6.x and 8.7.x before 8.7.0-171-LD, and 8.8.x before 8.8.0-085 on Web Security Appliance (WSA) devices allows remote authenticated users to obtain root privileges via crafted certificate-generation arguments, aka Bug ID CSCus83445.Show less
1Typemoon
4Fate/hollow Ataraxia
Fate/stay NightFate/stay Night + Hollow Ataraxia Set+1 more
May 6, 2026
Nov 6, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
TYPE-MOON Fate/stay night, Fate/hollow ataraxia, Witch on the Holy Night, and Fate/stay night + hollow ataraxia set allow remote attackers to execute arbitrary OS commands via crafted saved data.
1Commvault
1Edge Server
May 6, 2026
Nov 4, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
The Web Console in Commvault Edge Server 10 R2 allows remote attackers to execute arbitrary OS commands via crafted serialized data in a cookie.
1Isucon
1Isucon 5 Qualifier Eventapp
May 6, 2026
Nov 4, 2015
N/A· v4
N/A· v3
6.5 MEDIUM· v2
eventapp/lib/gcloud.rb in the ISUCON5 qualifier portal (aka eventapp) web application before 2015-10-30 makes improper popen calls, which allows remote attackers to execute arbitrary commands via an HTTP request that inc...Show more
eventapp/lib/gcloud.rb in the ISUCON5 qualifier portal (aka eventapp) web application before 2015-10-30 makes improper popen calls, which allows remote attackers to execute arbitrary commands via an HTTP request that includes shell metacharacters in an argument to a "gcloud compute" command.Show less
1Infinite Automation Systems
1Mango Automation
May 6, 2026
Oct 28, 2015
N/A· v4
N/A· v3
6.5 MEDIUM· v2
Infinite Automation Mango Automation 2.5.x and 2.6.x through 2.6.0 build 430 allows remote authenticated users to execute arbitrary OS commands via unspecified vectors.
1Owncloud
2Owncloud
Smb
May 6, 2026
Oct 21, 2015
N/A· v4
N/A· v3
9.0 HIGH· v2
icewind1991 SMB before 1.0.3 allows remote authenticated users to execute arbitrary SMB commands via shell metacharacters in the user argument in the (1) listShares function in Server.php or the (2) connect or (3) read f...Show more
icewind1991 SMB before 1.0.3 allows remote authenticated users to execute arbitrary SMB commands via shell metacharacters in the user argument in the (1) listShares function in Server.php or the (2) connect or (3) read function in Share.php.Show less
1Owncloud
2Owncloud
Owncloud Server
May 6, 2026
Oct 21, 2015
N/A· v4
N/A· v3
9.0 HIGH· v2
The external SMB storage driver in ownCloud Server before 6.0.8, 7.0.x before 7.0.6, and 8.0.x before 8.0.4 allows remote authenticated users to execute arbitrary SMB commands via a ; (semicolon) character in a file.
1Refbase
1Refbase
May 6, 2026
Sep 28, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
install.php in Web Reference Database (aka refbase) through 0.9.6 allows remote attackers to execute arbitrary commands via the adminPassword parameter, a different issue than CVE-2015-7381.
1Mcafee
3Enterprise Security Manager
Enterprise Security Manager/log ManagerEnterprise Security Manager/receiver
May 6, 2026
Sep 22, 2015
N/A· v4
N/A· v3
6.5 MEDIUM· v2
McAfee Enterprise Security Manager (ESM), Enterprise Security Manager/Log Manager (ESMLM), and Enterprise Security Manager/Receiver (ESMREC) before 9.3.2MR18, 9.4.x before 9.4.2MR8, and 9.5.x before 9.5.0MR7 allow remote...Show more
McAfee Enterprise Security Manager (ESM), Enterprise Security Manager/Log Manager (ESMLM), and Enterprise Security Manager/Receiver (ESMREC) before 9.3.2MR18, 9.4.x before 9.4.2MR8, and 9.5.x before 9.5.0MR7 allow remote authenticated users to execute arbitrary OS commands via a crafted filename, which is not properly handled when downloading the file.Show less
1Symantec
1Web Gateway
May 6, 2026
Sep 20, 2015
N/A· v4
N/A· v3
8.5 HIGH· v2
The management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allows remote authenticated users to bypass intended access restrictions and execute arbitrary commands by leveragi...Show more
The management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allows remote authenticated users to bypass intended access restrictions and execute arbitrary commands by leveraging a "redirect."Show less
1Cisco
1Telepresence Video Communication Server Software
May 6, 2026
Sep 2, 2015
N/A· v4
N/A· v3
6.9 MEDIUM· v2
A local file script in Cisco TelePresence Video Communication Server (VCS) Expressway X8.5.2 allows local users to gain privileges for OS command execution via invalid parameters, aka Bug ID CSCuv10556.
1Yodobashi
1Yodobashi
May 6, 2026
Aug 8, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The Yodobashi application 1.2.1.0 and earlier for Android allows remote attackers to execute arbitrary Java methods, and consequently obtain sensitive information or execute OS commands, via a crafted HTML document.
1Webservice Dic
1Yoyaku
May 6, 2026
Jul 29, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Webservice-DIC yoyaku_v41 allows remote attackers to execute arbitrary OS commands via unspecified vectors.
1Cisco
1Unified Computing System
May 6, 2026
Jul 20, 2015
N/A· v4
N/A· v3
7.2 HIGH· v2
The Manager component in Cisco Unified Computing System (UCS) 2.2(3b) on B Blade Server devices allows local users to gain privileges for executing arbitrary CLI commands by leveraging access to the subordinate fabric in...Show more
The Manager component in Cisco Unified Computing System (UCS) 2.2(3b) on B Blade Server devices allows local users to gain privileges for executing arbitrary CLI commands by leveraging access to the subordinate fabric interconnect, aka Bug ID CSCut32778.Show less
1Cisco
1Asr 5000 Series Software
May 6, 2026
Jul 10, 2015
N/A· v4
N/A· v3
7.2 HIGH· v2
The boot implementation on Cisco ASR 5000 and 5500 devices with software 14.0 allows local users to execute arbitrary Linux commands by leveraging administrative privileges for storage of these commands in a Compact Flas...Show more
The boot implementation on Cisco ASR 5000 and 5500 devices with software 14.0 allows local users to execute arbitrary Linux commands by leveraging administrative privileges for storage of these commands in a Compact Flash (CF) file, aka Bug ID CSCuu75278.Show less
1Cisco
1Nx Os
May 6, 2026
Jul 3, 2015
N/A· v4
N/A· v3
4.6 MEDIUM· v2
The CLI parser in Cisco NX-OS 4.1(2)E1(1), 6.2(11b), 6.2(12), 7.2(0)ZZ(99.1), 7.2(0)ZZ(99.3), and 9.1(1)SV1(3.1.8) on Nexus devices allows local users to execute arbitrary OS commands via crafted characters in a filename...Show more
The CLI parser in Cisco NX-OS 4.1(2)E1(1), 6.2(11b), 6.2(12), 7.2(0)ZZ(99.1), 7.2(0)ZZ(99.3), and 9.1(1)SV1(3.1.8) on Nexus devices allows local users to execute arbitrary OS commands via crafted characters in a filename, aka Bug IDs CSCuv08491, CSCuv08443, CSCuv08480, CSCuv08448, CSCuu99291, CSCuv08434, and CSCuv08436.Show less
1Cisco
1Wireless Lan Controller Software
May 6, 2026
Jun 26, 2015
N/A· v4
N/A· v3
7.2 HIGH· v2
Cisco Wireless LAN Controller (WLC) devices with software 7.0(240.0) allow local users to execute arbitrary OS commands in a privileged context via crafted CLI commands, aka Bug ID CSCuj39474.
1Cisco
1Virtualization Experience Client 6000 Series Firmware
May 6, 2026
Jun 17, 2015
N/A· v4
N/A· v3
7.2 HIGH· v2
The diagnostics subsystem in the administrative web interface on Cisco Virtualization Experience (aka VXC) Client 6215 devices with firmware 11.2(27.4) allows local users to gain privileges for OS command execution via a...Show more
The diagnostics subsystem in the administrative web interface on Cisco Virtualization Experience (aka VXC) Client 6215 devices with firmware 11.2(27.4) allows local users to gain privileges for OS command execution via a crafted option value, aka Bug ID CSCug54412.Show less
1Cisco
1Unified Computing System
May 6, 2026
Jun 17, 2015
N/A· v4
N/A· v3
7.2 HIGH· v2
Cisco UCS Central Software 1.2(1a) allows local users to gain privileges for OS command execution via a crafted CLI parameter, aka Bug ID CSCut32795.