CWE-78
6,626 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CVEs (6,626)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Fedoraproject Redhat7Enterprise Linux Enterprise Linux DesktopEnterprise Linux Server+4 moreNov 21, 2024 May 17, 2018 N/A· v4 7.5 HIGH· v3 7.9 HIGH· v2 DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in the NetworkManager integration script included in the DHCP client. A malicious DHCP server, or an at...Show more |
1Cisco 1Network Functions Virtualization Infrastructure Nov 21, 2024 May 17, 2018 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, high-privileged, local attacker to perform a command injection attack. The vulnerability is due to insuffic...Show more |
1Cisco 1Enterprise Nfv Infrastructure Software Nov 21, 2024 May 17, 2018 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A vulnerability in the Secure Copy Protocol (SCP) server of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, remote attacker to access the shell of the underlying Linux operating system...Show more |
An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP POST can cause a privilege escalation resulting in root shell. An attack...Show more |
An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP POST can cause a privilege escalation resulting in root shell. An attack...Show more |
An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP POST can cause a privilege escalation resulting in root shell. An attack...Show more |
An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP POST can cause a privilege escalation resulting in root shell. An attack...Show more |
An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP POST can cause a privilege escalation resulting in root shell. An attack...Show more |
An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 17030317. A specially crafted HTTP POST can cause a privilege escalation, resulting in a root shell. An att...Show more |
1Silextechnology 2Geh Sd 320an Firmware Sd 320an FirmwareJun 17, 2026 May 9, 2018 N/A· v4 7.4 HIGH· v3 6.5 MEDIUM· v2 Silex SD-320AN version 2.01 and prior and GE MobileLink(GEH-SD-320AN) version GEH-1.1 and prior have a system call parameter that is not properly sanitized, which may allow remote code execution. |
1Mysql Mmm 1Mysql Multi Master Replication Manager Nov 21, 2024 May 9, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 In the MMM::Agent::Helpers::Network::send_arp function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for Solaris), a specially crafted MMM protocol message can cause a shell command injection resultin...Show more |
1Mysql Mmm 1Mysql Multi Master Replication Manager Nov 21, 2024 May 9, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 In the MMM::Agent::Helpers::Network::clear_ip function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for FreeBSD), a specially crafted MMM protocol message can cause a shell command injection resultin...Show more |
1Mysql Mmm 1Mysql Multi Master Replication Manager Nov 21, 2024 May 9, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 In the MMM::Agent::Helpers::Network::clear_ip function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for Solaris), a specially crafted MMM protocol message can cause a shell command injection resultin...Show more |
1Mysql Mmm 1Mysql Multi Master Replication Manager Nov 21, 2024 May 9, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 In the MMM::Agent::Helpers::Network::clear_ip function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for Linux), a specially crafted MMM protocol message can cause a shell command injection resulting...Show more |
1Mysql Mmm 1Mysql Multi Master Replication Manager Nov 21, 2024 May 9, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 In the MMM::Agent::Helpers::Network::add_ip function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for FreeBSD), a specially crafted MMM protocol message can cause a shell command injection resulting...Show more |
1Mysql Mmm 1Mysql Multi Master Replication Manager Nov 21, 2024 May 9, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 In the MMM::Agent::Helpers::Network::add_ip function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for Solaris), a specially crafted MMM protocol message can cause a shell command injection resulting...Show more |
1Mysql Mmm 1Mysql Multi Master Replication Manager Nov 21, 2024 May 9, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 In the MMM::Agent::Helpers::Network::add_ip function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for Linux), a specially crafted MMM protocol message can cause a shell command injection resulting in...Show more |
1Mysql Mmm 1Mysql Multi Master Replication Manager Nov 21, 2024 May 9, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 In the MMM::Agent::Helpers::_execute function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1, a specially crafted MMM protocol message can cause a shell command injection resulting in arbitrary command...Show more |
In Vecna VGo Robot versions prior to 3.0.3.52164, an attacker on an adjacent network could perform command injection. |
1Dell 2Emc Unity Operating Environment Emc Unityvsa Operating EnvironmentNov 21, 2024 May 8, 2018 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 Dell EMC Unity Operating Environment (OE) versions prior to 4.3.0.1522077968 are affected by multiple OS command injection vulnerabilities. A remote application admin user could potentially exploit the vulnerabilities to...Show more |