CWE-78
6,626 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CVEs (6,626)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Dell EMC ScaleIO versions prior to 2.5, contain a command injection vulnerability in the Light Installation Agent (LIA). This component is used for central management of ScaleIO deployment and uses shell commands for cer...Show more |
1Qqq Systems Project 1Qqq Systems Nov 21, 2024 Mar 22, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 QQQ SYSTEMS version 2.24 allows an attacker to execute arbitrary commands via unspecified vectors. |
In the web ui of the openbuildservice before 2.3.0 a code injection of the project rebuildtimes statistics could be used by authorized attackers to execute shellcode. |
1Trendmicro 1Smart Protection Server Jun 17, 2026 Mar 15, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A server auth command injection authentication bypass vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.3 and below could allow remote attackers to escalate privileges on vulnerable installatio...Show more |
1Trendmicro 1Email Encryption Gateway Jun 17, 2026 Mar 15, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Arbitrary logs location in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to change location of log files and be manipulated to execute arbitrary commands and attain command execution on a vulnerable sy...Show more |
Buffalo WXR-1900DHP2 firmware Ver.2.48 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors. |
1Zohocorp 1Manageengine Applications Manager Jun 17, 2026 Mar 8, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A remote code execution issue was discovered in Zoho ManageEngine Applications Manager before 13.6 (build 13640). The publicly accessible testCredential.do endpoint takes multiple user inputs and validates supplied crede...Show more |
1Qnap 1Media Streaming Add On Nov 21, 2024 Mar 8, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier allows remote attackers to run arbitrary OS commands against the system with root privileges. |
A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers could allow an authenticated, local attacker to execute arbitrary commands with root privileges on an...Show more |
1Cisco 1Identity Services Engine Nov 21, 2024 Mar 8, 2018 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 A vulnerability in specific CLI commands for the Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to perform command injection to the underlying operating system or cause a hang or discon...Show more |
1Cisco 3Asr 5000 Firmware Asr 5500 FirmwareAsr 5700 FirmwareNov 21, 2024 Mar 8, 2018 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers could allow an authenticated, local attacker to perform a command injection attack on an affected sys...Show more |
1Cisco 1Identity Services Engine Nov 21, 2024 Mar 8, 2018 N/A· v4 5.3 MEDIUM· v3 4.6 MEDIUM· v2 A vulnerability in certain CLI commands of Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to execute arbitrary commands on the host operating system with the privileges of the local use...Show more |
Github Electron version Electron 1.8.2-beta.4 and earlier contains a Command Injection vulnerability in Protocol Handler that can result in command execute. This attack appear to be exploitable via the victim opening an...Show more |
1Dlink 4Dir 860l Firmware Dir 865l FirmwareDir 868l Firmware+1 moreJun 17, 2026 Mar 6, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 OS command injection vulnerability in soap.cgi (soapcgi_main in cgibin) in D-Link DIR-880L DIR-880L_REVA_FIRMWARE_PATCH_1.08B04 and previous versions, DIR-868L DIR868LA1_FW112b04 and previous versions, DIR-65L DIR-865L_R...Show more |
An issue was discovered in ClipBucket before 4.0.0 Release 4902. Any OS commands can be injected via shell metacharacters in the file_name parameter to /api/file_uploader.php or /actions/file_downloader.php. |
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Amazon Music Player 6.1.5.1213. User interaction is required to exploit this vulnerability in that the target must visit...Show more |
1Opensuse 1Obs Service Source Validator Nov 21, 2024 Mar 1, 2018 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 A shell command injection in the obs-service-source_validator before 0.7 could be used to execute code as the packager when checking RPM SPEC files with specific macro constructs. |
Vesta Control Panel before 0.9.8-14 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the backup parameter to list/backup/index.php. |
IBM BigFix Platform 9.0, 9.1 before 9.1.8, and 9.2 before 9.2.8 allow remote authenticated users to execute arbitrary commands by leveraging report server access. IBM X-Force ID: 111302. |
Remote code execution vulnerability in /cmsms-2.1.6-install.php/index.php in CMS Made Simple version 2.1.6 allows remote attackers to inject arbitrary PHP code via the "timezone" parameter in step 4 of a fresh installati...Show more |