CWE-78
6,626 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CVEs (6,626)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web man...Show more |
1Cambiumnetworks 2Epmp 1000 Firmware Epmp 2000 FirmwareMay 13, 2026 Dec 20, 2017 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 In version 3.5 and prior of Cambium Networks ePMP firmware, a lack of input sanitation for certain parameters on the web management console allows any authenticated user (including the otherwise low-privilege readonly us...Show more |
The ZoomLauncher binary in the Zoom client for Linux before 2.0.115900.1201 does not properly sanitize user input when constructing a shell command, which allows remote attackers to execute arbitrary code by leveraging t...Show more |
1Tp Link 15Tl War1200l Firmware Tl War1300l FirmwareTl War1750l Firmware+12 moreMay 13, 2026 Dec 19, 2017 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 TP-Link TL-WVR and TL-WAR devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the interface field of an admin/dhcps command to cgi-bin/luci, related to the zone_get_iface_by...Show more |
1Tp Link 15Tl War1200l Firmware Tl War1300l FirmwareTl War1750l Firmware+12 moreMay 13, 2026 Dec 19, 2017 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 TP-Link TL-WVR and TL-WAR devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the interface field of an admin/wportal command to cgi-bin/luci, related to the get_device_byif...Show more |
1Zivif 1Pr115 204 P Rs Firmware May 13, 2026 Dec 19, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Zivif PR115-204-P-RS V2.3.4.2103 and V4.7.4.2121 (and possibly in-between versions) web cameras are vulnerable to unauthenticated, blind remote command injection via CGI scripts used as part of the web interface, as demo...Show more |
2Heketi Project Redhat2Enterprise Linux HeketiMay 13, 2026 Dec 18, 2017 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A security-check flaw was found in the way the Heketi 5 server API handled user requests. An authenticated Heketi user could send specially crafted requests to the Heketi server, resulting in remote command execution as...Show more |
Qt for Android prior to 5.9.0 allows remote attackers to execute arbitrary OS commands via unspecified vectors. |
3Debian RedhatRuby Lang8Debian Linux Enterprise Linux DesktopEnterprise Linux Server+5 moreMay 13, 2026 Dec 15, 2017 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Ruby before 2.4.3 allows Net::FTP command injection. Net::FTP#get, getbinaryfile, gettextfile, put, putbinaryfile, and puttextfile use Kernel#open to open a local file. If the localfile argument starts with the "|" pipe...Show more |
In OTRS 6.0.x up to and including 6.0.1, OTRS 5.0.x up to and including 5.0.24, and OTRS 4.0.x up to and including 4.0.26, an attacker who is logged into OTRS as an agent can manipulate form parameters (related to PGP) a...Show more |
2Debian Mercurial2Debian Linux MercurialMay 13, 2026 Dec 7, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 In Mercurial before 4.4.1, it is possible that a specially malformed repository can cause Git subrepositories to run arbitrary code in the form of a .git/hooks/post-update script checked into the repository. Typical use...Show more |
Artica Web Proxy before 3.06.112911 allows remote attackers to execute arbitrary code as root by conducting a cross-site scripting (XSS) attack involving the username-form-id parameter to freeradius.users.php. |
The most package in Debian wheezy before 5.0.0a-2.2, in Debian jessie before 5.0.0a-2.3+deb8u1, and in Debian unstable before 5.0.0a-3 allows remote attackers to execute arbitrary commands via shell metacharacters in the...Show more |
1Princeton 1Ptw Wms1 Firmware May 13, 2026 Dec 1, 2017 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 PTW-WMS1 firmware version 2.000.012 allows remote attackers to execute arbitrary OS commands via unspecified vectors. |
Command injection in evince via filename when printing to PDF. This affects versions earlier than 3.25.91. |
GitPHP by xiphux is vulnerable to OS Command Injections |
1Tp Link 54Tl Er3210g Firmware Tl Er3220g FirmwareTl Er5110g Firmware+51 moreMay 13, 2026 Nov 27, 2017 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the t_bindif field of an admin/interface command to cgi-bin/luci, related to the...Show more |
1Tp Link 51Tl Er3210g Firmware Tl Er3220g FirmwareTl Er5110g Firmware+48 moreMay 13, 2026 Nov 27, 2017 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the t_bindif field of an admin/bridge command to cgi-bin/luci, related to the get...Show more |
1Tp Link 51Tl Er3210g Firmware Tl Er3220g FirmwareTl Er5110g Firmware+48 moreMay 13, 2026 Nov 27, 2017 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the iface field of an admin/diagnostic command to cgi-bin/luci, related to the zo...Show more |
The web server on DBL DBLTek devices allows remote attackers to execute arbitrary OS commands by obtaining the admin password via a frame.html?content=/dev/mtdblock/5 request, and then using this password for the HTTP Ba...Show more |