CWE-78
6,626 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CVEs (6,626)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Ohcount 3.0.0 is prone to a command injection via specially crafted filenames containing shell metacharacters, which can be exploited by an attacker (providing a source tree for Ohcount processing) to execute arbitrary c...Show more |
1Tenda 3Ac15 Firmware Ac18 FirmwareAc9 FirmwareMay 13, 2026 Nov 21, 2017 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 Command Injection vulnerability in app_data_center on Shenzhen Tenda Ac9 US_AC9V1.0BR_V15.03.05.14_multi_TD01, Ac9 ac9_kf_V15.03.05.19(6318_)_cn, Ac15 US_AC15V1.0BR_V15.03.05.18_multi_TD01, Ac15 US_AC15V1.0BR_V15.03.05.1...Show more |
ROOT xrootd version 4.6.0 and below is vulnerable to an unauthenticated shell command injection resulting in remote code execution |
ROOT version 6.9.03 and below is vulnerable to an authenticated shell metacharacter injection in the rootd daemon resulting in remote code execution |
I, Librarian version <=4.6 & 4.7 is vulnerable to OS Command Injection in batchimport.php resulting the web server being fully compromised. |
1Pidusage Project 1Pidusage May 13, 2026 Nov 17, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 soyuka/pidusage <=1.1.4 is vulnerable to command injection in the module resulting in arbitrary command execution |
1Windows Cpu Project 1Windows Cpu May 13, 2026 Nov 17, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 npm/KyleRoss windows-cpu all versions vulnerable to command injection resulting in code execution as Node.js user |
1Cisco 1Ip Phone 8800 Series Firmware May 13, 2026 Nov 16, 2017 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 A vulnerability in the debug interface of Cisco IP Phone 8800 series could allow an authenticated, local attacker to execute arbitrary commands, aka Debug Shell Command Injection. The vulnerability is due to insufficient...Show more |
CouchDB administrative users can configure the database server via HTTP(S). Some of the configuration options include paths for operating system-level binaries that are subsequently launched by CouchDB. This allows an ad...Show more |
1Ibm 1Security Access Manager 9.0 Firmware May 13, 2026 Nov 13, 2017 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 IBM Security Access Manager Appliance 9.0.3 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to...Show more |
backintime (aka Back in Time) before 1.1.24 did improper escaping/quoting of file paths used as arguments to the 'notify-send' command, leading to some parts of file paths being executed as shell commands within an os.sy...Show more |
lib/rrd.php in Cacti 1.1.27 allows remote authenticated administrators to execute arbitrary OS commands via the path_rrdtool parameter in an action=save request to settings.php. |
1Meetcircle 1Circle With Disney Firmware May 13, 2026 Nov 7, 2017 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 An exploitable vulnerability exists in the notifications functionality of Circle with Disney running firmware 2.0.1. Specially crafted network packets can cause an OS command injection. An attacker can send an HTTP reque...Show more |
1Meetcircle 1Circle With Disney Firmware May 13, 2026 Nov 7, 2017 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 An exploitable vulnerability exists in the /api/CONFIG/restore functionality of Circle with Disney running firmware 2.0.1. Specially crafted network packets can cause an OS command injection. An attacker can send an HTTP...Show more |
1Meetcircle 1Circle With Disney Firmware May 13, 2026 Nov 7, 2017 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 An exploitable vulnerability exists in the /api/CONFIG/backup functionality of Circle with Disney. Specially crafted network packets can cause an OS command injection. An attacker can send an HTTP request to trigger this...Show more |
1Cisco 3Firepower 4100 Next Generation Firewall Firmware Firepower 9300 Security Appliance FirmwareUnified Computing System Manager FirmwareMay 13, 2026 Nov 2, 2017 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A vulnerability in the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker t...Show more |
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.3.0.14878. User interaction is required to exploit this vulnerability in that the target must visit a mal...Show more |
1Barco 2Clickshare Csc 1 Firmware Clickshare Csm 1 FirmwareMay 13, 2026 Oct 30, 2017 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A command injection was identified on Barco ClickShare Base Unit devices with CSM-1 firmware before 1.7.0.3 and CSC-1 firmware before 1.10.0.10. An attacker with access to the product's web API can exploit this vulnerabi...Show more |
2Debian Shadowsocks2Debian Linux Shadowsocks LibevMay 13, 2026 Oct 27, 2017 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 In manager.c in ss-manager in shadowsocks-libev 3.1.0, improper parsing allows command injection via shell metacharacters in a JSON configuration request received via 127.0.0.1 UDP traffic, related to the add_server, bui...Show more |
An OS Command Injection vulnerability in Fortinet FortiWLC 6.1-2 through 6.1-5, 7.0-7 through 7.0-10, 8.0 through 8.2, and 8.3.0 through 8.3.2 file management AP script download webUI page allows an authenticated admin u...Show more |