← Back
CWE-78

6,626 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

JSON object

Loading...

CVEs (6,626)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Novell
1Groupwise
Apr 29, 2026
Feb 24, 2013
N/A· v4
N/A· v3
10.0 HIGH· v2
The client in Novell GroupWise 8.0 before 8.0.3 HP2 and 2012 before SP1 HP1 allows remote attackers to execute arbitrary code or cause a denial of service (incorrect pointer dereference) via unspecified vectors.
1Emc
1Alphastor
Apr 29, 2026
Jan 21, 2013
N/A· v4
N/A· v3
9.3 HIGH· v2
The NetWorker command processor in rrobotd.exe in the Device Manager in EMC AlphaStor 4.0 before build 800 allows remote attackers to execute arbitrary commands via a DCP "run command" operation.
1Sinapsitech
4Esolar Duo Photovoltaic System Monitor
Esolar Light Photovoltaic System MonitorEsolar Photovoltaic System Monitor+1 more
Apr 29, 2026
Nov 23, 2012
N/A· v4
N/A· v3
10.0 HIGH· v2
These Sinapsi devices do not check for special elements in commands sent to the system. By accessing certain pages with administrative privileges that do not require authentication within the device, attackers can exe...Show more
These Sinapsi devices do not check for special elements in commands sent to the system. By accessing certain pages with administrative privileges that do not require authentication within the device, attackers can execute arbitrary, unexpected, or dangerous commands directly onto the operating system.Show less
1Mutiny
1Standard
Apr 29, 2026
Oct 22, 2012
N/A· v4
N/A· v3
8.5 HIGH· v2
Mutiny Standard before 4.5-1.12 allows remote attackers to execute arbitrary commands via the network-interface menu, related to a "command injection vulnerability."
1Cybozu
1Kunai
Apr 29, 2026
Sep 8, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
The Cybozu KUNAI application before 2.0.6 for Android allows remote attackers to execute arbitrary Java methods, and obtain sensitive information or execute arbitrary commands, via a crafted web site.
1Hp
1San/iq
Apr 29, 2026
Aug 20, 2012
N/A· v4
N/A· v3
7.7 HIGH· v2
lhn/public/network/ping in HP SAN/iQ before 9.5 on the HP Virtual SAN Appliance allows remote authenticated users to execute arbitrary commands via shell metacharacters in the second parameter.
1Hp
1San/iq
Apr 29, 2026
Aug 20, 2012
N/A· v4
N/A· v3
7.7 HIGH· v2
lhn/public/network/ping in HP SAN/iQ 9.5 on the HP Virtual SAN Appliance allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1) first, (2) third, or (3) fourth parameter. NOT...Show more
lhn/public/network/ping in HP SAN/iQ 9.5 on the HP Virtual SAN Appliance allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1) first, (2) third, or (3) fourth parameter. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-4361.Show less
1Ubi
1Uplay Pc
Apr 29, 2026
Aug 7, 2012
N/A· v4
N/A· v3
10.0 HIGH· v2
The web browser plugin for Ubisoft Uplay PC before 2.0.4 allows remote attackers to execute arbitrary programs via the -orbit_exe_path command line argument.
1Symantec
1Web Gateway
Apr 29, 2026
Jul 23, 2012
N/A· v4
N/A· v3
10.0 HIGH· v2
The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary shell commands via crafted input to application scripts, related to an "injection" issue.
1Symantec
1Web Gateway
Apr 29, 2026
Jul 23, 2012
N/A· v4
N/A· v3
10.0 HIGH· v2
The management console in Symantec Web Gateway 5.0.x before 5.0.3.18 allows remote attackers to execute arbitrary commands via crafted input to application scripts.
1Johnsoncontrols
2Network Controller
Network Controller Firmware
Apr 29, 2026
Jul 16, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
The Johnson Controls CK721-A controller with firmware before SSM4388_03.1.0.14_BB allows remote attackers to perform arbitrary actions via crafted packets to TCP port 41014 (aka the download port).
1Cisco
1Telepresence Recording Server
Apr 29, 2026
Jul 12, 2012
N/A· v4
N/A· v3
9.0 HIGH· v2
The administrative web interface on Cisco TelePresence Recording Server before 1.8.0 allows remote authenticated users to execute arbitrary commands via unspecified vectors, aka Bug ID CSCth85804.
1Cisco
11Telepresence System 1300 65
Telepresence System 3000Telepresence System 3010+8 more
Apr 29, 2026
Jul 12, 2012
N/A· v4
N/A· v3
9.0 HIGH· v2
The administrative web interface on Cisco TelePresence Immersive Endpoint Devices before 1.7.4 allows remote authenticated users to execute arbitrary commands via a malformed request on TCP port 443, aka Bug ID CSCtn9972...Show more
The administrative web interface on Cisco TelePresence Immersive Endpoint Devices before 1.7.4 allows remote authenticated users to execute arbitrary commands via a malformed request on TCP port 443, aka Bug ID CSCtn99724.Show less
1Cisco
11Telepresence System 1300 65
Telepresence System 3000Telepresence System 3010+8 more
Apr 29, 2026
Jul 12, 2012
N/A· v4
N/A· v3
8.3 HIGH· v2
An unspecified API on Cisco TelePresence Immersive Endpoint Devices before 1.9.1 allows remote attackers to execute arbitrary commands by leveraging certain adjacency and sending a malformed request on TCP port 61460, ak...Show more
An unspecified API on Cisco TelePresence Immersive Endpoint Devices before 1.9.1 allows remote attackers to execute arbitrary commands by leveraging certain adjacency and sending a malformed request on TCP port 61460, aka Bug ID CSCtz38382.Show less
1Ge
5Intelligent Platforms Proficy Batch Execution
Intelligent Platforms Proficy HistorianIntelligent Platforms Proficy Hmi/scada Ifix+2 more
Apr 29, 2026
Jul 5, 2012
N/A· v4
N/A· v3
9.3 HIGH· v2
An ActiveX control in KeyHelp.ocx in KeyWorks KeyHelp Module (aka the HTML Help component), as used in GE Intelligent Platforms Proficy Historian 3.1, 3.5, 4.0, and 4.5; Proficy HMI/SCADA iFIX 5.0 and 5.1; Proficy Pulse...Show more
An ActiveX control in KeyHelp.ocx in KeyWorks KeyHelp Module (aka the HTML Help component), as used in GE Intelligent Platforms Proficy Historian 3.1, 3.5, 4.0, and 4.5; Proficy HMI/SCADA iFIX 5.0 and 5.1; Proficy Pulse 1.0; Proficy Batch Execution 5.6; SI7 I/O Driver 7.20 through 7.42; and other products, allows remote attackers to execute arbitrary commands via crafted input, related to a "command injection vulnerability."Show less
1Anl
1Bcfg2
Apr 29, 2026
Jul 3, 2012
N/A· v4
N/A· v3
9.0 HIGH· v2
The Trigger plugin in bcfg2 1.2.x before 1.2.3 allows remote attackers with root access to the client to execute arbitrary commands via shell metacharacters in the UUID field to the server process (bcfg2-server).
4Canonical
DebianFedoraproject+1 more
5Debian Linux
FedoraPuppet+2 more
Apr 29, 2026
May 29, 2012
N/A· v4
N/A· v3
6.0 MEDIUM· v2
Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with agent SSL keys and file-creation permissions on t...Show more
Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with agent SSL keys and file-creation permissions on the puppet master to execute arbitrary commands by creating a file whose full pathname contains shell metacharacters, then performing a filebucket request.Show less
1Webglimpse
1Webglimpse
Apr 29, 2026
Mar 20, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
webglimpse.cgi in Webglimpse before 2.20.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the query parameter, as exploited in the wild in March 2012.
1Mawashimono
1Nikki
Apr 29, 2026
Nov 30, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
HP no Mawashimono Nikki 6.6 and earlier allows remote attackers to execute arbitrary commands via unspecified vectors, related to a "command injection vulnerability."
4Canyon Tech
EdimaxSitecom+1 more
126114wg
6114wg Router FirmwareBr 6104k Router Firmware+9 more
Apr 29, 2026
Nov 22, 2011
N/A· v4
N/A· v3
10.0 HIGH· v2
The UPnP IGD implementation in Edimax EdiLinux on the Edimax BR-6104K with firmware before 3.25, Edimax 6114Wg, Canyon-Tech CN-WF512 with firmware 1.83, Canyon-Tech CN-WF514 with firmware 2.08, Sitecom WL-153 with firmwa...Show more
The UPnP IGD implementation in Edimax EdiLinux on the Edimax BR-6104K with firmware before 3.25, Edimax 6114Wg, Canyon-Tech CN-WF512 with firmware 1.83, Canyon-Tech CN-WF514 with firmware 2.08, Sitecom WL-153 with firmware before 1.39, and Sweex LB000021 with firmware 3.15 allows remote attackers to execute arbitrary commands via shell metacharacters.Show less