İçeriğe atla
Noroxi

CWE-77 · 3.230 kayıt

Improper Neutralization of Special Elements used in a Command ('Command Injection')

Bu sınıftaki CVE’ler

3.228 kayıt

  • A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    sophos · web appliance4 Nis 2023

  • sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle que

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    php · php11 May 2012

  • D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    dlink · dns-320l firmware3 Nis 2024

  • Deserialization Vulnerability in GoAnywhere MFT's License Servlet

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    fortra · goanywhere managed file transfer18 Eyl 2025

  • (1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear WN604 before 3.3.3

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %98

    netgear · wnap320 firmware21 Nis 2017

  • Aria Operations for Networks contains a command injection vulnerability.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %98

    vmware · aria operations for networks7 Haz 2023

  • masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to exe

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %97

    al-enterprise · omnipcx enterprise communication server18 Eyl 2007

  • In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbit

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %94

    cleo · harmony13 Ara 2024

  • A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an aut

    KritikCVSS 9,1KEVSilahlaştırılmışEPSS %100

    ivanti · connect secure12 Oca 2024

  • TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form o

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %100

    tp-link · archer ax21 firmware15 Mar 2023

  • Command Injection Vulnerability in Remote Support(RS) & Privileged Remote Access (PRA)

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %87

    beyondtrust · privileged remote access17 Ara 2024

  • The D-Link DIR-645 Wired/Wireless Router Rev.

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %97

    dlink · dir-645 firmware23 Şub 2015

  • Arbitrary Command Injection in Smartbedded MeteoBridge

    YüksekCVSS 8,7KEVSilahlaştırılmışEPSS %94

    smartbedded · meteobridge vm21 May 2025

  • OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %77

    progress · connection manager for objectscale4 Haz 2026

  • HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1)

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %75

    hp · openview network node manager2 Eyl 2005

  • D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wil

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %64

    dlink · dsl-2750b firmware19 Eki 2022

  • DrayTek Vigor2960/Vigor300B Web Management Interface apmcfgupload os command injection

    OrtaCVSS 6,9KEVSilahlaştırılmışEPSS %98

    draytek · vigor300b firmware27 Ara 2024

  • A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote

    YüksekCVSS 7,2KEVSilahlaştırılmışEPSS %88

    dlink · dir-823x firmware25 Mar 2025

  • An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices.

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %54

    dlink · dcs-4703e firmware2 Eyl 2020

  • A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Ex

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %53

    microsoft · internet explorer8 Oca 2019

  • On certain Ubiquiti devices, Command Injection exists via a GET request to stainfo.cgi (aka Show AP info) because the ifname variable is not

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %39

    ui · airos11 Haz 2019

  • CVE-2020-2509
    79Bu hafta

    Command Injection Vulnerability in QTS and QuTS hero

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %34

    qnap · qts17 Nis 2021

  • CVE-2023-33538
    77Bu hafta

    TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerability via the component

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %42

    tp-link · tl-wr940n firmware7 Haz 2023

  • CVE-2024-9380
    76Bu hafta

    An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker wit

    YüksekCVSS 7,2KEVSilahlaştırılmışEPSS %60

    ivanti · endpoint manager cloud services appliance8 Eki 2024

  • CVE-2017-6327
    76Bu hafta

    The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution, which describes a situation whereby an ind

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %36

    symantec · message gateway11 Ağu 2017

Tüm zafiyet sınıfları