VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,578)

page 162 of 329
  • CVE-2026-0507HigJan 13, 2026
    risk 0.55cvss 8.4epss 0.01

    Due to an OS Command Injection vulnerability in SAP Application Server for ABAP and SAP NetWeaver RFCSDK, an authenticated attacker with administrative access and adjacent network access could upload specially crafted content to the server. If processed by the application, this…

  • CVE-2025-67738HigDec 11, 2025
    risk 0.55cvss 8.5epss 0.00

    squid/cachemgr.cgi in Webmin before 2.600 does not properly quote arguments. This is relevant if Webmin's Squid module and its Cache Manager feature are available, and an untrusted party is able to authenticate to Webmin and has certain Cache Manager permissions (the "cms"…

  • CVE-2024-58278HigDec 4, 2025
    risk 0.55cvss epss 0.00

    perl2exe <= V30.10C contains an arbitrary code execution vulnerability that allows local authenticated attackers to execute malicious scripts. Attackers can control the 0th argument of packed executables to execute another executable, allowing them to bypass restrictions and…

  • CVE-2025-45379HigNov 5, 2025
    risk 0.55cvss 8.4epss 0.01

    Dell CloudLink, versions prior to 8.2, contain a vulnerability where a privileged user with known password can run command injection from console to gain shell access of system.

  • CVE-2025-30479HigNov 5, 2025
    risk 0.55cvss 8.4epss 0.01

    Dell CloudLink, versions prior to 8.2, contain a vulnerability where a privileged user with known password can run command injection to gain control of system.

  • CVE-2024-58274HigOct 22, 2025
    risk 0.55cvss 8.3epss 0.18

    Hikvision CSMP (Comprehensive Security Management Platform) iSecure Center through 2024-08-01 allows execution of a command within $( ) in /center/api/installation/detection JSON data, as exploited in the wild in 2024 and 2025.

  • CVE-2025-0636HigOct 13, 2025
    risk 0.55cvss 8.4epss 0.00

    EMCLI contains a high severity vulnerability where improper neutralization of special elements used in an OS command could be exploited leading to Arbitrary Code Execution.

  • CVE-2025-9494HigSep 23, 2025
    risk 0.55cvss epss 0.01

    An OS command injection vulnerability has been discovered in the Vitogate 300, which can be exploited by malicious users to compromise affected installations. Specifically, the `/cgi-bin/vitogate.cgi` endpoint is affected, when the `form` JSON parameter is set to `form-0-2`. The…

  • CVE-2025-54084HigSep 9, 2025
    risk 0.55cvss epss 0.01

    OS Command ('OS Command Injection') vulnerability in Calix GigaCenter ONT (Quantenna SoC modules) allows authenticated attackers with 'super' user credentials to execute arbitrary OS commands through improper input validation, potentially leading to full system compromise.This…

  • CVE-2025-58180HigSep 9, 2025
    risk 0.55cvss 8.8epss 0.21

    OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.11.2 contain a vulnerability that allows an authenticated attacker to upload a file under a specially crafted filename that will allow arbitrary command execution…

  • CVE-2025-56803HigSep 3, 2025
    risk 0.55cvss 8.4epss 0.01

    Figma Desktop for Windows version 125.6.5 contains a command injection vulnerability in the local plugin loader. An attacker can execute arbitrary OS commands by setting a crafted build field in the plugin's manifest.json. This field is passed to child_process.exec without…

  • CVE-2025-44015HigAug 29, 2025
    risk 0.55cvss 8.4epss 0.01

    A command injection vulnerability has been reported to affect HybridDesk Station. If an attacker gains local network access, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following version: HybridDesk…

  • CVE-2025-6181HigAug 20, 2025
    risk 0.55cvss epss 0.00

    The StrongDM Windows service incorrectly handled input validation. Authenticated attackers could potentially exploit this leading to privilege escalation.

  • CVE-2025-54135HigAug 5, 2025
    risk 0.55cvss 8.5epss 0.02

    Cursor is a code editor built for programming with AI. Cursor allows writing in-workspace files with no user approval in versions below 1.3.9, If the file is a dotfile, editing it requires approval but creating a new one doesn't. Hence, if sensitive MCP files, such as the…

  • CVE-2025-44960HigAug 4, 2025
    risk 0.55cvss 8.5epss 0.02

    RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows OS command injection via a certain parameter in an API route.

  • CVE-2025-7723HigJul 22, 2025
    risk 0.55cvss epss 0.01

    A command injection vulnerability exists that can be exploited after authentication in VIGI NVR1104H-4P V1 and VIGI NVR2016H-16MP V2.This issue affects VIGI NVR1104H-4P V1: before 1.1.5 Build 250518; VIGI NVR2016H-16MP V2: before 1.3.1 Build 250407.

  • CVE-2025-24938HigJul 21, 2025
    risk 0.55cvss 8.4epss 0.00

    The web application allows user input to pass unfiltered to a command executed on the underlying operating system. An attacker with high privileged access (administrator) to the application has the potential execute commands on the operating system under the context of the…

  • CVE-2025-25269HigJul 8, 2025
    risk 0.55cvss 8.4epss 0.00

    An unauthenticated local attacker can inject a command that is subsequently executed as root, leading to a privilege escalation.

  • CVE-2025-23049HigJun 23, 2025
    risk 0.55cvss epss 0.02

    Meridian Technique Materialise OrthoView through 7.5.1 allows OS Command Injection when servlet sharing is enabled.

  • CVE-2025-4230HigJun 13, 2025
    risk 0.55cvss epss 0.01

    A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to exploit this issue, the user must have access to the PAN-OS CLI. The security…