VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,529)

page 213 of 327
  • CVE-2021-23379HigApr 18, 2021
    risk 0.48cvss 7.3epss 0.01

    This affects all versions of package portkiller. If (attacker-controlled) user input is given, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.

  • CVE-2021-23375HigApr 18, 2021
    risk 0.48cvss 7.3epss 0.01

    This affects all versions of package psnode. If attacker-controlled user input is given to the kill function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.

  • CVE-2021-23374HigApr 18, 2021
    risk 0.48cvss 7.3epss 0.01

    This affects all versions of package ps-visitor. If attacker-controlled user input is given to the kill function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.

  • CVE-2020-28426HigFeb 1, 2021
    risk 0.48cvss 7.3epss 0.02

    All versions of package kill-process-on-port are vulnerable to Command Injection via a.getProcessPortId.

  • CVE-2020-7688HigJul 1, 2020
    risk 0.48cvss 8.4epss 0.01

    The issue occurs because tagName user input is formatted inside the exec function is executed without any checks.

  • CVE-2019-18934HigNov 19, 2019
    risk 0.48cvss 7.3epss 0.03

    Unbound 1.6.4 through 1.9.4 contain a vulnerability in the ipsec module that can cause shell code execution after receiving a specially crafted answer. This issue can only be triggered if unbound was compiled with `--enable-ipsecmod` support, and ipsecmod is enabled and used in…

  • CVE-2019-11829HigJun 30, 2019
    risk 0.48cvss 7.3epss 0.02

    OS command injection vulnerability in drivers_syno_import_user.php in Synology Calendar before 2.3.1-0617 allows remote attackers to execute arbitrary commands via the crafted 'X-Real-IP' header.

  • CVE-2018-19015HigJan 28, 2019
    risk 0.48cvss 7.3epss 0.01

    An attacker could inject commands to launch programs and create, write, and read files on CX-Supervisor (Versions 3.42 and prior) through a specially crafted project file. An attacker could exploit this to execute code under the privileges of the application.

  • CVE-2018-16863HigDec 3, 2018
    risk 0.48cvss 7.3epss 0.01

    It was found that RHSA-2018:2918 did not fully fix CVE-2018-16509. An attacker could possibly exploit another variant of the flaw and bypass the -dSAFER protection to, for example, execute arbitrary shell commands via a specially crafted PostScript document. This only affects…

  • CVE-2018-6021HigMay 9, 2018
    risk 0.48cvss 7.4epss 0.01

    Silex SD-320AN version 2.01 and prior and GE MobileLink(GEH-SD-320AN) version GEH-1.1 and prior have a system call parameter that is not properly sanitized, which may allow remote code execution.

  • CVE-2015-4956HigFeb 15, 2016
    risk 0.48cvss 7.4epss 0.01

    The Web UI in IBM Security QRadar SIEM 7.1.x before 7.1 MR2 Patch 12 allows remote authenticated users to execute unspecified OS commands via unknown vectors.

  • CVE-2026-53804HigAug 20, 2026
    risk 0.47cvss 7.2epss 0.01

    OTRS Community Edition contains an authenticated OS command injection vulnerability in the PGP encryption module that allows administrators to execute arbitrary operating-system commands by supplying crafted values for the PGP binary path and command options.…

  • CVE-2026-23501HigAug 19, 2026
    risk 0.47cvss 7.2epss 0.01

    Dell RecoverPoint for VMs, versions 6.0.3 and 6.0.3.1, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to…

  • CVE-2026-54796HigAug 19, 2026
    risk 0.47cvss 7.2epss 0.02

    Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to…

  • CVE-2026-56685HigAug 17, 2026
    risk 0.47cvss 7.3epss 0.00

    Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command…

  • CVE-2026-19628HigAug 14, 2026
    risk 0.47cvss 7.2epss 0.03

    A command injection vulnerability exists in Tenable Security Center. An authenticated administrator could modify application configuration values to achieve arbitrary command execution on the underlying operating system when specific backend operations are triggered.

  • CVE-2026-19771HigAug 14, 2026
    risk 0.47cvss 7.2epss 0.03

    A vulnerability was identified in Baicells EG3661M BaiCE_BQ6_2.0.5.3_NA. This impacts an unknown function of the file /cgi-bin/luci of the component LuCI Web Interface. Such manipulation of the argument MaxHops/Timeout/Size leads to os command injection. The attack may be…

  • CVE-2026-13476HigAug 12, 2026
    risk 0.47cvss 7.3epss 0.01

    IBM Informix Dynamic Server 14.10, 15.0, and 12.10 could allow an unauthenticated user to execute arbitrary commands with service account privileges on the system due to improper validation of user supplied input.

  • CVE-2026-12005HigAug 12, 2026
    risk 0.47cvss 7.2epss 0.00

    IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 contains a input validation vulnerability in the management interface that allows already privileged attackers to…

  • CVE-2026-48098HigAug 7, 2026
    risk 0.47cvss 7.3epss 0.00

    NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Versions prior to 2.0.0 execute privileged system commands using `sudo` and `shell=True` directly inside application logic. In environments where passwordless sudo…