VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,475)

page 36 of 324
  • CVE-2023-53963CriDec 22, 2025
    risk 0.64cvss 9.8epss 0.03

    SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary shell commands through the 'password' parameter. Attackers can exploit the login.php and index.php scripts by injecting shell…

  • CVE-2023-53948CriDec 19, 2025
    risk 0.64cvss 9.8epss 0.01

    Lilac-Reloaded for Nagios 2.0.8 contains a remote code execution vulnerability in the autodiscovery feature that allows attackers to inject arbitrary commands. Attackers can exploit the lack of input filtering in the nmap_binary parameter to execute a reverse shell by sending a…

  • CVE-2023-53941CriDec 18, 2025
    risk 0.64cvss 9.8epss 0.06

    EasyPHP Webserver 14.1 contains an OS command injection vulnerability that allows unauthenticated attackers to execute arbitrary system commands by injecting malicious payloads through the app_service_control parameter. Attackers can send POST requests to…

  • CVE-2025-67164CriDec 17, 2025
    risk 0.64cvss 9.9epss 0.01

    An authenticated arbitrary file upload vulnerability in the /storage/poc.php component of Pagekit CMS v1.0.18 allows attackers to execute arbitrary code via uploading a crafted PHP file.

  • CVE-2024-14010CriDec 12, 2025
    risk 0.64cvss 9.8epss 0.01

    Typora 1.7.4 contains a command injection vulnerability in the PDF export preferences that allows attackers to execute arbitrary system commands. Attackers can inject malicious commands into the 'run command' input field during PDF export to achieve remote code execution.

  • CVE-2021-47728CriDec 9, 2025
    risk 0.64cvss 9.8epss 0.03

    Selea Targa IP OCR-ANPR Camera contains an unauthenticated command injection vulnerability in utils.php that allows remote attackers to execute arbitrary shell commands. Attackers can exploit the 'addr' and 'port' parameters to inject commands and gain www-data user access…

  • CVE-2025-65882CriDec 9, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in openmptcprouter thru 0.64 in file common/package/utils/sys-upgrade-helper/src/tools/sysupgrade.c in function create_xor_ipad_opad allowing attackers to potentially write arbitrary files or execute arbitrary commands.

  • CVE-2025-66576CriDec 4, 2025
    risk 0.64cvss 9.8epss 0.01

    Remote Keyboard Desktop 1.0.1 enables remote attackers to execute system commands via the rundll32.exe exported function export, allowing unauthenticated code execution.

  • CVE-2025-29269CriDec 4, 2025
    risk 0.64cvss 9.8epss 0.02

    ALLNET ALL-RUT22GW v3.3.8 was discovered to contain an OS command injection vulnerability via the command parameter in the popen.cgi endpoint.

  • CVE-2025-66208CriDec 3, 2025
    risk 0.64cvss 9.8epss 0.01

    Collabora Online - Built-in CODE Server (richdocumentscode) provides a built-in server with all of the document editing features of Collabora Online. In versions prior to 25.04.702, Collabora Online has a Configuration-Dependent RCE (OS Command Injection) in richdocumentscode…

  • CVE-2025-62354CriNov 26, 2025
    risk 0.64cvss 9.8epss 0.01

    Improper neutralization of special elements used in an OS command ('command injection') in Cursor allows an unauthorized attacker to execute commands that are outside of those specified in the allowlist, resulting in arbitrary code execution.

  • CVE-2025-66261CriNov 26, 2025
    risk 0.64cvss 9.8epss 0.02

    Unauthenticated OS Command Injection (restore_settings.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform URL-decoded name parameter passed to exec() allows remote…

  • CVE-2025-66253CriNov 26, 2025
    risk 0.64cvss 9.8epss 0.02

    Unauthenticated OS Command Injection (start_upgrade.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, 50, 100, 300, 500, 1000, 2000, 3000, 3500, 6000, 7000 allows an attacker to perform User input passed directly to exec() allows remote code…

  • CVE-2025-64755CriNov 21, 2025
    risk 0.64cvss 9.8epss 0.01

    Claude Code is an agentic coding tool. Prior to version 2.0.31, due to an error in sed command parsing, it was possible to bypass the Claude Code read-only validation and write to arbitrary files on the host system. This issue has been patched in version 2.0.31.

  • CVE-2025-60738CriNov 20, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in Ilevia EVE X1 Server Firmware Version v4.7.18.0.eden and before Logic Version v6.00 - 2025_07_21 and before allows a remote attacker to execute arbitrary code via the ping.php component does not perform secure filtering on IP parameters

  • CVE-2025-13284CriNov 17, 2025
    risk 0.64cvss 9.8epss 0.02

    ThinPLUS developed by ThinPLUS has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server.

  • CVE-2022-50596CriNov 6, 2025
    risk 0.64cvss 9.8epss 0.04

    D-Link DIR-1260 Wi-Fi router firmware versions up to and including v1.20B05 contain a command injection vulnerability within the web management interface that allows for unauthenticated attackers to execute arbitrary commands on the device with root privileges. The flaw…

  • CVE-2025-63334CriNov 5, 2025
    risk 0.64cvss 9.8epss 0.01

    PocketVJ CP PocketVJ-CP-v3 pvj version 3.9.1 contains an unauthenticated remote code execution vulnerability in the submit_opacity.php component. The application fails to sanitize user input in the opacityValue POST parameter before passing it to a shell command, allowing remote…

  • CVE-2025-61304CriNov 5, 2025
    risk 0.64cvss 9.8epss 0.02

    OS command injection vulnerability in Dynatrace ActiveGate ping extension up to 1.016 via crafted ip address.

  • CVE-2024-14003CriOct 30, 2025
    risk 0.64cvss 9.8epss 0.02

    Nagios XI versions prior to 2024R1.2 are vulnerable to remote code execution (RCE) through its NRDP (Nagios Remote Data Processor) server plugins. Insufficient validation of inbound NRDP request parameters allows crafted input to reach command execution paths, enabling…