CWE-78

High likelihood

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Parent: CWE-77 - Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

5,967 vulnerabilities with CWE-78
CVE-2024-31976 HIGH
EnGenius EWS356-FIR <=1.1.30 - Controller Parameter OS Command Injection
CVSS 8.0
CVE-2024-9461 HIGH
Total Upkeep - WordPress Backup Plugin < 1.16.7 - Authenticated Remote Code Execution via cron_interval Parameter
CVSS 7.2
CVE-2024-50377 MEDIUM
Advantech EKI-6333AC-2G/2GD <1.6.5 & EKI-6333AC-1GPO <1.2.2 - Hard-coded Credentials
CVSS 6.5
CVE-2024-50376 HIGH
Advantech EKI-6333AC-2G/2GD/1GPO Firmware - Cross-Site Scripting via Malicious Wi-Fi SSID
CVSS 7.3
CVE-2024-50375 CRITICAL
Advantech EKI-6333AC-2G/2GD/1GPO Firmware - Unauthenticated OS Command Injection via edgserver Service
CVSS 9.8
CVE-2024-50374 CRITICAL
Advantech EKI-6333AC Firmware - Unauthenticated OS Command Injection via edgserver capture_packages
CVSS 9.8
CVE-2024-50373 CRITICAL
Advantech EKI-6333AC-2G/2GD/1GPO Firmware - Unauthenticated OS Command Injection
CVSS 9.8
CVE-2024-50372 CRITICAL
Advantech EKI-6333AC Firmware < 1.6.5 - Unauthenticated OS Command Injection via edgserver backup_config_to_utility
CVSS 9.8
CVE-2024-50371 CRITICAL
Advantech EKI-6333AC Firmware <= 1.6.3/1.2.1 - Unauthenticated OS Command Injection via wlan_scan Operation
CVSS 9.8
CVE-2024-50370 CRITICAL
Advantech EKI-6333AC-2G/2GD/1GPO Firmware - Unauthenticated OS Command Injection via cfg_cmd_set_eth_conf
CVSS 9.8
CVE-2024-50369 HIGH
Advantech EKI-6333AC Firmware - OS Command Injection via multiple_ssid_htm API Parameters
CVSS 7.2
CVE-2024-50368 HIGH
Advantech EKI-6333AC Firmware - OS Command Injection via basic_htm API Parameters
CVSS 7.2
CVE-2024-50367 HIGH
Advantech EKI-6333AC Firmware - OS Command Injection via sta_log_htm API Parameters
CVSS 7.2
CVE-2024-50366 HIGH
Advantech EKI-6333AC-2G/2GD/1GPO Firmware - OS Command Injection via applications_apply API
CVSS 7.2
CVE-2024-50365 HIGH
Advantech EKI-6333AC Firmware - OS Command Injection via lan_apply API Parameters
CVSS 7.2
CVE-2024-50364 HIGH
Advantech EKI-6333AC Firmware - OS Command Injection via Export Log API Parameters
CVSS 7.2
CVE-2024-50363 HIGH
Advantech EKI-6333AC Firmware - OS Command Injection via mp_apply API Parameters
CVSS 7.2
CVE-2024-50362 HIGH
Advantech EKI-6333AC-2G/2GD/1GPO Firmware - OS Command Injection via connection_profile_apply API
CVSS 7.2
CVE-2024-50361 HIGH
Advantech EKI-6333AC Firmware - OS Command Injection via Certificate File Remove API
CVSS 7.2
CVE-2024-50360 HIGH
Advantech EKI-6333AC Firmware - OS Command Injection via SNMP Apply API Parameters
CVSS 7.2
CVE-2024-50359 HIGH
Advantech EKI-6333AC Firmware - OS Command Injection via scan_ap API Parameters
CVSS 7.2
CVE-2024-53899 HIGH
virtualenv <20.26.6 - Command Injection
CVSS 7.8
CVE-2024-52034 CRITICAL
mySCADA myPRO Manager - Unauthenticated OS Command Injection
CVSS 10.0
CVE-2024-47407 CRITICAL
mySCADA myPRO Manager Unauthenticated Command Injection (CVE-2024-47407)
CVSS 10.0
CVE-2024-8360 MEDIUM
Visteon Infotainment - Command Injection
CVSS 6.8
Details
Vulnerabilities 5,967
Exploit Likelihood High