Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

type:cmd-inject — CVE vulnerabilities tagged 6358

6358 CVE security advisories tagged "type:cmd-inject" with AI Chinese analysis, CVSS, references and POCs.

The tag "type:cmd-inject" identifies Command Injection vulnerabilities, a critical security flaw where untrusted user input is improperly concatenated into system commands without adequate sanitization. This matters because it allows attackers to execute arbitrary operating system commands with the privileges of the vulnerable application, potentially leading to full system compromise, data exfiltration, or lateral movement within a network. Typical scenarios involve web applications that pass user-supplied data to backend shell interpreters, such as using PHP’s exec function or Python’s os.system, to perform tasks like pinging a host or listing directory contents. The 5,541 associated CVEs highlight the pervasive nature of this risk across diverse software ecosystems, emphasizing the necessity for strict input validation, parameterized interfaces, and the principle of least privilege to mitigate the severe impact of unintended command execution.

CVE ID Title CVSS Severity Published
CVE-2026-53932 wnx/laravel-backup-restore: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') and Improper Neutralization of Special Elements used in a Command ('Command Injection') — laravel-backup-restore CWE-77 8.0 High 2026-09-04
CVE-2026-78327 SonicWall NSM命令注入致远程代码执行漏洞 — Network Security Manager (NSM) CWE-78 - - 2026-09-04
CVE-2026-85656 OS command injection in Amazon log4j-cve-2021-44228-hotpatch — log4j-cve-2021-44228-hotpatch CWE-78 7.8 High 2026-09-04
CVE-2026-17499 IBM i is Affected By Multiple Vulnerabilities in Debug Server — i CWE-78 4.4 Medium 2026-09-04
CVE-2026-85696 SadTalker OS Command Injection via Audio Filename — SadTalker CWE-78 9.8 Critical 2026-09-04
CVE-2026-85672 zerox 1.1.20 OS Command Injection via Document URL File Extension — zerox CWE-78 9.8 Critical 2026-09-04
CVE-2026-62928 XING CPTrans-ME-X 未认证 OS 命令注入漏洞 — XING CPTrans-ME-X CWE-78 9.3 Critical 2026-09-04
CVE-2026-85224 D-Link DNS-320 ShareCenter File Sharing file_sharing.cgi os command injection — DNS-320 ShareCenter CWE-78 9.1 Critical 2026-09-03
CVE-2026-85223 D-Link DNS-340L CGI dropbox.cgi os command injection — DNS-340L CWE-78 9.9 Critical 2026-09-03
CVE-2026-85222 D-Link DNS-340L Add-On Center addon_center.cgi os command injection — DNS-340L CWE-78 9.1 Critical 2026-09-03
CVE-2026-85012 OS command injection in the Amazon CodeCatalyst blueprints SDK — @amazon-codecatalyst/blueprints.blueprint CWE-78 8.0 High 2026-09-03
CVE-2026-84967 Arbitrary command execution via shell-expanded connection string in Launch MongoDB Shell terminal — MongoDB for VS Code CWE-78 4.3 Medium 2026-09-03
CVE-2026-63694 Dell SmartFabric OS10 Software 命令注入漏洞 — SmartFabric OS10 CWE-77 5.0 Medium 2026-09-03
CVE-2026-35160 Dell SmartFabric OS10 Software 命令注入漏洞 — SmartFabric OS10 Software CWE-78 5.0 Medium 2026-09-03
CVE-2026-84830 OS command injection in privileged configuration handling — Secure Email Gateway CWE-78 8.6 High 2026-09-03
CVE-2026-85040 ZhongBangKeJi CRMEB Custom Scheduled Task Feature save eval os command injection — CRMEB CWE-78 4.7 Medium 2026-09-03
CVE-2026-79756 Nuclio: Unauthenticated OS command injection via namespace header in list-all resource path on local platform — nuclio CWE-78 8.7 High 2026-09-02
CVE-2026-53611 Looking Glass: Remote Code Execution via Unanchored Regular Expression in BGPASPath Input Validation — looking-glass CWE-78 9.8 Critical 2026-09-02
CVE-2026-84675 Jenkins TICS Plugin 命令注入漏洞 — Jenkins TICS Plugin - - 2026-09-02
CVE-2026-84838 Rpm: command injection in rpmuncompress via unescaped filenames passed to popen() — Red Hat Enterprise Linux 10 CWE-78 7.8 High 2026-09-02
CVE-2026-84837 Rpm: command injection in `rpmbuild -t*` (`gettarspec`) via unescaped tarball path — Red Hat Enterprise Linux 10 CWE-78 7.8 High 2026-09-02
CVE-2026-84694 Coolify before 4.2.0 Remote Code Execution via Environment Variable Key — coolify CWE-78 8.8 High 2026-09-02
CVE-2025-46418 Westermo WeOS 命令注入漏洞 — WeOS CWE-78 7.6 High 2026-09-02
CVE-2026-83549 SonicWALL SMA1000 命令注入漏洞 — SMA1000 CWE-78 - - 2026-09-01
CVE-2026-73767 Authenticated Remote Command Injection Vulnerabilities in AOS-CX Command Line Interface — AOS-CX 7.2 High 2026-09-01
CVE-2026-73766 Authenticated Command Injection Vulnerabilities in the API Endpoint of AOS-CX — AOS-CX 7.2 High 2026-09-01
CVE-2026-73751 Authenticated Remote Command Injection in AOS-CX Web-based Management Interface — AOS-CX 8.8 High 2026-09-01
CVE-2026-73722 Authenticated Command Injection Vulnerabilities in HPE Networking Fabric Composer Web-Based Management Interface — Fabric Composer 7.2 High 2026-09-01
CVE-2026-73717 Unauthenticated Command Injection Vulnerability in HPE Networking Fabric Composer Web-Based Management Interface — Fabric Composer 7.5 High 2026-09-01
CVE-2026-58567 Dell PowerStore 命令注入漏洞 — PowerStore 500T CWE-78 8.8 High 2026-09-01

Vulnerabilities classified as type:cmd-inject represent 6358 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.