Command Injection

CWE-77 · 9 records · 7 with a public proof-of-concept

Records the NVD classes as Command Injection (CWE-77), highest CVSS first.

  1. CRITICAL 9.8CVE-2025-29296

    H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R009, H3C Magic NX15 V100R017, H3C Magic R1510 V100R016, H3C NE36 Pro V100R002 and H3C MC102G HM1A0V200R010 contain multiple command injection vulnerabilities in

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 8.8CVE-2026-18787public PoC

    A vulnerability was identified in GL.iNet AX1800 up to 4.8.3. The affected element is the function remove_rule of the file /usr/share/gl-ngx/oui-rpc.lua of the component RPC Endpoint. The manipulation of the argument args.id leads to command injection. The att

    AI risk analysis on Exploit-DB.ai →

  3. HIGH 7.2CVE-2026-7693

    The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 2.1.5.1 due to insufficient sanitization of the `file` POST parameter on the `restoreBackup()` AJAX handler. The handler applies `esc_attr()`

    AI risk analysis on Exploit-DB.ai →

  4. HIGH 7.2CVE-2026-18902public PoC

    A vulnerability was detected in H3C NX15 V100R017. Affected by this vulnerability is the function esps.wan.repeater.set/repeaterproc of the file /api/esps. Performing a manipulation of the argument my2P4key results in command injection. Remote exploitation of

    AI risk analysis on Exploit-DB.ai →

  5. HIGH 7.2CVE-2026-18900public PoC

    A weakness has been identified in H3C NX15 V100R017. This impacts the function file.exec of the file /api/esps of the component Backend RPC. This manipulation of the argument File causes os command injection. The attack may be initiated remotely. The exploit h

    AI risk analysis on Exploit-DB.ai →

  6. HIGH 7.2CVE-2026-18814public PoC

    A vulnerability was found in H3C NX15 V100R017. This impacts the function reload.reload_config of the file /api/esps. The manipulation results in command injection. The attack can be launched remotely. The exploit has been made public and could be used. The ve

    AI risk analysis on Exploit-DB.ai →

  7. HIGH 7.2CVE-2026-18813public PoC

    A vulnerability has been found in H3C NX15 V100R017. This affects the function delete of the file /api/esps. The manipulation of the argument esps.apcm.version leads to command injection. The attack can be initiated remotely. The exploit has been disclosed to

    AI risk analysis on Exploit-DB.ai →

  8. HIGH 7.2CVE-2026-18812public PoC

    A flaw has been found in H3C NX15 V100R017. The impacted element is the function esps.ipv6.wan of the file /api/esps. Executing a manipulation of the argument workMode can lead to command injection. It is possible to launch the attack remotely. The exploit has

    AI risk analysis on Exploit-DB.ai →

  9. HIGH 7.2CVE-2026-18811public PoC

    A vulnerability was detected in H3C NX15 V100R017. The affected element is the function Add of the file /api/esps. Performing a manipulation of the argument esps.filter.url results in command injection. It is possible to initiate the attack remotely. The explo

    AI risk analysis on Exploit-DB.ai →