CWE-77— Command Injection
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.— MITRE CWE catalog
4,102 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-77page 11 of 83
- CVE-2020-17759HIGHCVSS 8.8EG 8.82021-06-24
An issue was found in the Evernote client for Windows 10, 7, and 2008 in the protocol handler. This enables attackers for arbitrary command execution if the user clicks on a specially crafted URL. AKA: WINNOTE-19941.
- CVE-2020-1790HIGHCVSS 8.8EG 8.82020-02-18
GaussDB 200 with version of 6.5.1 have a command injection vulnerability. The software constructs part of a command using external input from users, but the software does not sufficiently validate the user input. Successful exploit could a…
- CVE-2020-18048CRITICALCVSS 9.8EG 9.82021-09-02
An issue in craigms/main.php of CraigMS 1.0 allows attackers to execute arbitrary commands via a crafted input entered into the DB Name field.
- CVE-2020-1811HIGHCVSS 8.8EG 8.82020-02-18
GaussDB 200 with version of 6.5.1 have a command injection vulnerability. Due to insufficient input validation, remote attackers with low permissions could exploit this vulnerability by sending crafted commands to the affected device. Succ…
- CVE-2020-18568CRITICALCVSS 9.8EG 9.82021-02-02
The D-Link DSR-250 (3.14) DSR-1000N (2.11B201) UPnP service contains a command injection vulnerability, which can cause remote command execution.
- CVE-2020-18758CRITICALCVSS 9.8EG 9.82021-08-13
An issue in Dut Computer Control Engineering Co.'s PLC MAC1100 allows attackers to execute arbitrary code.
- CVE-2020-18885HIGHCVSS 7.2EG 7.22021-08-20
Command Injection in PHPMyWind v5.6 allows remote attackers to execute arbitrary code via the "text color" field of the component '/admin/web_config.php'.
- CVE-2020-19001CRITICALCVSS 9.8EG 9.82021-08-27
Command Injection in Simiki v1.6.2.1 and prior allows remote attackers to execute arbitrary system commands via line 64 of the component 'simiki/blob/master/simiki/config.py'.
- CVE-2020-19151HIGHCVSS 8.8EG 8.82021-09-15
Command Injection in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code by uploading a malicious HTML template file via the component 'jfinal_cms/admin/filemanager/list'.
- CVE-2020-19664HIGHCVSS 8.8EG 8.82020-12-31
DrayTek Vigor2960 1.5.1 allows remote command execution via shell metacharacters in a toLogin2FA action to mainfunction.cgi.
- CVE-2020-1980HIGHCVSS 7.8EG 7.82020-03-11
A shell command injection vulnerability in the PAN-OS CLI allows a local authenticated user to escape the restricted shell and escalate privileges. This issue affects only PAN-OS 8.1 versions earlier than PAN-OS 8.1.13. This issue does not…
- CVE-2020-20951CRITICALCVSS 9.8EG 9.82021-05-18
In Pluck-4.7.10-dev2 admin background, a remote command execution vulnerability exists when uploading files.
- CVE-2020-21785HIGHCVSS 8.8EG 8.82021-06-24
In IBOS 4.5.4 Open, the database backup has Command Injection Vulnerability.
- CVE-2020-21935CRITICALCVSS 9.8EG 9.82021-07-21
A command injection vulnerability in HNAP1/GetNetworkTomographySettings of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to execute arbitrary code.
- CVE-2020-21937CRITICALCVSS 9.8EG 9.82021-07-21
An command injection vulnerability in HNAP1/SetWLanApcliSettings of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to execute arbitrary system commands.
- CVE-2020-21996HIGHCVSS 7.5EG 7.52021-04-28
AVE DOMINAplus <=1.10.x suffers from an unauthenticated reboot command execution. Attackers can exploit this issue to cause a denial of service scenario.
- CVE-2020-22201HIGHCVSS 8.8EG 8.82021-06-16
phpCMS 2008 sp4 allowas remote malicious users to execute arbitrary php commands via the pagesize parameter to yp/product.php.
- CVE-2020-22570HIGHCVSS 7.5EG 7.52023-08-22
Memcached 1.6.0 before 1.6.3 allows remote attackers to cause a denial of service (daemon crash) via a crafted meta command.
- CVE-2020-22662HIGHCVSS 7.5EG 7.52023-01-20
In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10.5.1.0.199, SmartCell Gateway 200 (SCG200) before 3.6.2.0.795, SmartZone 100 (SZ-100) befo…
- CVE-2020-22724CRITICALCVSS 9.8EG 9.82021-10-14
A remote command execution vulnerability exists in add_server_service of PPTP_SERVER in Mercury Router MER1200 v1.0.1 and Mercury Router MER1200G v1.0.1.
- CVE-2020-23151CRITICALCVSS 9.8EG 9.82021-08-09
rConfig 3.9.5 allows command injection by sending a crafted GET request to lib/ajaxHandlers/ajaxArchiveFiles.php since the path parameter is passed directly to the exec function without being escaped.
- CVE-2020-23219HIGHCVSS 8.8EG 8.82021-07-01
Monstra CMS 3.0.4 allows attackers to execute arbitrary code via a crafted payload entered into the "Snippet content" field under the "Edit Snippet" module.
- CVE-2020-23583CRITICALCVSS 9.8EG 9.82022-11-23
OPTILINK OP-XT71000N V2.2 is vulnerable to Remote Code Execution. The issue occurs when the attacker sends an arbitrary code on "/diag_ping_admin.asp" to "PingTest" interface that leads to COMMAND EXECUTION. An attacker can successfully tr…
- CVE-2020-23584CRITICALCVSS 9.8EG 9.82022-11-23
Unauthenticated remote code execution in OPTILINK OP-XT71000N, Hardware Version: V2.2 occurs when the attacker passes arbitrary commands with IP-ADDRESS using " | " to execute commands on " /diag_tracert_admin.asp " in the "PingTest" param…
- CVE-2020-23639CRITICALCVSS 9.8EG 9.82020-11-02
A command injection vulnerability exists in Moxa Inc VPort 461 Series Firmware Version 3.4 or lower that could allow a remote attacker to execute arbitrary commands in Moxa's VPort 461 Series Industrial Video Servers.
- CVE-2020-23826HIGHCVSS 8.8EG 8.82021-01-26
The Yale WIPC-303W 2.21 through 2.31 camera is vulnerable to remote command execution (RCE) through command injection via the HTTP API. NOTE: This may be a duplicate of CVE-2020-10176
- CVE-2020-24561CRITICALCVSS 9.1EG 9.12020-09-15
A command injection vulnerability in Trend Micro ServerProtect for Linux 3.0 could allow an attacker to execute arbitrary code on an affected system. An attacker must first obtain admin/root privileges on the SPLX console to exploit this v…
- CVE-2020-24631HIGHCVSS 7.2EG 7.22020-10-26
A remote execution of arbitrary commands vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2.
- CVE-2020-24632HIGHCVSS 7.2EG 7.22020-10-26
A remote execution of arbitrary commandss vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2.
- CVE-2020-24634CRITICALCVSS 9.8EG 9.82020-12-11
An attacker is able to remotely inject arbitrary commands by sending especially crafted packets destined to the PAPI (Aruba Networks AP Management protocol) UDP port (8211) of access-pointsor controllers in Aruba 9000 Gateway; Aruba 7000 S…
- CVE-2020-24635HIGHCVSS 7.2EG 7.22021-03-29
A remote execution of arbitrary commands vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.5.x: 6.5.4.17 and below; Aruba Instant 8.3.x: 8.3.0.13 and below; Aruba Instant 8.5.x: 8…
- CVE-2020-24636CRITICALCVSS 9.8EG 9.82021-03-29
A remote execution of arbitrary commands vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.5.x: 6.5.4.17 and below; Aruba Instant 8.3.x: 8.3.0.13 and below; Aruba Instant 8.5.x: 8…
- CVE-2020-24899HIGHCVSS 8.8EG 8.82021-02-15
Nagios XI 5.7.2 is affected by a remote code execution (RCE) vulnerability. An authenticated user can inject additional commands into normal webapp query.
- CVE-2020-2490HIGHCVSS 7.2EG 7.22020-11-16
If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. QTS versions prior to 4.4.3.1421 on build 20200907.
- CVE-2020-2492HIGHCVSS 7.2EG 7.22020-11-16
If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. QTS versions prior to 4.4.3.1421 on build 20200907.
- CVE-2020-25067CRITICALCVSS 9.6EG 9.62020-09-01
NETGEAR R8300 devices before 1.0.2.134 are affected by command injection by an unauthenticated attacker.
- CVE-2020-2507CRITICALCVSS 9.8EG 9.82021-02-03
The vulnerability have been reported to affect earlier versions of QTS. If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. This issue affects: QNAP Systems Inc. Helpdesk versions prio…
- CVE-2020-25079CRITICALCVSS 8.8EG 9.0⚠ KEV2020-09-02
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. cgi-bin/ddns_enc.cgi allows authenticated command injection.
- CVE-2020-2508HIGHCVSS 7.2EG 7.22021-01-11
A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulnerability in th…
- CVE-2020-2509CRITICALCVSS 9.8EG 9.8⚠ KEV2021-04-17
A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. We have already fixed this vulnerability in the …
- CVE-2020-25217HIGHCVSS 7.2EG 7.22021-03-29
Grandstream GRP261x VoIP phone running firmware version 1.0.3.6 (Base) allows Command Injection as root in its administrative web interface.
- CVE-2020-25367CRITICALCVSS 9.8EG 9.82021-11-04
A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to execute arbitrary web scripts via shell metacharacters in the Captcha field to Login.
- CVE-2020-25368CRITICALCVSS 9.8EG 9.82021-11-04
A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B05. An attacker is able to execute arbitrary web scripts via shell metacharacters in the PrivateLogin field to Login.
- CVE-2020-25483CRITICALCVSS 9.8EG 9.82020-10-23
An arbitrary command execution vulnerability exists in the fopen() function of file writes of UCMS v1.4.8, where an attacker can gain access to the server.
- CVE-2020-25499HIGHCVSS 8.8EG 8.82020-12-09
TOTOLINK A3002RU-V2.0.0 B20190814.1034 allows authenticated remote users to modify the system's 'Run Command'. An attacker can use this functionality to execute arbitrary OS commands on the router.
- CVE-2020-25506CRITICALCVSS 9.8EG 9.8⚠ KEV2021-02-02
D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead to remote arbitrary code execution.
- CVE-2020-25538HIGHCVSS 8.8EG 8.82020-11-13
An authenticated attacker can inject malicious code into "lang" parameter in /uno/central.php file in CMSuno 1.6.2 and run this PHP code in the web page. In this way, attacker can takeover the control of the server.
- CVE-2020-25557HIGHCVSS 8.8EG 8.82020-11-13
In CMSuno 1.6.2, an attacker can inject malicious PHP code as a "username" while changing his/her username & password. After that, when attacker logs in to the application, attacker's code will be run. As a result of this vulnerability, au…
- CVE-2020-25755HIGHCVSS 8.8EG 8.82021-06-16
An issue was discovered on Enphase Envoy R3.x and D4.x (and other current) devices. The upgrade_start function in /installer/upgrade_start allows remote authenticated users to execute arbitrary commands via the force parameter.
- CVE-2020-25847HIGHCVSS 8.8EG 8.82020-12-29
This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP have already fixed this vulnerability in the following versions of QTS and QuTS hero.
Map vulnerabilities like CWE-77 to your infrastructure
EchelonGraph correlates every CVE — across CWE-77 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →