CWE-77— Command Injection
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.— MITRE CWE catalog
4,102 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-77page 14 of 83
- CVE-2020-36650MEDIUMCVSS 5.5EG 5.52023-01-11
A vulnerability, which was classified as critical, was found in IonicaBizau node-gry up to 5.x. This affects an unknown part. The manipulation leads to command injection. Upgrading to version 6.0.0 is able to address this issue. The patch …
- CVE-2020-3760CRITICALCVSS 9.8EG 9.82020-02-13
Adobe Digital Editions versions 4.5.10 and below have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.
- CVE-2020-3924MEDIUMCVSS 6.4EG 6.42020-02-27
DVR firmware in TAT-76 and TAT-77 series of products, provided by TONNET do not properly verify patch files. Attackers can inject a specific command into a patch file and gain access to the system.
- CVE-2020-4006CRITICALCVSS 9.1EG 9.1⚠ KEV2020-11-23
VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability.
- CVE-2020-4059HIGHCVSS 7.3EG 7.32020-06-18
In mversion before 2.0.0, there is a command injection vulnerability. This issue may lead to remote code execution if a client of the library calls the vulnerable method with untrusted input. This vulnerability is patched by version 2.0.0.…
- CVE-2020-4432HIGHCVSS 7.5EG 7.52020-06-10
Certain IBM Aspera applications are vulnerable to command injection after valid authentication, which could allow an attacker with intimate knowledge of the system to execute commands in a SOAP API. IBM X-Force ID: 180810.
- CVE-2020-4636HIGHCVSS 7.2EG 7.22020-10-16
IBM Resilient OnPrem 38.2 could allow a privileged user to inject malicious commands through Python3 scripting. IBM X-Force ID: 185503.
- CVE-2020-4688HIGHCVSS 7.8EG 7.82021-01-20
IBM Security Guardium 10.6 and 11.2 could allow a local attacker to execute arbitrary commands on the system as an unprivileged user, caused by command injection vulnerability. IBM X-Force ID: 186700.
- CVE-2020-4979CRITICALCVSS 9.8EG 9.82021-05-05
IBM QRadar SIEM 7.3 and 7.4 is vulnerable to insecure inter-deployment communication. An attacker that is able to comprimise or spoof traffic between hosts may be able to execute arbitrary commands. IBM X-Force D: 192538.
- CVE-2020-4983HIGHCVSS 7.8EG 7.82021-01-20
IBM Spectrum LSF 10.1 and IBM Spectrum LSF Suite 10.2 could allow a user on the local network who has privileges to submit LSF jobs to execute arbitrary commands. IBM X-Force ID: 192586.
- CVE-2020-5299MEDIUMCVSS 4.0EG 4.02020-06-03
In OctoberCMS (october/october composer package) versions from 1.0.319 and before 1.0.466, any users with the ability to modify any data that could eventually be exported as a CSV file from the `ImportExportController` could potentially in…
- CVE-2020-5601HIGHCVSS 8.8EG 8.82020-06-30
Chrome Extension for e-Tax Reception System Ver1.0.0.0 allows remote attackers to execute an arbitrary command via unspecified vectors.
- CVE-2020-5792HIGHCVSS 7.2EG 8.22020-10-20
Improper neutralization of argument delimiters in a command in Nagios XI 5.7.3 allows a remote, authenticated admin user to write to arbitrary files and ultimately execute code with the privileges of the apache user.
- CVE-2020-6811HIGHCVSS 8.8EG 8.82020-03-25
The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If a user used the 'Copy as Curl' feature and pasted the command into a terminal, it could ha…
- CVE-2020-7034HIGHCVSS 7.2EG 8.82021-04-23
A command injection vulnerability in Avaya Session Border Controller for Enterprise could allow an authenticated, remote attacker to send specially crafted messages and execute arbitrary commands with the affected system privileges. Affect…
- CVE-2020-7128CRITICALCVSS 9.8EG 9.82020-11-04
A remote unauthenticated arbitrary code execution vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2.
- CVE-2020-7129HIGHCVSS 7.2EG 7.22020-11-04
A remote execution of arbitrary commands vulnerability was discovered in Aruba Airwave Software version(s): Prior to 1.3.2.
- CVE-2020-7373CRITICALCVSS 9.8EG 9.82020-10-30
vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. NOTE: this issue exists because of an incomplete fix for CVE-2019-16759. ALSO NOTE: CVE-2…
- CVE-2020-7384HIGHCVSS 7.0EG 7.02020-10-29
Rapid7's Metasploit msfvenom framework handles APK files in a way that allows for a malicious user to craft and publish a file that would execute arbitrary commands on a victim's machine.
- CVE-2020-7697CRITICALCVSS 9.8EG 9.82020-07-29
This affects all versions of package mock2easy. a malicious user could inject commands through the _data variable: Affected Area require('../server/getJsonByCurl')(mock2easy, function (error, stdout) { if (error) { return res.json(500, err…
- CVE-2020-7784CRITICALCVSS 9.8EG 9.82021-01-08
This affects all versions of package ts-process-promises. The injection point is located in line 45 in main entry of package in lib/process-promises.js. The vulnerability is demonstrated with the following PoC:
- CVE-2020-7794CRITICALCVSS 9.8EG 9.82021-01-08
This affects all versions of package buns. The injection point is located in line 678 in index file lib/index.js in the exported function install(requestedModule).
- CVE-2020-7795HIGHCVSS 7.3EG 7.32022-08-02
The package get-npm-package-version before 1.0.7 are vulnerable to Command Injection via main function in index.js.
- CVE-2020-7848HIGHCVSS 8.0EG 8.02021-02-17
The EFM ipTIME C200 IP Camera is affected by a Command Injection vulnerability in /login.cgi?logout=1 script. To exploit this vulnerability, an attacker can send a GET request that executes arbitrary OS commands via cookie value.
- CVE-2020-8101MEDIUMCVSS 6.9EG 6.92021-02-02
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in HTTP interface of ADT LifeShield DIY HD Video Doorbell allows an attacker on the same network to execute commands on the device. This issu…
- CVE-2020-8171CRITICALCVSS 9.8EG 9.82020-05-26
We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilities found on AirMax AirOS v6.2.0 and prior TI, XW and XM boards, according to the description below:There are certain end…
- CVE-2020-8186CRITICALCVSS 9.8EG 9.82020-07-10
A command injection vulnerability in the `devcert` module may lead to remote code execution when users of the module pass untrusted input to the `certificateFor` function.
- CVE-2020-8188HIGHCVSS 8.8EG 8.82020-07-02
We have recently released new version of UniFi Protect firmware v1.13.3 and v1.14.10 for Unifi Cloud Key Gen2 Plus and UniFi Dream Machine Pro/UNVR respectively that fixes vulnerabilities found on Protect firmware v1.13.2, v1.14.9 and prio…
- CVE-2020-8211CRITICALCVSS 9.8EG 9.82020-08-17
Improper input validation in Citrix XenMobile Server 10.12 before RP3, Citrix XenMobile Server 10.11 before RP6, Citrix XenMobile Server 10.10 RP6 and Citrix XenMobile Server before 10.9 RP5 allows SQL Injection.
- CVE-2020-8233HIGHCVSS 8.8EG 8.82020-08-17
A command injection vulnerability exists in EdgeSwitch firmware <v1.9.0 that allowed an authenticated read-only user to execute arbitrary shell commands over the HTTP interface, allowing them to escalate privileges.
- CVE-2020-8298CRITICALCVSS 9.8EG 9.82021-03-04
fs-path node module before 0.0.25 is vulnerable to command injection by way of user-supplied inputs via the `copy`, `copySync`, `remove`, and `removeSync` methods.
- CVE-2020-8466CRITICALCVSS 9.8EG 9.82020-12-17
A command injection vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2, with the improved password hashing method enabled, could allow an unauthenticated attacker to execute certain commands by providing a manipu…
- CVE-2020-9115HIGHCVSS 7.2EG 7.22020-12-01
ManageOne versions 6.5.1.1.B010, 6.5.1.1.B020, 6.5.1.1.B030, 6.5.1.1.B040, ,6.5.1.1.B050, 8.0.0 and 8.0.1 have a command injection vulnerability. An attacker with high privileges may exploit this vulnerability through some operations on th…
- CVE-2020-9116HIGHCVSS 7.2EG 7.22020-12-01
Huawei FusionCompute versions 6.5.1 and 8.0.0 have a command injection vulnerability. An authenticated, remote attacker can craft specific request to exploit this vulnerability. Due to insufficient verification, this could be exploited to …
- CVE-2020-9127MEDIUMCVSS 6.7EG 6.72020-11-13
Some Huawei products have a command injection vulnerability. Due to insufficient input validation, an attacker with high privilege may inject some malicious codes in some files of the affected products. Successful exploit may cause command…
- CVE-2020-9199MEDIUMCVSS 6.8EG 6.82020-09-03
B2368-22 V100R001C00;B2368-57 V100R001C00;B2368-66 V100R001C00 have a command injection vulnerability. An attacker with high privileges may exploit this vulnerability through some operations on the LAN. Due to insufficient input validation…
- CVE-2020-9242HIGHCVSS 8.8EG 8.82020-08-17
FusionCompute 8.0.0 have a command injection vulnerability. The software does not sufficiently validate certain parameters post from user, successful exploit could allow an authenticated attacker to launch a command injection attack.
- CVE-2020-9576CRITICALCVSS 9.8EG 9.82020-06-26
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.
- CVE-2020-9578CRITICALCVSS 9.8EG 9.82020-06-26
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.
- CVE-2020-9582CRITICALCVSS 9.8EG 9.82020-06-26
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.
- CVE-2020-9583CRITICALCVSS 9.8EG 9.82020-06-26
Magento versions 2.3.4 and earlier, 2.2.11 and earlier (see note), 1.14.4.4 and earlier, and 1.9.4.4 and earlier have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.
- CVE-2020-9688HIGHCVSS 7.8EG 7.82020-07-17
Adobe Download Manager version 2.0.0.518 have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.
- CVE-2020-9862HIGHCVSS 7.8EG 7.82020-10-16
A command injection issue existed in Web Inspector. This issue was addressed with improved escaping. This issue is fixed in iOS 13.6 and iPadOS 13.6, tvOS 13.4.8, watchOS 6.2.8, Safari 13.1.2, iTunes 12.10.8 for Windows, iCloud for Windows…
- CVE-2021-0252HIGHCVSS 7.8EG 7.82021-04-22
NFX Series devices using Juniper Networks Junos OS are susceptible to a local code execution vulnerability thereby allowing an attacker to elevate their privileges via the Junos Device Management Daemon (JDMD) process. This issue affects J…
- CVE-2021-0253HIGHCVSS 7.8EG 7.82021-04-22
NFX Series devices using Juniper Networks Junos OS are susceptible to a local command execution vulnerability thereby allowing an attacker to elevate their privileges via the Junos Device Management Daemon (JDMD) process. This issue affect…
- CVE-2021-0356MEDIUMCVSS 6.7EG 6.72021-02-03
In netdiag, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android…
- CVE-2021-0358MEDIUMCVSS 6.7EG 6.72021-02-03
In netdiag, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android…
- CVE-2021-0363MEDIUMCVSS 6.7EG 6.72021-02-03
In mobile_log_d, there is a possible command injection due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Andro…
- CVE-2021-0364MEDIUMCVSS 6.7EG 6.72021-02-03
In mobile_log_d, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: An…
- CVE-2021-1142CRITICALCVSS 9.8EG 9.82021-01-20
Multiple vulnerabilities in the web UI of Cisco Smart Software Manager Satellite could allow an unauthenticated, remote attacker to execute arbitrary commands on the underlying operating system. For more information about these vulnerabili…
Map vulnerabilities like CWE-77 to your infrastructure
EchelonGraph correlates every CVE — across CWE-77 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →