CWE-77— Command Injection
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.— MITRE CWE catalog
4,102 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-77page 16 of 83
- CVE-2021-22867MEDIUMCVSS 6.5EG 6.52021-07-14
A path traversal vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled configuration options used by GitHub Pages were not sufficiently restricted and made it po…
- CVE-2021-22868MEDIUMCVSS 4.3EG 4.32021-09-24
A path traversal vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled configuration options used by GitHub Pages were not sufficiently restricted and made it po…
- CVE-2021-22899CRITICALCVSS 8.8EG 9.0⚠ KEV2021-05-27
A command injection vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to perform remote code execution via Windows Resource Profiles Feature
- CVE-2021-22935HIGHCVSS 7.2EG 7.22021-08-16
A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform command injection via an unsanitized web parameter.
- CVE-2021-22938HIGHCVSS 7.2EG 7.22021-08-16
A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform command injection via an unsanitized web parameter in the administrator web console.
- CVE-2021-23012HIGHCVSS 8.2EG 8.22021-05-10
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, 14.1.x before 14.1.4, and 13.1.x before 13.1.4, lack of input validation for items used in the system support functionality may allow users granted either "Resource Administr…
- CVE-2021-23247CRITICALCVSS 9.8EG 9.82022-04-01
A command injection vulerability found in quick game engine allows arbitrary remote code in quick app. Allows remote attacke0rs to gain arbitrary code execution in quick game engine
- CVE-2021-23330CRITICALCVSS 9.8EG 9.82021-02-01
All versions of package launchpad are vulnerable to Command Injection via stop.
- CVE-2021-23355CRITICALCVSS 5.6EG 9.82021-03-15
This affects all versions of package ps-kill. If (attacker-controlled) user input is given to the kill function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without in…
- CVE-2021-23356CRITICALCVSS 5.6EG 9.82021-03-15
This affects all versions of package kill-process-by-name. If (attacker-controlled) user input is given, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sani…
- CVE-2021-23359HIGHCVSS 7.5EG 7.52021-03-18
This affects all versions of package port-killer. If (attacker-controlled) user input is given, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.…
- CVE-2021-23374CRITICALCVSS 7.3EG 9.82021-04-18
This affects all versions of package ps-visitor. If attacker-controlled user input is given to the kill function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without i…
- CVE-2021-23375HIGHCVSS 7.3EG 7.32021-04-18
This affects all versions of package psnode. If attacker-controlled user input is given to the kill function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input…
- CVE-2021-23376CRITICALCVSS 9.8EG 9.82021-04-18
This affects all versions of package ffmpegdotjs. If attacker-controlled user input is given to the trimvideo function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function wit…
- CVE-2021-23377CRITICALCVSS 9.8EG 9.82021-04-18
This affects all versions of package onion-oled-js. If attacker-controlled user input is given to the scroll function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function with…
- CVE-2021-23378CRITICALCVSS 9.8EG 9.82021-04-18
This affects all versions of package picotts. If attacker-controlled user input is given to the say function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input…
- CVE-2021-23379HIGHCVSS 7.3EG 7.32021-04-18
This affects all versions of package portkiller. If (attacker-controlled) user input is given, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.
- CVE-2021-23380MEDIUMCVSS 5.6EG 5.62021-04-18
This affects all versions of package roar-pidusage. If attacker-controlled user input is given to the stat function of this package on certain operating systems, it is possible for an attacker to execute arbitrary commands. This is due to …
- CVE-2021-23381HIGHCVSS 7.3EG 7.32021-04-18
This affects all versions of package killing. If attacker-controlled user input is given, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.
- CVE-2021-23412CRITICALCVSS 8.1EG 9.82021-07-23
All versions of package gitlogplus are vulnerable to Command Injection via the main functionality, as options attributes are appended to the command to be executed without sanitization.
- CVE-2021-23727HIGHCVSS 7.5EG 7.52021-12-29
This affects the package celery before 5.2.2. It by default trusts the messages and metadata stored in backends (result stores). When reading task metadata from the backend, the data is deserialized. Given that an attacker can gain access …
- CVE-2021-23861MEDIUMCVSS 6.5EG 6.52021-12-08
By executing a special command, an user with administrative rights can get access to extended debug functionality on the VRM allowing an impact on integrity or availability of the installed software. This issue also affects installations o…
- CVE-2021-23862HIGHCVSS 7.2EG 7.22021-12-08
A crafted configuration packet sent by an authenticated administrative user can be used to execute arbitrary commands in system context. This issue also affects installations of the VRM, DIVAR IP, BVMS with VRM installed, the VIDEOJET deco…
- CVE-2021-24684HIGHCVSS 8.8EG 8.82021-10-18
The WordPress PDF Light Viewer Plugin WordPress plugin before 1.4.12 allows users with Author roles to execute arbitrary OS command on the server via OS Command Injection when invoking Ghostscript.
- CVE-2021-25146HIGHCVSS 7.2EG 7.22021-03-30
A remote execution of arbitrary commands vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.5.x: 6.5.4.17 and below; Aruba Instant 8.3.x: 8.3.0.13 and below; Aruba Instant 8.5.x: 8…
- CVE-2021-25150HIGHCVSS 8.8EG 8.82021-03-30
A remote execution of arbitrary commands vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.5.x: 6.5.4.17 and below; Aruba Instant 8.3.x: 8.3.0.13 and below; Aruba Instant 8.5.x: 8…
- CVE-2021-25162HIGHCVSS 8.1EG 8.12021-03-30
A remote execution of arbitrary commands vulnerability was discovered in some Aruba Instant Access Point (IAP) products in version(s): Aruba Instant 6.4.x: 6.4.4.8-4.2.4.17 and below; Aruba Instant 6.5.x: 6.5.4.18 and below; Aruba Instant …
- CVE-2021-25166HIGHCVSS 8.8EG 8.82021-04-29
A remote unauthorized access vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability.
- CVE-2021-25172HIGHCVSS 7.8EG 7.82021-02-08
The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a command injection vulnerability in libifc.so websetdefaultlangcfg function.
- CVE-2021-25812CRITICALCVSS 9.8EG 9.82021-04-29
Command injection vulnerability in China Mobile An Lianbao WF-1 1.01 via the 'ip' parameter with a POST request to /api/ZRQos/set_online_client.
- CVE-2021-26275CRITICALCVSS 9.8EG 9.82021-03-19
The eslint-fixer package through 0.1.5 for Node.js allows command injection via shell metacharacters to the fix function. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. The ozum/eslint-fixer …
- CVE-2021-26311HIGHCVSS 7.2EG 7.22021-05-13
In the AMD SEV/SEV-ES feature, memory can be rearranged in the guest address space that is not detected by the attestation mechanism which could be used by a malicious hypervisor to potentially lead to arbitrary code execution within the g…
- CVE-2021-26321MEDIUMCVSS 5.5EG 5.52021-11-16
Insufficient ID command validation in the SEV Firmware may allow a local authenticated attacker to perform a denial of service of the PSP.
- CVE-2021-26384HIGHCVSS 7.8EG 7.82022-07-14
A malformed SMI (System Management Interface) command may allow an attacker to establish a corrupted SMI Trigger Info data structure, potentially leading to out-of-bounds memory reads and writes when triggering an SMI resulting in a potent…
- CVE-2021-26422HIGHCVSS 7.2EG 7.22021-05-11
Skype for Business and Lync Remote Code Execution Vulnerability
- CVE-2021-26576HIGHCVSS 7.8EG 7.82021-02-08
The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a command injection vulnerability in libifc.so uploadsshkey function.
- CVE-2021-26679HIGHCVSS 7.2EG 7.22021-02-23
A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the ClearPass web-based management interface allows remote authen…
- CVE-2021-26680HIGHCVSS 7.2EG 7.22021-02-23
A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the ClearPass web-based management interface allows remote authen…
- CVE-2021-26681HIGHCVSS 7.2EG 7.22021-02-23
A remote authenticated command Injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the ClearPass CLI could allow remote authenticated users to run a…
- CVE-2021-26683HIGHCVSS 7.2EG 7.22021-02-23
A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the ClearPass web-based management interface allows remote authen…
- CVE-2021-26684HIGHCVSS 7.2EG 7.22021-02-23
A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.9.5, 6.8.8-HF1, 6.7.14-HF1. A vulnerability in the ClearPass web-based management interface allows remote authen…
- CVE-2021-26727CRITICALCVSS 10.0EG 10.02022-10-24
Multiple command injections and stack-based buffer overflows vulnerabilities in the SubNet_handler_func function of spx_restservice allow an attacker to execute arbitrary code with the same privileges as the server user (root). This issue …
- CVE-2021-26728CRITICALCVSS 10.0EG 10.02022-10-24
Command injection and stack-based buffer overflow vulnerabilities in the KillDupUsr_func function of spx_restservice allow an attacker to execute arbitrary code with the same privileges as the server user (root). This issue affects: Lanner…
- CVE-2021-26729CRITICALCVSS 10.0EG 10.02022-10-24
Command injection and multiple stack-based buffer overflows vulnerabilities in the Login_handler_func function of spx_restservice allow an attacker to execute arbitrary code with the same privileges as the server user (root). This issue af…
- CVE-2021-26731CRITICALCVSS 9.1EG 9.82022-10-24
Command injection and multiple stack-based buffer overflows vulnerabilities in the modifyUserb_func function of spx_restservice allow an authenticated attacker to execute arbitrary code with the same privileges as the server user (root). T…
- CVE-2021-26962HIGHCVSS 7.2EG 7.22021-03-05
A remote authenticated arbitrary command execution vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Vulnerabilities in the AirWave CLI could allow remote authenticated users to run arbitrary …
- CVE-2021-26970MEDIUMCVSS 6.3EG 6.32021-03-05
A remote authenticated arbitrary command execution vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Vulnerabilities in the AirWave web-base management interface could allow remote authenticat…
- CVE-2021-27185CRITICALCVSS 9.8EG 9.82021-02-10
The samba-client package before 4.0.0 for Node.js allows command injection because of the use of process.exec.
- CVE-2021-27221HIGHCVSS 8.1EG 8.12021-03-19
MikroTik RouterOS 6.47.9 allows remote authenticated ftp users to create or overwrite arbitrary .rsc files via the /export command. NOTE: the vendor's position is that this is intended behavior because of how user policies work
- CVE-2021-27447CRITICALCVSS 10.0EG 10.02021-12-21
Mesa Labs AmegaView version 3.0 is vulnerable to a command injection, which may allow an attacker to remotely execute arbitrary code.
Map vulnerabilities like CWE-77 to your infrastructure
EchelonGraph correlates every CVE — across CWE-77 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →