CWE-77— Command Injection
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.— MITRE CWE catalog
4,102 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-77page 18 of 83
- CVE-2021-3148CRITICALCVSS 9.8EG 9.82021-02-27
An issue was discovered in SaltStack Salt before 3002.5. Sending crafted web requests to the Salt API can result in salt.utils.thin.gen_thin() command injection because of different handling of single versus double quotes. This is related …
- CVE-2021-31573CRITICALCVSS 9.8EG 9.82023-02-06
In Config Manager, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege from a proximal attacker with no additional execution privileges needed. User interaction is not n…
- CVE-2021-31574CRITICALCVSS 9.8EG 9.82023-02-06
In Config Manager, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege from a proximal attacker with no additional execution privileges needed. User interaction is not n…
- CVE-2021-31575CRITICALCVSS 9.8EG 9.82023-02-06
In Config Manager, there is a possible command injection due to improper input validation. This could lead to remote escalation of privilege from a proximal attacker with no additional execution privileges needed. User interaction is not n…
- CVE-2021-31605HIGHCVSS 7.5EG 7.52021-09-27
furlongm openvpn-monitor through 1.1.3 allows %0a command injection via the OpenVPN management interface socket. This can shut down the server via signal%20SIGTERM.
- CVE-2021-31726CRITICALCVSS 9.8EG 9.82021-04-25
Akuvox C315 115.116.2613 allows remote command Injection via the cfgd_server service. The attack vector is sending a payload to port 189 (default root 0.0.0.0).
- CVE-2021-31838CRITICALCVSS 8.4EG 9.12021-06-29
A command injection vulnerability in MVISION EDR (MVEDR) prior to 3.4.0 allows an authenticated MVEDR administrator to trigger the EDR client to execute arbitrary commands through PowerShell using the EDR functionality 'execute reaction'.
- CVE-2021-31854HIGHCVSS 7.7EG 7.82022-01-19
A command Injection Vulnerability in McAfee Agent (MA) for Windows prior to 5.7.5 allows local users to inject arbitrary shell code into the file cleanup.exe. The malicious clean.exe file is placed into the relevant folder and executed by …
- CVE-2021-32499HIGHCVSS 7.5EG 7.52021-12-17
SICK SOPAS ET before version 4.8.0 allows attackers to manipulate the command line arguments to pass in any value to the Emulator executable.
- CVE-2021-32529CRITICALCVSS 9.8EG 9.82021-07-07
Command injection vulnerability in QSAN XEVO, SANOS allows remote unauthenticated attackers to execute arbitrary commands. Suggest contacting with QSAN and refer to recommendations in QSAN Document.
- CVE-2021-32660MEDIUMCVSS 6.8EG 6.82021-06-03
Backstage is an open platform for building developer portals, and techdocs-common contains common functionalities for Backstage's TechDocs. In versions of `@backstage/tehdocs-common` prior to 0.6.4, a malicious internal actor is able to up…
- CVE-2021-32661MEDIUMCVSS 6.8EG 6.82021-06-03
Backstage is an open platform for building developer portals. In versions of Backstage's Techdocs Plugin (`@backstage/plugin-techdocs`) prior to 0.9.5, a malicious internal actor can potentially upload documentation content with malicious …
- CVE-2021-32692CRITICALCVSS 9.6EG 9.62022-12-23
Activity Watch is a free and open-source automated time tracker. Versions prior to 0.11.0 allow an attacker to execute arbitrary commands on any macOS machine with ActivityWatch running. The attacker can exploit this vulnerability by havin…
- CVE-2021-32830LOWCVSS 3.9EG 3.92021-08-17
The @diez/generation npm package is a client for Diez. The locateFont method of @diez/generation has a command injection vulnerability. Clients of the @diez/generation library are unlikely to be aware of this, so they might unwittingly wri…
- CVE-2021-32849HIGHCVSS 8.8EG 8.82022-01-26
Gerapy is a distributed crawler management framework. Prior to version 0.9.9, an authenticated user could execute arbitrary commands. This issue is fixed in version 0.9.9. There are no known workarounds.
- CVE-2021-32933CRITICALCVSS 10.0EG 10.02022-04-01
An attacker could leverage an API to pass along a malicious file that could then manipulate the process creation command line in MDT AutoSave versions prior to v6.02.06 and run a command line argument. This could then be leveraged to run a…
- CVE-2021-3317HIGHCVSS 8.8EG 8.82021-01-26
KLog Server through 2.4.1 allows authenticated command injection. async.php calls shell_exec() on the original value of the source parameter.
- CVE-2021-33204CRITICALCVSS 9.8EG 9.82021-05-19
In the pg_partman (aka PG Partition Manager) extension before 4.5.1 for PostgreSQL, arbitrary code execution can be achieved via SECURITY DEFINER functions because an explicit search_path is not set.
- CVE-2021-33360CRITICALCVSS 9.8EG 9.82023-03-10
An issue found in Stoqey gnuplot v.0.0.3 and earlier allows attackers to execute arbitrary code via the src/index.ts, plotCallack, child_process, and/or filePath parameter(s).
- CVE-2021-33515MEDIUMCVSS 4.8EG 4.82021-06-28
The submission service in Dovecot before 2.3.15 allows STARTTLS command injection in lib-smtp. Sensitive information can be redirected to an attacker-controlled address.
- CVE-2021-33544CRITICALCVSS 7.2EG 9.02021-09-13
Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.
- CVE-2021-33548HIGHCVSS 7.2EG 8.12021-09-13
Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.
- CVE-2021-33550HIGHCVSS 7.2EG 8.12021-09-13
Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.
- CVE-2021-33551HIGHCVSS 7.2EG 7.82021-09-13
Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.
- CVE-2021-33552HIGHCVSS 7.2EG 7.82021-09-13
Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.
- CVE-2021-33553HIGHCVSS 7.2EG 7.82021-09-13
Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.
- CVE-2021-33554HIGHCVSS 7.2EG 8.12021-09-13
Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.
- CVE-2021-33963CRITICALCVSS 9.8EG 9.82022-01-15
China Mobile An Lianbao WF-1 v1.0.1 router web interface through /api/ZRMacClone/mac_addr_clone receives parameters by POST request, and the parameter macType has a command injection vulnerability. An attacker can use the vulnerability to …
- CVE-2021-33964HIGHCVSS 8.8EG 8.82022-01-18
China Mobile An Lianbao WF-1 V1.0.1 router provides a web interface /api/ZRRuleFilter/set_firewall_level which receives parameters by POST request, and the parameter firewall_level has a command injection vulnerability. An attacker can use…
- CVE-2021-33965HIGHCVSS 8.8EG 8.82022-01-18
China Mobile An Lianbao WF-1 V1.0.1 router provides a web interface /api/ZRMesh/set_ZRMesh which receives parameters by POST request, and the parameter mesh_enable and mesh_device have a command injection vulnerability. An attacker can use…
- CVE-2021-3401CRITICALCVSS 9.8EG 9.82021-02-04
Bitcoin Core before 0.19.0 might allow remote attackers to execute arbitrary code when another application unsafely passes the -platformpluginpath argument to the bitcoin-qt program, as demonstrated by an x-scheme-handler/bitcoin handler f…
- CVE-2021-34111CRITICALCVSS 9.8EG 9.82022-05-20
Thecus 4800Eco was discovered to contain a command injection vulnerability via the username parameter in /adm/setmain.php.
- CVE-2021-34348CRITICALCVSS 9.8EG 9.82021-09-27
A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability could allow remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following versi…
- CVE-2021-34349HIGHCVSS 7.2EG 7.22021-09-27
A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability could allow remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following versi…
- CVE-2021-34351CRITICALCVSS 9.8EG 9.82021-09-27
A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability could allow remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following versi…
- CVE-2021-34352HIGHCVSS 7.2EG 7.22021-10-01
A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability could allow remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following versi…
- CVE-2021-34362HIGHCVSS 8.7EG 8.72021-10-22
A command injection vulnerability has been reported to affect QNAP device running Media Streaming add-on. If exploited, this vulnerability allow remote attackers to run arbitrary commands. We have already fixed this vulnerability in the fo…
- CVE-2021-34592HIGHCVSS 8.8EG 8.82022-04-27
In Bender/ebee Charge Controllers in multiple versions are prone to Command injection via Web interface. An authenticated attacker could enter shell commands into some input fields.
- CVE-2021-34610HIGHCVSS 7.2EG 7.22021-07-08
A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this security vulnerabili…
- CVE-2021-34611HIGHCVSS 7.2EG 7.22021-07-08
A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this security vulnerabili…
- CVE-2021-34612MEDIUMCVSS 6.3EG 6.32021-07-08
A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this security vulnerabili…
- CVE-2021-34613MEDIUMCVSS 6.3EG 6.32021-07-08
A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this security vulnerabili…
- CVE-2021-34614MEDIUMCVSS 6.3EG 6.32021-07-08
A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this security vulnerabili…
- CVE-2021-34615MEDIUMCVSS 6.3EG 6.32021-07-08
A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this security vulnerabili…
- CVE-2021-34616MEDIUMCVSS 6.3EG 6.32021-07-08
A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this security vulnerabili…
- CVE-2021-34710HIGHCVSS 8.8EG 8.82021-10-06
Multiple vulnerabilities in the Cisco ATA 190 Series Analog Telephone Adapter Software could allow an attacker to perform a command injection attack resulting in remote code execution or cause a denial of service (DoS) condition on an affe…
- CVE-2021-34725MEDIUMCVSS 6.7EG 6.72021-09-23
A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands to be executed with root-level privileges on the underlying operating system. This vulnerability is due to…
- CVE-2021-34726MEDIUMCVSS 6.7EG 6.72021-09-23
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands to be executed with root-level privileges on the underlying operating system of an affected device. This vulnerab…
- CVE-2021-34729MEDIUMCVSS 6.7EG 6.72021-09-23
A vulnerability in the CLI of Cisco IOS XE SD-WAN Software and Cisco IOS XE Software could allow an authenticated, local attacker to execute arbitrary commands with elevated privileges on an affected device. This vulnerability is due to in…
- CVE-2021-34735HIGHCVSS 8.8EG 8.82021-10-06
Multiple vulnerabilities in the Cisco ATA 190 Series Analog Telephone Adapter Software could allow an attacker to perform a command injection attack resulting in remote code execution or cause a denial of service (DoS) condition on an affe…
Map vulnerabilities like CWE-77 to your infrastructure
EchelonGraph correlates every CVE — across CWE-77 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →