CWE-77— Command Injection
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.— MITRE CWE catalog
4,102 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-77page 20 of 83
- CVE-2021-38542MEDIUMCVSS 5.9EG 5.92022-01-04
Apache James prior to release 3.6.1 is vulnerable to a buffering attack relying on the use of the STARTTLS command. This can result in Man-in -the-middle command injection attacks, leading potentially to leakage of sensible information.
- CVE-2021-3855HIGHCVSS 8.8EG 8.82023-03-01
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Liman Central Management System Liman MYS (HTTP/Controllers, CronMail, Jobs modules) allows Command Injection. This issue affects Liman C…
- CVE-2021-38556HIGHCVSS 8.8EG 8.82021-08-24
includes/configure_client.php in RaspAP 2.6.6 allows attackers to execute commands via command injection.
- CVE-2021-38611CRITICALCVSS 9.8EG 9.82021-08-24
A command-injection vulnerability in the Image Upload function of the NASCENT RemKon Device Manager 4.0.0.0 allows attackers to execute arbitrary commands, as root, via shell metacharacters in the filename parameter to assets/index.php.
- CVE-2021-38991HIGHCVSS 7.8EG 7.82022-01-11
IBM AIX 7.0, 7.1, 7.2, and VIOS 3.1 could allow a non-privileged local user to exploit a vulnerability in the lscore command which could lead to code execution. IBM X-Force ID: 212953.
- CVE-2021-39217HIGHCVSS 7.2EG 7.22023-01-27
OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, Custom Layout enabled admin users to execute arbitrary commands via block methods. Versions 19.4.22 and 20.0.19 contain patches for this issue.
- CVE-2021-39363CRITICALCVSS 9.8EG 9.82022-02-24
Honeywell HDZP252DI 1.00.HW02.4 and HBW2PER1 1.000.HW01.3 devices allow a video replay attack after ARP cache poisoning has been achieved.
- CVE-2021-39383CRITICALCVSS 9.8EG 9.82022-03-20
DWSurvey v3.2.0 was discovered to contain a remote command execution (RCE) vulnerability via the component /sysuser/SysPropertyAction.java.
- CVE-2021-39509CRITICALCVSS 9.8EG 9.82021-08-24
An issue was discovered in D-Link DIR-816 DIR-816A2_FWv1.10CNB05_R1B011D88210 The HTTP request parameter is used in the handler function of /goform/form2userconfig.cgi route, which can construct the user name string to delete the user func…
- CVE-2021-39510CRITICALCVSS 9.8EG 9.82021-08-24
An issue was discovered in D-Link DIR816_A1_FW101CNB04 750m11ac wireless router, The HTTP request parameter is used in the handler function of /goform/form2userconfig.cgi route, which can construct the user name string to delete the user f…
- CVE-2021-40043HIGHCVSS 7.8EG 7.82022-02-25
The laser command injection vulnerability exists on AIS-BW80H-00 versions earlier than AIS-BW80H-00 9.0.3.4(H100SP13C00). The devices cannot effectively defend against external malicious interference. Attackers need the device to be visual…
- CVE-2021-40084CRITICALCVSS 9.8EG 9.82021-08-25
opensysusers through 0.6 does not safely use eval on files in sysusers.d that may contain shell metacharacters. For example, it allows command execution via a crafted GECOS field whereas systemd-sysusers (a program with the same specificat…
- CVE-2021-40113CRITICALCVSS 10.0EG 10.02021-11-04
Multiple vulnerabilities in the web-based management interface of the Cisco Catalyst Passive Optical Network (PON) Series Switches Optical Network Terminal (ONT) could allow an unauthenticated, remote attacker to perform the following acti…
- CVE-2021-40345HIGHCVSS 7.2EG 7.22021-10-26
An issue was discovered in Nagios XI 5.8.5. In the Manage Dashlets section of the Admin panel, an administrator can upload ZIP files. A command injection (within the name of the first file in the archive) allows an attacker to execute syst…
- CVE-2021-4045CRITICALCVSS 9.8EG 9.82022-03-10
TP-Link Tapo C200 IP camera, on its 1.1.15 firmware version and below, is affected by an unauthenticated RCE vulnerability, present in the uhttpd binary running by default as root. The exploitation of this vulnerability allows an attacker …
- CVE-2021-40553HIGHCVSS 8.8EG 8.82022-06-28
piwigo 11.5.0 is affected by a remote code execution (RCE) vulnerability in the LocalFiles Editor.
- CVE-2021-40986HIGHCVSS 7.2EG 7.22021-10-15
A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x prior to 6.10.2 - - ClearPass Policy Manager 6.9.x prior to 6.9.7-HF1 - - ClearPass Policy Mana…
- CVE-2021-40987HIGHCVSS 7.2EG 7.22021-10-15
A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x prior to 6.10.2 - - ClearPass Policy Manager 6.9.x prior to 6.9.7-HF1 - - ClearPass Policy Mana…
- CVE-2021-40994MEDIUMCVSS 6.3EG 6.32021-10-15
A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x prior to 6.10.2 - - ClearPass Policy Manager 6.9.x prior to 6.9.7-HF1 - - ClearPass Policy Mana…
- CVE-2021-40995MEDIUMCVSS 6.3EG 6.32021-10-15
A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x prior to 6.10.2 - - ClearPass Policy Manager 6.9.x prior to 6.9.7-HF1 - - ClearPass Policy Mana…
- CVE-2021-40998HIGHCVSS 7.2EG 7.22021-10-15
A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x prior to 6.10.2 - - ClearPass Policy Manager 6.9.x prior to 6.9.7-HF1 - - ClearPass Policy Mana…
- CVE-2021-40999HIGHCVSS 7.2EG 7.22021-10-15
A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPass Policy Manager 6.10.x prior to 6.10.2 - - ClearPass Policy Manager 6.9.x prior to 6.9.7-HF1 - - ClearPass Policy Mana…
- CVE-2021-41000HIGHCVSS 8.8EG 8.82022-03-02
Multiple authenticated remote code execution vulnerabilities were discovered in the AOS-CX command line interface in Aruba CX 6200F Switch Series, Aruba 6300 Switch Series, Aruba 6400 Switch Series, Aruba 8320 Switch Series, Aruba 8325 Swi…
- CVE-2021-41001HIGHCVSS 8.8EG 8.82022-03-02
An authenticated remote code execution vulnerability was discovered in the AOS-CX Network Analytics Engine (NAE) in Aruba CX 6200F Switch Series, Aruba 6300 Switch Series, Aruba 6400 Switch Series, Aruba 8320 Switch Series, Aruba 8325 Swit…
- CVE-2021-41016HIGHCVSS 7.8EG 8.82022-02-02
A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiExtender version 7.0.1 and below, 4.2.3 and below, 4.1.7 and below allows an authenticated attacker to execute privileged shell commands…
- CVE-2021-41116HIGHCVSS 8.2EG 8.22021-10-05
Composer is an open source dependency manager for the PHP language. In affected versions windows users running Composer to install untrusted dependencies are subject to command injection and should upgrade their composer version. Other OSs…
- CVE-2021-41143HIGHCVSS 7.2EG 7.22023-01-27
OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, Magento admin users with access to the customer media could execute code on the server. Versions 19.4.22 and 20.0.19 contain a patch for this issue.
- CVE-2021-41144HIGHCVSS 8.8EG 8.82023-01-27
OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, a layout block was able to bypass the block blacklist to execute remote code. Versions 19.4.22 and 20.0.19 contain a patch for this issue.
- CVE-2021-41146HIGHCVSS 8.8EG 8.82021-10-21
qutebrowser is an open source keyboard-focused browser with a minimal GUI. Starting with qutebrowser v1.7.0, the Windows installer for qutebrowser registers a `qutebrowserurl:` URL handler. With certain applications, opening a specially cr…
- CVE-2021-41231HIGHCVSS 7.2EG 7.22023-01-27
OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, an administrator with the permissions to upload files via DataFlow and to create products was able to execute arbitrary code via the convert profile. Versions 1…
- CVE-2021-41383HIGHCVSS 7.2EG 7.22021-09-17
setup.cgi on NETGEAR R6020 1.0.0.48 devices allows an admin to execute arbitrary shell commands via shell metacharacters in the ntp_server field.
- CVE-2021-41552HIGHCVSS 8.8EG 8.82022-02-15
CommScope SURFboard SBG6950AC2 9.1.103AA23 devices allow Command Injection.
- CVE-2021-41599HIGHCVSS 8.8EG 8.82022-02-18
A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. To exploit this vulnerability, an attacker would need permission to create and build a GitHub Pages…
- CVE-2021-41738HIGHCVSS 8.8EG 8.82022-06-11
ZeroShell 3.9.5 has a command injection vulnerability in /cgi-bin/kerbynet IP parameter, which may allow an authenticated attacker to execute system commands.
- CVE-2021-41744CRITICALCVSS 9.8EG 9.82021-10-22
All versions of yongyou PLM are affected by a command injection issue. UFIDA PLM (Product Life Cycle Management) is a strategic management method. It applies a series of enterprise application systems to support the entire process from con…
- CVE-2021-42094CRITICALCVSS 9.8EG 9.82021-10-07
An issue was discovered in Zammad before 4.1.1. Command Injection can occur via custom Packages.
- CVE-2021-42129CRITICALCVSS 8.8EG 9.02021-12-07
A command injection vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform arbitrary command execution.
- CVE-2021-42132HIGHCVSS 8.8EG 8.92021-12-07
A command Injection vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform arbitrary command execution.
- CVE-2021-42538HIGHCVSS 8.0EG 8.82021-10-22
The affected product is vulnerable to a parameter injection via passphrase, which enables the attacker to supply uncontrolled input.
- CVE-2021-42559HIGHCVSS 8.8EG 8.82022-01-12
An issue was discovered in CALDERA 2.8.1. It contains multiple startup "requirements" that execute commands when starting the server. Because these commands can be changed via the REST API, an authenticated user can insert arbitrary comman…
- CVE-2021-42638HIGHCVSS 8.1EG 8.12022-02-01
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below do not sanitize user input resulting in pre-auth remote code execution.
- CVE-2021-42740CRITICALCVSS 9.8EG 9.82021-10-21
The shell-quote package before 1.7.3 for Node.js allows command injection. An attacker can inject unescaped shell metacharacters through a regex designed to support Windows drive letters. If the output of this package is passed to a real s…
- CVE-2021-42875CRITICALCVSS 9.8EG 9.82022-06-02
TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in the function setDiagnosisCfg of the file lib/cste_modules/system.so to control the ipDoamin.
- CVE-2021-42884CRITICALCVSS 9.8EG 9.82022-06-03
TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function setDeviceName of the file global.so which can control thedeviceName to attack.
- CVE-2021-42885CRITICALCVSS 9.8EG 9.82022-06-03
TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function setDeviceMac of the file global.so which can control deviceName to attack.
- CVE-2021-42888CRITICALCVSS 9.8EG 9.82022-06-03
TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function setLanguageCfg of the file global.so which can control langType to attack.
- CVE-2021-42890CRITICALCVSS 9.8EG 9.82022-06-03
TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function NTPSyncWithHost of the file system.so which can control hostTime to attack.
- CVE-2021-42897CRITICALCVSS 9.8EG 9.82022-05-16
A remote command execution (RCE) vulnerability was found in FeMiner wms V1.0 in /wms/src/system/datarec.php. The $_POST[r_name] is directly passed into the $mysqlstr and is executed by exec.
- CVE-2021-4304CRITICALCVSS 6.3EG 9.82023-01-05
A vulnerability was found in eprintsug ulcc-core. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file cgi/toolbox/toolbox. The manipulation of the argument password leads to command inje…
- CVE-2021-43113CRITICALCVSS 9.8EG 9.82021-12-15
iTextPDF in iText 7 and up to (excluding 4.4.13.3) 7.1.17 allows command injection via a CompareTool filename that is mishandled on the gs (aka Ghostscript) command line in GhostscriptHelper.java.
Map vulnerabilities like CWE-77 to your infrastructure
EchelonGraph correlates every CVE — across CWE-77 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →