CWE-77— Command Injection
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.— MITRE CWE catalog
4,102 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-77page 24 of 83
- CVE-2021-46230CRITICALCVSS 9.8EG 9.82022-02-04
D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function upgrade_filter. This vulnerability allows attackers to execute arbitrary commands via the path and time parameters.
- CVE-2021-46231CRITICALCVSS 9.8EG 9.82022-02-04
D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function urlrd_opt.asp. This vulnerability allows attackers to execute arbitrary commands via the url_en parameter.
- CVE-2021-46232CRITICALCVSS 9.8EG 9.82022-02-04
D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function version_upgrade.asp. This vulnerability allows attackers to execute arbitrary commands via the path parameter.
- CVE-2021-46233CRITICALCVSS 9.8EG 9.82022-02-04
D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function msp_info.htm. This vulnerability allows attackers to execute arbitrary commands via the cmd parameter.
- CVE-2021-46314CRITICALCVSS 9.8EG 9.82022-02-17
A Remote Command Execution (RCE) vulnerability exists in HNAP1/control/SetNetworkTomographySettings.php of D-Link Router DIR-846 DIR846A1_FW100A43.bin and DIR846enFW100A53DLA-Retail.bin because backticks can be used for command injection w…
- CVE-2021-46452CRITICALCVSS 9.8EG 9.82022-02-04
D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetNetworkTomographySettings. This vulnerability allows attackers to execute arbitrary commands via the tomography_ping_add…
- CVE-2021-46453CRITICALCVSS 9.8EG 9.82022-02-04
D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetStaticRouteSettings. This vulnerability allows attackers to execute arbitrary commands via the staticroute_list paramete…
- CVE-2021-46454CRITICALCVSS 9.8EG 9.82022-02-04
D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetWLanApcliSettings. This vulnerability allows attackers to execute arbitrary commands via the ApCliKeyStr parameter.
- CVE-2021-46455CRITICALCVSS 9.8EG 9.82022-02-04
D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetStationSettings. This vulnerability allows attackers to execute arbitrary commands via the station_access_enable paramet…
- CVE-2021-46456CRITICALCVSS 9.8EG 9.82022-02-04
D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetWLanACLSettings. This vulnerability allows attackers to execute arbitrary commands via the wl(0).(0)_maclist parameter.
- CVE-2021-46457CRITICALCVSS 9.8EG 9.82022-02-04
D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function ChgSambaUserSettings. This vulnerability allows attackers to execute arbitrary commands via the samba_name parameter.
- CVE-2021-46560CRITICALCVSS 9.8EG 9.82022-01-26
The firmware on Moxa TN-5900 devices through 3.1 allows command injection that could lead to device damage.
- CVE-2021-46850HIGHCVSS 7.2EG 7.22022-10-24
myVesta Control Panel before 0.9.8-26-43 and Vesta Control Panel before 0.9.8-26 are vulnerable to command injection. An authenticated and remote administrative user can execute arbitrary commands via the v_sftp_license parameter when send…
- CVE-2022-0902CRITICALCVSS 8.1EG 9.82022-07-21
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in flow computer and remote controller products of ABB ( RMC-…
- CVE-2022-0999HIGHCVSS 8.8EG 8.82022-04-11
An authenticated user may be able to misuse parameters to inject arbitrary operating system commands into mySCADA myPRO versions 8.25.0 and prior.
- CVE-2022-1030HIGHCVSS 8.8EG 8.82022-03-23
Okta Advanced Server Access Client for Linux and macOS prior to version 1.58.0 was found to be vulnerable to command injection via a specially crafted URL. An attacker, who has knowledge of a valid team name for the victim and also knows a…
- CVE-2022-1509CRITICALCVSS 9.9EG 9.92022-04-28
Command Injection Vulnerability in GitHub repository hestiacp/hestiacp prior to 1.5.12. An authenticated remote attacker with low privileges can execute arbitrary code under root context.
- CVE-2022-1884CRITICALCVSS 9.8EG 9.82024-11-15
A remote command execution vulnerability exists in gogs/gogs versions <=0.12.7 when deployed on a Windows server. The vulnerability arises due to improper validation of the `tree_path` parameter during file uploads. An attacker can set `tr…
- CVE-2022-20054HIGHCVSS 7.8EG 7.82022-03-10
In ims service, there is a possible AT command injection due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. P…
- CVE-2022-20345HIGHCVSS 8.8EG 8.82022-08-10
In l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not…
- CVE-2022-20665MEDIUMCVSS 6.0EG 6.72022-04-06
A vulnerability in the CLI of Cisco StarOS could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to insufficient input validation of CLI commands. An attacker could exploit this…
- CVE-2022-20799HIGHCVSS 4.7EG 7.22022-05-04
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV340 and RV345 Routers could allow an authenticated, remote attacker to inject and execute arbitrary commands on the underlying operating system of an …
- CVE-2022-20801HIGHCVSS 4.7EG 7.22022-05-04
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV340 and RV345 Routers could allow an authenticated, remote attacker to inject and execute arbitrary commands on the underlying operating system of an …
- CVE-2022-20851HIGHCVSS 5.5EG 7.22022-09-30
A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to perform an injection attack against an affected device. This vulnerability is due to insufficient input validation. An attacker…
- CVE-2022-20925HIGHCVSS 6.3EG 7.22022-11-15
A vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. The vulnerability is…
- CVE-2022-20926HIGHCVSS 6.3EG 8.82022-11-15
A vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. The vulnerability is…
- CVE-2022-20934MEDIUMCVSS 6.0EG 6.72022-11-15
A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software and Cisco FXOS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system as root. This vulnerabilit…
- CVE-2022-21129HIGHCVSS 7.4EG 7.42023-01-31
Versions of the package nemo-appium before 0.0.9 are vulnerable to Command Injection due to improper input sanitization in the 'module.exports.setup' function. **Note:** In order to exploit this vulnerability appium-running 0.1.3 has to…
- CVE-2022-21165CRITICALCVSS 9.8EG 9.82022-08-29
All versions of package font-converter are vulnerable to Arbitrary Command Injection due to missing sanitization of input that potentially flows into the child_process.exec() function.
- CVE-2022-21191HIGHCVSS 7.4EG 7.42023-01-13
Versions of the package global-modules-path before 3.0.0 are vulnerable to Command Injection due to missing input sanitization or other checks and sandboxes being employed to the getPath function.
- CVE-2022-2143CRITICALCVSS 9.8EG 9.82022-07-22
The affected product is vulnerable to two instances of command injection, which may allow an attacker to remotely execute arbitrary code.
- CVE-2022-21668HIGHCVSS 8.0EG 8.02022-01-10
pipenv is a Python development workflow tool. Starting with version 2018.10.9 and prior to version 2022.1.8, a flaw in pipenv's parsing of requirements files allows an attacker to insert a specially crafted string inside a comment anywhere…
- CVE-2022-21810HIGHCVSS 7.4EG 7.82023-01-26
All versions of the package smartctl are vulnerable to Command Injection via the info method due to improper input sanitization.
- CVE-2022-21941CRITICALCVSS 10.0EG 10.02022-08-31
All versions of iSTAR Ultra prior to version 6.8.9.CU01 are vulnerable to a command injection that could allow an unauthenticated user root access to the system.
- CVE-2022-22308HIGHCVSS 7.8EG 7.82022-02-21
IBM Planning Analytics 2.0 is vulnerable to a Remote File Include (RFI) attack. User input could be passed into file include commands and the web application could be tricked into including remote files with malicious code. IBM X-Force ID:…
- CVE-2022-2234CRITICALCVSS 9.9EG 9.92022-08-24
An authenticated mySCADA myPRO 8.26.0 user may be able to modify parameters to run commands directly in the operating system.
- CVE-2022-22454HIGHCVSS 7.8EG 7.82022-05-10
IBM InfoSphere Information Server 11.7 could allow a locally authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request.
- CVE-2022-2251HIGHCVSS 4.8EG 8.02023-01-17
Improper sanitization of branch names in GitLab Runner affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows a user who creates a branch with a specially crafted name and gets another user to trigger…
- CVE-2022-22688HIGHCVSS 8.8EG 8.82022-03-25
Improper neutralization of special elements used in a command ('Command Injection') vulnerability in File service functionality in Synology DiskStation Manager (DSM) before 6.2.4-25556-2 allows remote authenticated users to execute arbitra…
- CVE-2022-22744HIGHCVSS 8.8EG 8.82022-12-22
The constructed curl command from the "Copy as curl" feature in DevTools was not properly escaped for PowerShell. This could have lead to command injection if pasted into a Powershell prompt.<br>*This bug only affects Thunderbird for Windo…
- CVE-2022-22991HIGHCVSS 7.8EG 7.82022-01-13
A malicious user on the same LAN could use DNS spoofing followed by a command injection attack to trick a NAS device into loading through an unsecured HTTP call. Addressed this vulnerability by disabling checks for internet connectivity us…
- CVE-2022-22992CRITICALCVSS 7.8EG 9.82022-01-28
A command injection remote code execution vulnerability was discovered on Western Digital My Cloud Devices that could allow an attacker to execute arbitrary system commands on the device. The vulnerability was addressed by escaping individ…
- CVE-2022-2323HIGHCVSS 8.8EG 8.82022-07-29
Improper neutralization of special elements used in a user input allows an authenticated malicious user to perform remote code execution in the host system. This vulnerability impacts SonicWall Switch 1.1.1.0-2s and earlier versions
- CVE-2022-23332HIGHCVSS 8.8EG 8.82022-05-09
Command injection vulnerability in Manual Ping Form (Web UI) in Shenzhen Ejoin Information Technology Co., Ltd. ACOM508/ACOM516/ACOM532 609-915-041-100-020 allows a remote attacker to inject arbitrary code via the field.
- CVE-2022-23663CRITICALCVSS 9.1EG 9.12022-05-16
A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Man…
- CVE-2022-23672HIGHCVSS 7.2EG 7.22022-05-17
A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Man…
- CVE-2022-23673HIGHCVSS 7.2EG 7.22022-05-17
A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Man…
- CVE-2022-23881CRITICALCVSS 9.8EG 9.82022-03-23
ZZZCMS zzzphp v2.1.0 was discovered to contain a remote command execution (RCE) vulnerability via danger_key() at zzz_template.php.
- CVE-2022-23900CRITICALCVSS 9.8EG 9.82022-04-07
A command injection vulnerability in the API of the Wavlink WL-WN531P3 router, version M31G3.V5030.201204, allows an attacker to achieve unauthorized remote code execution via a malicious POST request through /cgi-bin/adm.cgi.
- CVE-2022-23935CRITICALCVSS 7.8EG 9.82022-01-25
lib/Image/ExifTool.pm in ExifTool before 12.38 mishandles a $file =~ /\|$/ check, leading to command injection.
Map vulnerabilities like CWE-77 to your infrastructure
EchelonGraph correlates every CVE — across CWE-77 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →