CWE-77— Command Injection
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.— MITRE CWE catalog
4,102 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-77page 32 of 83
- CVE-2022-42906HIGHCVSS 7.8EG 7.82022-10-13
powerline-gitstatus (aka Powerline Gitstatus) before 1.3.2 allows arbitrary code execution. git repositories can contain per-repository configuration that changes the behavior of git, including running arbitrary commands. When using powerl…
- CVE-2022-42999HIGHCVSS 7.5EG 7.52022-10-26
D-Link DIR-816 A2 1.10 B05 was discovered to contain multiple command injection vulnerabilities via the admuser and admpass parameters at /goform/setSysAdm.
- CVE-2022-43109CRITICALCVSS 9.8EG 9.82022-11-03
D-Link DIR-823G v1.0.2 was found to contain a command injection vulnerability in the function SetNetworkTomographySettings. This vulnerability allows attackers to execute arbitrary commands via a crafted packet.
- CVE-2022-43184CRITICALCVSS 9.8EG 9.82022-10-19
D-Link DIR878 1.30B08 Hotfix_04 was discovered to contain a command injection vulnerability via the component /bin/proc.cgi.
- CVE-2022-43367CRITICALCVSS 9.8EG 9.82022-10-27
IP-COM EW9 V15.11.0.14(9732) was discovered to contain a command injection vulnerability in the formSetDebugCfg function.
- CVE-2022-43536HIGHCVSS 7.2EG 8.82023-01-05
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploits could allow an attacker to execute arbitrary commands as …
- CVE-2022-43537HIGHCVSS 7.2EG 7.22023-01-05
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploits could allow an attacker to execute arbitrary commands as …
- CVE-2022-43538HIGHCVSS 7.2EG 7.22023-01-05
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploits could allow an attacker to execute arbitrary commands as …
- CVE-2022-43550CRITICALCVSS 9.8EG 9.82023-02-09
A command injection vulnerability exists in Jitsi before commit 8aa7be58522f4264078d54752aae5483bfd854b2 when launching browsers on Windows which could allow an attacker to insert an arbitrary URL which opens up the opportunity to remote e…
- CVE-2022-43623MEDIUMCVSS 6.8EG 6.82023-03-29
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechan…
- CVE-2022-4364CRITICALCVSS 7.3EG 9.82022-12-08
A vulnerability has been found in Teledyne FLIR AX8 up to 1.46.16. Affected by this issue is some unknown functionality of the file palette.php of the component Web Service Handler. The manipulation of the argument palette leads to command…
- CVE-2022-43781CRITICALCVSS 9.8EG 9.82022-11-17
There is a command injection vulnerability using environment variables in Bitbucket Server and Data Center. An attacker with permission to control their username can exploit this issue to execute arbitrary code on the system. This vulnerab…
- CVE-2022-44249CRITICALCVSS 9.8EG 9.82022-11-23
TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the UploadFirmwareFile function.
- CVE-2022-44250CRITICALCVSS 9.8EG 9.82022-11-23
TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the hostName parameter in the setOpModeCfg function.
- CVE-2022-44251CRITICALCVSS 9.8EG 9.82022-11-23
TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the ussd parameter in the setUssd function.
- CVE-2022-44252CRITICALCVSS 9.8EG 9.82022-11-23
TOTOLINK NR1800X V9.1.0u.6279_B20210910 contains a command injection via the FileName parameter in the setUploadSetting function.
- CVE-2022-44621CRITICALCVSS 9.8EG 9.82022-12-30
Diagnosis Controller miss parameter validation, so user may attacked by command injection via HTTP Request.
- CVE-2022-44832CRITICALCVSS 9.8EG 9.82022-12-14
D-Link DIR-3040 device with firmware 120B03 was discovered to contain a command injection vulnerability via the SetTriggerLEDBlink function.
- CVE-2022-44844CRITICALCVSS 9.8EG 9.82022-11-25
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the pass parameter in the setting/setOpenVpnCfg function.
- CVE-2022-44928CRITICALCVSS 9.8EG 9.82022-12-02
D-Link DVG-G5402SP GE_1.03 was discovered to contain a command injection vulnerability via the Maintenance function.
- CVE-2022-44930CRITICALCVSS 9.8EG 9.82022-12-02
D-Link DHP-W310AV 3.10EU was discovered to contain a command injection vulnerability via the System Checks function.
- CVE-2022-45005CRITICALCVSS 9.8EG 9.82022-12-13
IP-COM EW9 V15.11.0.14(9732) was discovered to contain a command injection vulnerability in the cmd_get_ping_output function.
- CVE-2022-45025CRITICALCVSS 9.8EG 9.82022-12-07
Markdown Preview Enhanced v0.6.5 and v0.19.6 for VSCode and Atom was discovered to contain a command injection vulnerability via the PDF file import function.
- CVE-2022-45043HIGHCVSS 8.8EG 8.82022-12-12
Tenda AX12 V22.03.01.16_cn is vulnerable to command injection via goform/fast_setting_internet_set.
- CVE-2022-45063CRITICALCVSS 9.8EG 9.82022-11-10
xterm before 375 allows code execution via font ops, e.g., because an OSC 50 response may have Ctrl-g and therefore lead to command execution within the vi line-editing mode of Zsh. NOTE: font ops are not allowed in the xterm default confi…
- CVE-2022-45094HIGHCVSS 8.4EG 8.82023-01-10
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 1). An authenticated remote attacker with access to the Web Based Management (443/tcp) of the affected product, could potentially inject commands into the dhc…
- CVE-2022-45095MEDIUMCVSS 6.7EG 6.72023-02-01
Dell PowerScale OneFS, 8.2.x-9.4.x, contain a command injection vulnerability. An authenticated user having access local shell and having the privilege to gather logs from the cluster could potentially exploit this vulnerability, leading …
- CVE-2022-45104HIGHCVSS 8.8EG 8.82023-02-11
Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 9.2.3.x contain a command execution vulnerability. A low privileged remote attacker could potentially exploit this vulnerability, leading to execute a…
- CVE-2022-45462CRITICALCVSS 9.8EG 9.82022-11-23
Alarm instance management has command injection when there is a specific command configured. It is only for logged-in users. We recommend you upgrade to version 2.0.6 or higher
- CVE-2022-45497CRITICALCVSS 9.8EG 9.82022-12-08
Tenda W6-S v1.0.0.4(510) was discovered to contain a command injection vulnerability in the tpi_get_ping_output function at /goform/exeCommand.
- CVE-2022-45506CRITICALCVSS 9.8EG 9.82022-12-08
Tenda W30E v1.0.1.25(633) was discovered to contain a command injection vulnerability via the fileNameMit parameter at /goform/delFileName.
- CVE-2022-45600HIGHCVSS 8.8EG 8.82023-02-22
Aztech WMB250AC Mesh Routers Firmware Version 016 2020 devices improperly manage sessions, which allows remote attackers to bypass authentication in opportunistic circumstances and execute arbitrary commands with administrator privileges b…
- CVE-2022-45699CRITICALCVSS 9.8EG 9.82023-02-10
Command injection in the administration interface in APSystems ECU-R version 5203 allows a remote unauthenticated attacker to execute arbitrary commands as root using the timezone parameter.
- CVE-2022-45701HIGHCVSS 8.8EG 8.82023-02-17
Arris TG2482A firmware through 9.1.103GEM9 allow Remote Code Execution (RCE) via the ping utility feature.
- CVE-2022-45717CRITICALCVSS 9.8EG 9.82022-12-23
IP-COM M50 V15.11.0.33(10768) was discovered to contain a command injection vulnerability via the usbPartitionName parameter in the formSetUSBPartitionUmount function. This vulnerability is exploited via a crafted GET request.
- CVE-2022-45768HIGHCVSS 8.8EG 8.82023-02-07
Command Injection vulnerability in Edimax Technology Co., Ltd. Wireless Router N300 Firmware BR428nS v3 allows attacker to execute arbitrary code via the formWlanMP function.
- CVE-2022-45796CRITICALCVSS 9.1EG 9.12022-12-16
Command injection vulnerability in nw_interface.html in SHARP multifunction printers (MFPs)'s Digital Full-color Multifunctional System 202 or earlier, 120 or earlier, 600 or earlier, 121 or earlier, 500 or earlier, 402 or earlier, 790 or …
- CVE-2022-45977HIGHCVSS 8.8EG 8.82022-12-12
Tenda AX12 V22.03.01.21_CN was found to have a command injection vulnerability via /goform/setMacFilterCfg function.
- CVE-2022-45996HIGHCVSS 7.2EG 7.22022-12-12
Tenda W20E V16.01.0.6(3392) is vulnerable to Command injection via cmd_get_ping_output.
- CVE-2022-4616CRITICALCVSS 7.2EG 9.12023-01-13
The webserver in Delta DX-3021 versions prior to 1.24 is vulnerable to command injection through the network diagnosis page. This vulnerability could allow a remote unauthenticated user to add files, delete files, and change file permis…
- CVE-2022-46303HIGHCVSS 8.0EG 8.02023-02-20
Command injection in SMS notifications in Tribe29 Checkmk <= 2.1.0p10, Checkmk <= 2.0.0p27, and Checkmk <= 1.6.0p29 allows an attacker with User Management permissions, as well as LDAP administrators in certain scenarios, to perform arbitr…
- CVE-2022-46333HIGHCVSS 7.2EG 7.22022-12-06
The admin user interface in Proofpoint Enterprise Protection (PPS/PoD) contains a command injection vulnerability that enables an admin to execute commands beyond their allowed scope. This affects all versions 8.19.0 and below.
- CVE-2022-46361MEDIUMCVSS 6.9EG 6.92023-05-30
An attacker having physical access to WDM can plug USB device to gain access and execute unwanted commands. A malicious user could enter a system command along with a backup configuration, which could result in the execution of unwanted co…
- CVE-2022-46404CRITICALCVSS 9.8EG 9.82022-12-13
A command injection vulnerability has been identified in Atos Unify OpenScape 4000 Assistant and Unify OpenScape 4000 Manager (8 before R2.22.18, 10 before 0.28.13, and 10 R1 before R1.34.4) that may allow an unauthenticated attacker to up…
- CVE-2022-46421CRITICALCVSS 9.8EG 9.82022-12-20
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache Airflow Hive Provider.This issue affects Apache Airflow Hive Provider: before 5.0.0.
- CVE-2022-46476CRITICALCVSS 9.8EG 9.82023-01-19
D-Link DIR-859 A1 1.05 was discovered to contain a command injection vulnerability via the service= variable in the soapcgi_main function.
- CVE-2022-46538CRITICALCVSS 9.8EG 9.82022-12-20
Tenda F1203 V2.0.1.6 was discovered to contain a command injection vulnerability via the mac parameter at /goform/WriteFacMac.
- CVE-2022-46631CRITICALCVSS 9.8EG 9.82022-12-15
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the wscDisabled parameter in the setting/setWiFiSignalCfg function.
- CVE-2022-46634CRITICALCVSS 9.8EG 9.82022-12-15
TOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the wscDisabled parameter in the setting/setWiFiWpsCfg function.
- CVE-2022-46640CRITICALCVSS 9.8EG 9.82023-04-18
Nanoleaf Desktop App before v1.3.1 was discovered to contain a command injection vulnerability which is exploited via a crafted HTTP request.
Map vulnerabilities like CWE-77 to your infrastructure
EchelonGraph correlates every CVE — across CWE-77 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →