CWE-77— Command Injection
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.— MITRE CWE catalog
4,102 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-77page 34 of 83
- CVE-2023-1458CRITICALCVSS 7.2EG 9.82023-03-25
A vulnerability has been found in Ubiquiti EdgeRouter X 2.0.9-hotfix.6 and classified as critical. Affected by this vulnerability is an unknown functionality of the component OSPF Handler. The manipulation of the argument area leads to com…
- CVE-2023-1671CRITICALCVSS 9.8EG 9.8⚠ KEV2023-04-04
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution of arbitrary code.
- CVE-2023-1685HIGHCVSS 6.3EG 7.22023-03-29
A vulnerability was found in HadSky up to 7.11.8. It has been declared as critical. This vulnerability affects unknown code of the file /install/index.php of the component Installation Interface. The manipulation leads to command injection…
- CVE-2023-1708CRITICALCVSS 5.7EG 9.82023-04-05
An issue was identified in GitLab CE/EE affecting all versions from 1.0 prior to 15.8.5, 15.9 prior to 15.9.4, and 15.10 prior to 15.10.1 where non-printable characters gets copied from clipboard, allowing unexpected commands to be execute…
- CVE-2023-1877CRITICALCVSS 9.8EG 9.82023-04-05
Command Injection in GitHub repository microweber/microweber prior to 1.3.3.
- CVE-2023-20013MEDIUMCVSS 6.5EG 6.52023-08-16
Multiple vulnerabilities in Cisco Intersight Private Virtual Appliance could allow an authenticated, remote attacker to execute arbitrary commands using root-level privileges. The attacker would need to have Administrator privileges on the…
- CVE-2023-20017MEDIUMCVSS 6.5EG 6.52023-08-16
Multiple vulnerabilities in Cisco Intersight Private Virtual Appliance could allow an authenticated, remote attacker to execute arbitrary commands using root-level privileges. The attacker would need to have Administrator privileges on the…
- CVE-2023-20026HIGHCVSS 6.5EG 7.22023-01-20
A vulnerability in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320 and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary commands on an affected device. This v…
- CVE-2023-20045HIGHCVSS 4.9EG 7.22023-01-20
A vulnerability in the web-based management interface of Cisco Small Business RV160 and RV260 Series VPN Routers could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected …
- CVE-2023-20075MEDIUMCVSS 6.0EG 6.72023-03-01
Vulnerability in the CLI of Cisco Secure Email Gateway could allow an authenticated, remote attacker to execute arbitrary commands. These vulnerability is due to improper input validation in the CLI. An attacker could exploit this vulne…
- CVE-2023-20097MEDIUMCVSS 4.6EG 6.72023-03-23
A vulnerability in Cisco access points (AP) software could allow an authenticated, local attacker to inject arbitrary commands and execute them with root privileges. This vulnerability is due to improper input validation of commands that a…
- CVE-2023-20118CRITICALCVSS 6.5EG 9.0⚠ KEV2023-04-13
A vulnerability in the web-based management interface of Cisco Small Business Routers RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary commands on an affected device. …
- CVE-2023-20121MEDIUMCVSS 6.0EG 6.72023-04-05
Multiple vulnerabilities in the restricted shell of Cisco Evolved Programmable Network Manager (EPNM), Cisco Identity Services Engine (ISE), and Cisco Prime Infrastructure could allow an authenticated, local attacker to escape the restrict…
- CVE-2023-20122HIGHCVSS 6.0EG 7.82023-04-05
Multiple vulnerabilities in the restricted shell of Cisco Evolved Programmable Network Manager (EPNM), Cisco Identity Services Engine (ISE), and Cisco Prime Infrastructure could allow an authenticated, local attacker to escape the restrict…
- CVE-2023-20124HIGHCVSS 6.5EG 7.22023-04-05
A vulnerability in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary commands on an affected device. This vul…
- CVE-2023-20152MEDIUMCVSS 6.0EG 6.72023-04-05
Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To …
- CVE-2023-20153MEDIUMCVSS 6.0EG 6.72023-04-05
Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To …
- CVE-2023-20170MEDIUMCVSS 6.0EG 6.02023-11-01
A vulnerability in a specific Cisco ISE CLI command could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, an atta…
- CVE-2023-20209MEDIUMCVSS 6.5EG 6.92023-08-16
A vulnerability in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with read-write privileges on the application to perform…
- CVE-2023-20219HIGHCVSS 7.2EG 7.22023-11-01
Multiple vulnerabilities in the web management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. The attacker would…
- CVE-2023-20220HIGHCVSS 7.2EG 7.22023-11-01
Multiple vulnerabilities in the web-based management interface of Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. To exploit t…
- CVE-2023-20237MEDIUMCVSS 4.3EG 4.32023-08-16
A vulnerability in Cisco Intersight Virtual Appliance could allow an unauthenticated, adjacent attacker to access internal HTTP services that are otherwise inaccessible. This vulnerability is due to insufficient restrictions on internal…
- CVE-2023-20865HIGHCVSS 7.2EG 7.22023-04-20
VMware Aria Operations for Logs contains a command injection vulnerability. A malicious actor with administrative privileges in VMware Aria Operations for Logs can execute arbitrary commands as root.
- CVE-2023-20887CRITICALCVSS 9.8EG 9.8⚠ KEV2023-06-07
Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in remote code execution.
- CVE-2023-20889HIGHCVSS 7.5EG 8.82023-06-07
Aria Operations for Networks contains an information disclosure vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in information disclos…
- CVE-2023-21413CRITICALCVSS 9.1EG 9.12023-10-16
GoSecure on behalf of Genetec Inc. has found a flaw that allows for a remote code execution during the installation of ACAP applications on the Axis device. The application handling service in AXIS OS was vulnerable to command injection al…
- CVE-2023-21778HIGHCVSS 8.0EG 8.32023-02-14
Microsoft Dynamics Unified Service Desk Remote Code Execution Vulnerability
- CVE-2023-21805HIGHCVSS 7.8EG 7.82023-02-14
Windows MSHTML Platform Remote Code Execution Vulnerability
- CVE-2023-22306HIGHCVSS 7.2EG 7.22023-07-06
An OS command injection vulnerability exists in the libzebra.so bridge_group functionality of Milesight UR32L v32.3.0.5. A specially crafted network packet can lead to command execution. An attacker can send a sequence of requests to trigg…
- CVE-2023-22371HIGHCVSS 8.1EG 8.12023-07-06
An os command injection vulnerability exists in the liburvpn.so create_private_key functionality of Milesight VPN v2.0.2. A specially-crafted network request can lead to command execution. An attacker can send a malicious packet to trigger…
- CVE-2023-22496HIGHCVSS 8.1EG 8.22023-01-14
Netdata is an open source option for real-time infrastructure monitoring and troubleshooting. An attacker with the ability to establish a streaming connection can execute arbitrary commands on the targeted Netdata agent. When an alert is t…
- CVE-2023-22657HIGHCVSS 7.0EG 7.82023-02-01
On F5OS-A beginning in version 1.2.0 to before 1.3.0 and F5OS-C beginning in version 1.3.0 to before 1.5.0, processing F5OS tenant file names may allow for command injection. Note: Software versions which have reached End of Technical Sup…
- CVE-2023-22659HIGHCVSS 7.2EG 7.22023-07-06
An os command injection vulnerability exists in the libzebra.so change_hostname functionality of Milesight UR32L v32.3.0.5. A specially-crafted network packets can lead to command execution. An attacker can send a sequence of requests to t…
- CVE-2023-22671CRITICALCVSS 9.8EG 9.82023-01-06
Ghidra/RuntimeScripts/Linux/support/launch.sh in NSA Ghidra through 10.2.2 passes user-provided input into eval, leading to command injection when calling analyzeHeadless with untrusted input.
- CVE-2023-22747CRITICALCVSS 9.8EG 9.82023-03-01
There are multiple command injection vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks access point management protocol) UDP port (8211). Succ…
- CVE-2023-22748CRITICALCVSS 9.8EG 9.82023-03-01
There are multiple command injection vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks access point management protocol) UDP port (8211). Suc…
- CVE-2023-22749CRITICALCVSS 9.8EG 9.82023-03-01
There are multiple command injection vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks access point management protocol) UDP port (8211). Suc…
- CVE-2023-22750CRITICALCVSS 9.8EG 9.82023-03-01
There are multiple command injection vulnerabilities that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba Networks access point management protocol) UDP port (8211). Suc…
- CVE-2023-22758HIGHCVSS 7.2EG 7.22023-03-01
Authenticated remote command injection vulnerabilities exist in the ArubaOS web-based management interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the un…
- CVE-2023-22759HIGHCVSS 7.2EG 7.22023-03-01
Authenticated remote command injection vulnerabilities exist in the ArubaOS web-based management interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the un…
- CVE-2023-22760HIGHCVSS 7.2EG 7.22023-03-01
Authenticated remote command injection vulnerabilities exist in the ArubaOS web-based management interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the un…
- CVE-2023-22761HIGHCVSS 7.2EG 7.22023-03-01
Authenticated remote command injection vulnerabilities exist in the ArubaOS web-based management interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the un…
- CVE-2023-22762HIGHCVSS 7.2EG 7.22023-03-01
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operat…
- CVE-2023-22763HIGHCVSS 7.2EG 7.22023-03-01
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operat…
- CVE-2023-22764HIGHCVSS 7.2EG 7.22023-03-01
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operat…
- CVE-2023-22765HIGHCVSS 7.2EG 7.22023-03-01
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operat…
- CVE-2023-22766HIGHCVSS 7.2EG 7.22023-03-01
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operat…
- CVE-2023-22767HIGHCVSS 7.2EG 7.22023-03-01
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operat…
- CVE-2023-22768HIGHCVSS 7.2EG 7.22023-03-01
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operat…
- CVE-2023-22769HIGHCVSS 7.2EG 7.22023-03-01
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operat…
Map vulnerabilities like CWE-77 to your infrastructure
EchelonGraph correlates every CVE — across CWE-77 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →