CWE-77— Command Injection
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.— MITRE CWE catalog
4,102 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-77page 39 of 83
- CVE-2023-33782HIGHCVSS 8.8EG 8.82023-06-07
D-Link DIR-842V2 v1.0.3 was discovered to contain a command injection vulnerability via the iperf3 diagnostics function.
- CVE-2023-33806HIGHCVSS 7.8EG 7.82024-04-15
Insecure default configurations in Hikvision Interactive Tablet DS-D5B86RB/B V2.3.0 build220119, allows attackers to execute arbitrary commands.
- CVE-2023-33831CRITICALCVSS 9.8EG 9.82023-09-18
A remote command execution (RCE) vulnerability in the /api/runscript endpoint of FUXA 1.1.13 allows attackers to execute arbitrary commands via a crafted POST request.
- CVE-2023-33919HIGHCVSS 7.2EG 7.82023-06-13
A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All versions < CPCI85 V05). The web interface of affected devices is vulnerable to command injection due to missing server sid…
- CVE-2023-34105HIGHCVSS 7.5EG 7.52023-06-12
SRS is a real-time video server supporting RTMP, WebRTC, HLS, HTTP-FLV, SRT, MPEG-DASH, and GB28181. Prior to versions 5.0.157, 5.0-b1, and 6.0.48, SRS's `api-server` server is vulnerable to a drive-by command injection. An attacker may se…
- CVE-2023-34111HIGHCVSS 8.1EG 8.12023-06-06
The `Release PR Merged` workflow in the github repo taosdata/grafanaplugin is subject to a command injection vulnerability which allows for arbitrary code execution within the github action context due to the insecure usage of `${{ github.…
- CVE-2023-34153HIGHCVSS 7.8EG 7.82023-05-30
A vulnerability was found in ImageMagick. This security flaw causes a shell command injection vulnerability via video:vsync or video:pixel-format options in VIDEO encoding/decoding.
- CVE-2023-34213HIGHCVSS 8.8EG 8.82023-08-17
TN-5900 Series firmware versions v3.3 and prior are vulnerable to command-injection vulnerability. This vulnerability stems from insufficient input validation and improper authentication in the key-generation function, which could potentia…
- CVE-2023-34214HIGHCVSS 7.2EG 7.22023-08-17
TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command-injection vulnerability. This vulnerability stems from insufficient input validation in the certificate-gen…
- CVE-2023-34215HIGHCVSS 7.2EG 7.22023-08-17
TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command-injection vulnerability. This vulnerability stems from insufficient input validation and improper authentication in the certification-generation function, which …
- CVE-2023-34230HIGHCVSS 7.3EG 7.32023-06-08
snowflake-connector-net, the Snowflake Connector for .NET, is vulnerable to command injection prior to version 2.0.18 via SSO URL authentication. In order to exploit the potential for command injection, an attacker would need to be success…
- CVE-2023-34231HIGHCVSS 8.8EG 8.82023-06-08
gosnowflake is th Snowflake Golang driver. Prior to version 1.6.19, a command injection vulnerability exists in the Snowflake Golang driver via single sign-on (SSO) browser URL authentication. In order to exploit the potential for command …
- CVE-2023-34232HIGHCVSS 7.3EG 7.32023-06-08
snowflake-connector-nodejs, a NodeJS driver for Snowflake, is vulnerable to command injection via single sign on (SSO) browser URL authentication in versions prior to 1.6.21. In order to exploit the potential for command injection, an atta…
- CVE-2023-34233HIGHCVSS 8.8EG 8.82023-06-08
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Versions prior to 3.0.2 are vulnerable to command injection via single sign-on(S…
- CVE-2023-34849CRITICALCVSS 9.8EG 9.82023-06-29
An unauthorized command injection vulnerability exists in the ActionLogin function of the webman.lua file in Ikuai router OS through 3.7.1.
- CVE-2023-34960CRITICALCVSS 9.8EG 9.82023-08-01
A command injection vulnerability in the wsConvertPpt component of Chamilo v1.11.* up to v1.11.18 allows attackers to execute arbitrary commands via a SOAP API call with a crafted PowerPoint name.
- CVE-2023-34999HIGHCVSS 8.4EG 8.42023-09-18
A command injection vulnerability exists in RTS VLink Virtual Matrix Software Versions v5 (< 5.7.6) and v6 (< 6.5.0) that allows an attacker to perform arbitrary code execution via the admin web interface.
- CVE-2023-35031HIGHCVSS 8.8EG 8.82023-06-12
Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8, Assistant V10 R0, Manager V10 R1 before V10 R1.42.0 and V10 R1.34.8, and Manager V10 R0 allow command injection by authenticated users, aka OSFOURK-24036.
- CVE-2023-35032HIGHCVSS 8.8EG 8.82023-06-12
Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8 and Manager V10 R1 before V10 R1.42.0 and V10 R1.34.8 allow command injection by authenticated users, aka OSFOURK-23554.
- CVE-2023-35033HIGHCVSS 8.8EG 8.82023-06-12
Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8, Assistant V10 R0, Manager V10 R1 before V10 R1.42.0 and V10 R1.34.8, and Manager V10 R0 allow command injection by authenticated users, aka OSFOURK-23556.
- CVE-2023-35035HIGHCVSS 8.8EG 8.82023-06-12
Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8, Assistant V10 R0, Manager V10 R1 before V10 R1.42.0 and V10 R1.34.8, and Manager V10 R0 allow command injection by authenticated users, aka OSFOURK-23557.
- CVE-2023-35390HIGHCVSS 7.8EG 7.82023-08-08
.NET and Visual Studio Remote Code Execution Vulnerability
- CVE-2023-35932HIGHCVSS 7.1EG 7.12023-06-23
jcvi is a Python library to facilitate genome assembly, annotation, and comparative genomics. A configuration injection happens when user input is considered by the application in an unsanitized format and can reach the configuration file.…
- CVE-2023-35972HIGHCVSS 7.2EG 7.22023-07-05
An authenticated remote command injection vulnerability exists in the ArubaOS web-based management interface. Successful exploitation of this vulnerability results in the ability to execute arbitrary commands as a privileged user on th…
- CVE-2023-35973HIGHCVSS 7.2EG 7.22023-07-05
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying op…
- CVE-2023-35974HIGHCVSS 7.2EG 7.22023-07-05
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying op…
- CVE-2023-36103CRITICALCVSS 9.8EG 9.82024-09-10
Command Injection vulnerability in goform/SetIPTVCfg interface of Tenda AC15 V15.03.05.20 allows remote attackers to run arbitrary commands via crafted POST request.
- CVE-2023-36414HIGHCVSS 8.8EG 8.82023-10-10
Azure Identity SDK Remote Code Execution Vulnerability
- CVE-2023-36415HIGHCVSS 8.8EG 8.82023-10-10
Azure Identity SDK Remote Code Execution Vulnerability
- CVE-2023-36457MEDIUMCVSS 6.3EG 6.32023-07-05
1Panel is an open source Linux server operation and maintenance management panel. Prior to version 1.3.6, an authenticated attacker can craft a malicious payload to achieve command injection when adding container repositories. The vulnerab…
- CVE-2023-36458MEDIUMCVSS 6.3EG 6.32023-07-05
1Panel is an open source Linux server operation and maintenance management panel. Prior to version 1.3.6, an authenticated attacker can craft a malicious payloads to achieve command injection when entering the container terminal. The vulne…
- CVE-2023-36642MEDIUMCVSS 6.7EG 6.72023-09-13
An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface of FortiTester 3.0.0 through 7.2.3 may allow an authenticated attacker to execute unauthorized commands via specifical…
- CVE-2023-36750CRITICALCVSS 9.1EG 9.12023-07-11
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V2.16.0), RUGGEDCOM …
- CVE-2023-36751CRITICALCVSS 9.1EG 9.12023-07-11
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V2.16.0), RUGGEDCOM …
- CVE-2023-36752CRITICALCVSS 9.1EG 9.12023-07-11
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V2.16.0), RUGGEDCOM …
- CVE-2023-36753CRITICALCVSS 9.1EG 9.12023-07-11
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V2.16.0), RUGGEDCOM …
- CVE-2023-36754CRITICALCVSS 9.1EG 9.12023-07-11
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V2.16.0), RUGGEDCOM …
- CVE-2023-36755CRITICALCVSS 9.1EG 9.12023-07-11
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.0), RUGGEDCOM ROX MX5000RE (All versions < V2.16.0), RUGGEDCOM ROX RX1400 (All versions < V2.16.0), RUGGEDCOM ROX RX1500 (All versions < V2.16.0), RUGGEDCOM …
- CVE-2023-36805HIGHCVSS 7.0EG 7.02023-09-12
Windows MSHTML Platform Security Feature Bypass Vulnerability
- CVE-2023-36953CRITICALCVSS 9.8EG 9.82023-10-16
TOTOLINK CP300+ V5.2cu.7594_B20200910 and before is vulnerable to command injection.
- CVE-2023-36954CRITICALCVSS 9.8EG 9.82023-10-16
TOTOLINK CP300+ V5.2cu.7594_B20200910 and before is vulnerable to command injection.
- CVE-2023-3710CRITICALCVSS 9.9EG 9.92023-09-12
Improper Input Validation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Command Injection.This issue affects PM43 versions prior to P10.19.050004. Update to the latest available firmware version of the r…
- CVE-2023-37144CRITICALCVSS 9.8EG 9.82023-07-07
Tenda AC10 v15.03.06.26 was discovered to contain a command injection vulnerability via the mac parameter in the function formWriteFacMac.
- CVE-2023-37145CRITICALCVSS 9.8EG 9.82023-07-07
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the hostname parameter in the setOpModeCfg function.
- CVE-2023-37146CRITICALCVSS 9.8EG 9.82023-07-07
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the FileName parameter in the UploadFirmwareFile function.
- CVE-2023-37148CRITICALCVSS 9.8EG 9.82023-07-07
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the ussd parameter in the setUssd function.
- CVE-2023-37149CRITICALCVSS 9.8EG 9.82023-07-07
TOTOLINK LR350 V9.3.5u.6369_B20220309 was discovered to contain a command injection vulnerability via the FileName parameter in the setUploadSetting function.
- CVE-2023-37154HIGHCVSS 8.4EG 8.42024-10-09
check_by_ssh in Nagios nagios-plugins 2.4.5 allows arbitrary command execution via ProxyCommand, LocalCommand, and PermitLocalCommand with \${IFS}. This has been categorized both as fixed in e8810de, and as intended behavior.
- CVE-2023-3718HIGHCVSS 8.8EG 8.82023-08-01
An authenticated command injection vulnerability exists in the AOS-CX command line interface. Successful exploitation of this vulnerability results in the ability to execute arbitrary commands on the underlying operating system as a privi…
- CVE-2023-37214CRITICALCVSS 9.8EG 9.82023-07-30
Heights Telecom ERO1xS-Pro Dual-Band FW version BZ_ERO1XP.025.
Map vulnerabilities like CWE-77 to your infrastructure
EchelonGraph correlates every CVE — across CWE-77 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →