CWE-77— Command Injection
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.— MITRE CWE catalog
4,102 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-77page 7 of 83
- CVE-2018-9866CRITICALCVSS 9.8EG 9.82018-08-03
A vulnerability in lack of validation of user-supplied parameters pass to XML-RPC calls on SonicWall Global Management System (GMS) virtual appliance's, allow remote user to execute arbitrary code. This vulnerability affected GMS version 8…
- CVE-2019-0541CRITICALCVSS 8.8EG 9.0⚠ KEV2019-01-08
A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Office Word Viewer, Internet Explo…
- CVE-2019-1000018HIGHCVSS 7.8EG 7.82019-02-04
rssh version 2.3.4 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in allowscp permission that can result in Local command execution. This attack appear to be exploitable…
- CVE-2019-10095CRITICALCVSS 9.8EG 9.82021-09-02
bash command injection vulnerability in Apache Zeppelin allows an attacker to inject system commands into Spark interpreter settings. This issue affects Apache Zeppelin Apache Zeppelin version 0.9.0 and prior versions.
- CVE-2019-1010174CRITICALCVSS 9.8EG 9.82019-07-25
CImg The CImg Library v.2.3.3 and earlier is affected by: command injection. The impact is: RCE. The component is: load_network() function. The attack vector is: Loading an image from a user-controllable url can lead to command injection, …
- CVE-2019-10640HIGHCVSS 7.5EG 7.52019-05-15
An issue was discovered in GitLab Community and Enterprise Edition before 11.7.10, 11.8.x before 11.8.6, and 11.9.x before 11.9.4. A regex input validation issue for the .gitlab-ci.yml refs value allows Uncontrolled Resource Consumption.
- CVE-2019-10854HIGHCVSS 8.8EG 8.82019-05-23
Computrols CBAS 18.0.0 allows Authenticated Command Injection.
- CVE-2019-11076CRITICALCVSS 9.8EG 9.82019-04-23
Cribl UI 1.5.0 allows remote attackers to run arbitrary commands via an unauthenticated web request.
- CVE-2019-11217CRITICALCVSS 9.8EG 9.82019-04-24
The GitController in Jakub Chodounsky Bonobo Git Server before 6.5.0 allows execution of arbitrary commands in the context of the web server via a crafted http request.
- CVE-2019-11278HIGHCVSS 8.8EG 8.82019-09-26
CF UAA versions prior to 74.1.0, allow external input to be directly queried against. A remote malicious user with 'client.write' and 'groups.update' can craft a SCIM query, which leaks information that allows an escalation of privileges, …
- CVE-2019-11279HIGHCVSS 8.8EG 8.82019-09-26
CF UAA versions prior to 74.1.0 can request scopes for a client that shouldn't be allowed by submitting an array of requested scopes. A remote malicious user can escalate their own privileges to any scope, allowing them to take control of …
- CVE-2019-11535CRITICALCVSS 9.8EG 9.82019-07-17
Unsanitized user input in the web interface for Linksys WiFi extender products (RE6400 and RE6300 through 1.2.04.022) allows for remote command execution. An attacker can access system OS configurations and commands that are not intended f…
- CVE-2019-11853LOWCVSS 3.9EG 3.92020-08-21
Several potential command injections vulnerabilities exist in the AT command interface of ALEOS before 4.11.0, and 4.9.4.
- CVE-2019-12104HIGHCVSS 8.8EG 8.82019-08-14
The web-based configuration interface of the TP-Link M7350 V3 with firmware before 190531 is affected by several post-authentication command injection vulnerabilities.
- CVE-2019-12430HIGHCVSS 8.8EG 8.82020-03-10
An issue was discovered in GitLab Community and Enterprise Edition 11.11. A specially crafted payload would allow an authenticated malicious user to execute commands remotely through the repository download feature. It allows Command Injec…
- CVE-2019-12591MEDIUMCVSS 6.8EG 6.82019-06-03
NETGEAR Insight Cloud with firmware before Insight 5.6 allows remote authenticated users to achieve command injection.
- CVE-2019-12629HIGHCVSS 7.2EG 7.22020-01-26
A vulnerability in the WebUI of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to inject and execute arbitrary commands with vmanage user privileges on an affected system. The vulnerability is due to insufficient i…
- CVE-2019-12650HIGHCVSS 8.8EG 8.82019-09-25
Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands with elevated privileges on the affected device. For more information about these …
- CVE-2019-12651HIGHCVSS 8.8EG 8.82019-09-25
Multiple vulnerabilities in the web-based user interface (Web UI) of Cisco IOS XE Software could allow an authenticated, remote attacker to execute commands with elevated privileges on the affected device. For more information about these …
- CVE-2019-12661MEDIUMCVSS 6.7EG 6.72019-09-25
A vulnerability in a Virtualization Manager (VMAN) related CLI command of Cisco IOS XE Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying Linux operating system with a privilege level of r…
- CVE-2019-12736CRITICALCVSS 9.8EG 9.82019-10-02
JetBrains Ktor framework before 1.2.0-rc does not sanitize the username provided by the user for the LDAP protocol, leading to command injection.
- CVE-2019-12786HIGHCVSS 8.8EG 8.82019-06-10
An issue was discovered on D-Link DIR-818LW devices from 2.05.B03 to 2.06B01 BETA. There is a command injection in HNAP1 SetWanSettings via an XML injection of the value of the IPAddress key.
- CVE-2019-12805HIGHCVSS 8.8EG 8.82019-08-09
NCSOFT Game Launcher, NC Launcher2 2.4.1.691 and earlier versions have a vulnerability in the custom protocol handler that could allow remote attacker to execute arbitrary command. User interaction is required to exploit this vulnerability…
- CVE-2019-12921MEDIUMCVSS 6.5EG 6.52020-03-18
In GraphicsMagick before 1.3.32, the text filename component allows remote attackers to read arbitrary files via a crafted image because of TranslateTextEx for SVG.
- CVE-2019-13024HIGHCVSS 8.8EG 8.82019-07-01
Centreon 18.x before 18.10.6, 19.x before 19.04.3, and Centreon web before 2.8.29 allows the attacker to execute arbitrary system commands by using the value "init_script"-"Monitoring Engine Binary" in main.get.php to insert a arbitrary co…
- CVE-2019-13148HIGHCVSS 8.8EG 8.82019-07-02
An issue was discovered in TRENDnet TEW-827DRU firmware before 2.05B11. There is a command injection in apply.cgi (exploitable with authentication) via the UDP Ports To Open in Add Gaming Rule.
- CVE-2019-13150HIGHCVSS 8.8EG 8.82019-07-02
An issue was discovered in TRENDnet TEW-827DRU firmware before 2.05B11. There is a command injection in apply.cgi (exploitable with authentication). The command injection exists in the key ip_addr.
- CVE-2019-13152HIGHCVSS 8.8EG 8.82019-07-02
An issue was discovered in TRENDnet TEW-827DRU firmware before 2.05B11. There is a command injection in apply.cgi (exploitable with authentication) via the IP Address in Add Gaming Rule.
- CVE-2019-13552HIGHCVSS 8.8EG 8.82019-09-18
In WebAccess versions 8.4.1 and prior, multiple command injection vulnerabilities are caused by a lack of proper validation of user-supplied data and may allow arbitrary file deletion and remote code execution.
- CVE-2019-14719HIGHCVSS 7.8EG 7.82020-10-23
Verifone MX900 series Pinpad Payment Terminals with OS 30251000 allow multiple arbitrary command injections, as demonstrated by the file manager.
- CVE-2019-14745HIGHCVSS 7.8EG 7.82019-08-07
In radare2 before 3.7.0, a command injection vulnerability exists in bin_symbols() in libr/core/cbin.c. By using a crafted executable file, it's possible to execute arbitrary shell commands with the permissions of the victim. This vulnerab…
- CVE-2019-14868HIGHCVSS 7.4EG 7.82020-04-02
In ksh version 20120801, a flaw was found in the way it evaluates certain environment variables. An attacker could use this flaw to override or bypass environment restrictions to execute shell commands. Services and applications that allow…
- CVE-2019-14944MEDIUMCVSS 6.5EG 6.52023-04-16
An issue was discovered in GitLab Community and Enterprise Edition before 11.11.8, 12 before 12.0.6, and 12.1 before 12.1.6. Gitaly allows injection of command-line flags. This sometimes leads to privilege escalation or remote code executi…
- CVE-2019-15010HIGHCVSS 8.8EG 8.82020-01-15
Bitbucket Server and Bitbucket Data Center versions starting from version 3.0.0 before version 5.16.11, from version 6.0.0 before 6.0.11, from version 6.1.0 before 6.1.9, from version 6.2.0 before 6.2.7, from version 6.3.0 before 6.3.6, fr…
- CVE-2019-15051HIGHCVSS 8.8EG 8.82019-10-10
An issue was discovered in Softing uaGate (SI, MB, 840D) firmware through 1.71.00.1225. A CGI script is vulnerable to command injection via a maliciously crafted form parameter.
- CVE-2019-15575HIGHCVSS 7.5EG 7.52019-12-18
A command injection exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.12 that allowed an attacker to inject commands via the API through the blobs scope.
- CVE-2019-15588HIGHCVSS 7.2EG 7.22019-11-01
There is an OS Command Injection in Nexus Repository Manager <= 2.14.14 (bypass CVE-2019-5475) that could allow an attacker a Remote Code Execution (RCE). All instances using CommandLineExecutor.java with user-supplied data is vulnerable, …
- CVE-2019-15595HIGHCVSS 8.8EG 8.82019-11-26
A privilege escalation exists in UniFi Video Controller =<3.10.6 that would allow an attacker on the local machine to run arbitrary commands.
- CVE-2019-15609CRITICALCVSS 9.8EG 9.82020-02-28
The kill-port-process package version < 2.2.0 is vulnerable to a Command Injection vulnerability.
- CVE-2019-1584CRITICALCVSS 9.8EG 9.82019-10-09
A security vulnerability exists in Zingbox Inspector version 1.293 and earlier, that allows for remote code execution if the Inspector were sent a malicious command from the Zingbox cloud, or if the Zingbox Inspector were tampered with to …
- CVE-2019-15954CRITICALCVSS 9.9EG 9.92019-09-05
An issue was discovered in Total.js CMS 12.0.0. An authenticated user with the widgets privilege can gain achieve Remote Command Execution (RCE) on the remote server by creating a malicious widget with a special tag containing JavaScript c…
- CVE-2019-16005HIGHCVSS 7.2EG 7.22020-01-26
A vulnerability in the web-based management interface of Cisco Webex Video Mesh could allow an authenticated, remote attacker to execute arbitrary commands on the affected system. The vulnerability is due to improper validation of user-sup…
- CVE-2019-16011HIGHCVSS 7.8EG 7.82020-04-29
A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges. The vulnerability is due to insufficient input validation. An atta…
- CVE-2019-16012HIGHCVSS 8.1EG 8.52020-03-19
A vulnerability in the web UI of Cisco SD-WAN Solution vManage software could allow an authenticated, remote attacker to conduct SQL injection attacks on an affected system. The vulnerability exists because the web UI improperly validates …
- CVE-2019-1606HIGHCVSS 7.8EG 7.82019-03-08
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device. The vulnerability is due to insufficient validation of …
- CVE-2019-1607MEDIUMCVSS 6.7EG 6.72019-03-08
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device. The vulnerability is due to insufficient validation of …
- CVE-2019-1608MEDIUMCVSS 6.7EG 6.72019-03-08
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device. The vulnerability is due to insufficient validation of …
- CVE-2019-1609MEDIUMCVSS 6.7EG 6.72019-03-08
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device. The vulnerability is due to insufficient validation of …
- CVE-2019-1610MEDIUMCVSS 6.7EG 6.72019-03-11
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device. The vulnerability is due to insufficient validation of …
- CVE-2019-1611MEDIUMCVSS 6.7EG 6.72019-03-11
A vulnerability in the CLI of Cisco NX-OS Software and Cisco FXOS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device. The vulnerability is due to ins…
Map vulnerabilities like CWE-77 to your infrastructure
EchelonGraph correlates every CVE — across CWE-77 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →