CWE-78— OS Command Injection
5,525 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-78page 24 of 111
- CVE-2020-11084MEDIUMCVSS 6.4EG 6.42020-07-14
In iPear, the manual execution of the eval() function can lead to command injection. Only PCs where commands are manually executed via "For Developers" are affected. This function allows executing any PHP code within iPear which may change…
- CVE-2020-11490HIGHCVSS 7.2EG 7.22020-04-02
Manage::Certificates in Zen Load Balancer 3.10.1 allows remote authenticated admins to execute arbitrary OS commands via shell metacharacters in the index.cgi cert_issuer, cert_division, cert_organization, cert_locality, cert_state, cert_c…
- CVE-2020-11581HIGHCVSS 8.1EG 8.12020-04-06
An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris clients when a Host Checker policy is enforced, allows a man-in-the-middle attacker to per…
- CVE-2020-11699HIGHCVSS 8.8EG 8.82020-09-17
An issue was discovered in Titan SpamTitan 7.07. Improper validation of the parameter fname on the page certs-x.php would allow an attacker to execute remote code on the target server. The user has to be authenticated before interacting wi…
- CVE-2020-11733MEDIUMCVSS 6.7EG 6.72020-08-13
An issue was discovered on Spirent TestCenter and Avalanche appliance admin interface firmware. An attacker, who already has access to an SSH restricted shell, can achieve root access via shell metacharacters. The attacker can then, for ex…
- CVE-2020-11766HIGHCVSS 8.8EG 8.82020-05-19
sendfax.php in iFAX AvantFAX before 3.3.6 and HylaFAX Enterprise Web Interface before 0.2.5 allows authenticated Command Injection.
- CVE-2020-11847HIGHCVSS 8.2EG 8.22024-08-21
SSH authenticated user when access the PAM server can execute an OS command to gain the full system access using bash. This issue affects Privileged Access Manager before 3.7.0.1.
- CVE-2020-11852HIGHCVSS 8.8EG 8.82020-08-07
DKIM key management page vulnerability on Micro Focus Secure Messaging Gateway (SMG). Affecting all SMG Appliance running releases prior to July 2020. The vulnerability could allow a logged in user with rights to generate DKIM key informat…
- CVE-2020-11920CRITICALCVSS 9.8EG 9.82021-02-08
An issue was discovered in Svakom Siime Eye 14.1.00000001.3.330.0.0.3.14. A command injection vulnerability resides in the HOST/IP section of the NFS settings menu in the webserver running on the device. By injecting Bash commands via shel…
- CVE-2020-11941HIGHCVSS 8.8EG 8.82020-04-27
An issue was discovered in Open-AudIT 3.2.2. There is OS Command injection in Discovery.
- CVE-2020-11950HIGHCVSS 8.8EG 8.82020-05-28
VIVOTEK Network Cameras before XXXXX-VVTK-2.2002.xx.01x (and before XXXXX-VVTK-0XXXX_Beta2) allows an authenticated user to upload and execute a script (with resultant execution of OS commands). For example, this affects IT9388-HT devices.
- CVE-2020-11953HIGHCVSS 8.8EG 8.82020-07-14
An issue was discovered on Rittal PDU-3C002DEC through 5.15.40 and CMCIII-PU-9333E0FB through 3.15.70_4 devices. Attackers can execute code.
- CVE-2020-11956CRITICALCVSS 9.8EG 9.82020-07-14
An issue was discovered on Rittal PDU-3C002DEC through 5.17.10 and CMCIII-PU-9333E0FB through 3.17.10 devices. There is a least privilege violation.
- CVE-2020-11963CRITICALCVSS 9.8EG 9.82020-04-21
IQrouter through 3.3.1, when unconfigured, has multiple remote code execution vulnerabilities in the web-panel because of Bash Shell Metacharacter Injection. Note: The vendor claims that this vulnerability can only occur on a brand-new net…
- CVE-2020-11978HIGHCVSS 8.8EG 9.0⚠ KEV2020-07-17
An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow which would allow any authenticated user to run arbitrary command…
- CVE-2020-11981CRITICALCVSS 9.8EG 9.82020-07-17
An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attacker can connect to the broker (Redis, RabbitMQ) directly, it is possible to inject commands, resulting in the celery worker running arbi…
- CVE-2020-12078HIGHCVSS 8.8EG 8.82020-04-28
An issue was discovered in Open-AudIT 3.3.1. There is shell metacharacter injection via attributes to an open-audit/configuration/ URI. An attacker can exploit this by adding an excluded IP address to the global discovery settings (interna…
- CVE-2020-12107CRITICALCVSS 9.8EG 9.82020-08-12
The Web portal of the WiFi module of VPNCrypt M10 2.6.5 allows command injection via a text field, which allow full control over this module's Operating System.
- CVE-2020-12109HIGHCVSS 8.8EG 8.82020-05-04
Certain TP-Link devices allow Command Injection. This affects NC200 2.1.9 build 200225, NC210 1.0.9 build 200304, NC220 1.3.0 build 200304, NC230 1.3.0 build 200304, NC250 1.3.0 build 200304, NC260 1.5.2 build 200304, and NC450 1.5.3 build…
- CVE-2020-12111HIGHCVSS 8.8EG 8.82020-05-04
Certain TP-Link devices allow Command Injection. This affects NC260 1.5.2 build 200304 and NC450 1.5.3 build 200304.
- CVE-2020-12124CRITICALCVSS 9.8EG 9.82020-10-02
A remote command-line injection vulnerability in the /cgi-bin/live_api.cgi endpoint of the WAVLINK WN530H4 M30H4.V5030.190403 allows an attacker to execute arbitrary Linux commands as root without authentication.
- CVE-2020-12148MEDIUMCVSS 6.8EG 6.82020-12-11
A command injection flaw identified in the nslookup API in Silver Peak Unity ECOSTM (ECOS) appliance software could allow an attacker to execute arbitrary commands with the privileges of the web server running on the EdgeConnect appliance.…
- CVE-2020-12149MEDIUMCVSS 6.8EG 6.82020-12-11
The configuration backup/restore function in Silver Peak Unity ECOSTM (ECOS) appliance software was found to directly incorporate the user-controlled config filename in a subsequent shell command, allowing an attacker to manipulate the res…
- CVE-2020-12242HIGHCVSS 7.8EG 7.82020-04-27
Valve Source allows local users to gain privileges by writing to the /tmp/hl2_relaunch file, which is later executed in the context of a different user account.
- CVE-2020-12246HIGHCVSS 8.8EG 8.82020-04-29
Beeline Smart Box 2.0.38 routers allow "Advanced settings > Other > Diagnostics" OS command injection via the Ping ping_ipaddr parameter, the Nslookup nslookup_ipaddr parameter, or the Traceroute traceroute_ipaddr parameter.
- CVE-2020-12393HIGHCVSS 7.8EG 7.82020-05-26
The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If a user used the 'Copy as cURL' feature and pasted the command into a terminal, it could ha…
- CVE-2020-12513HIGHCVSS 7.5EG 7.52021-01-22
Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated blind OS Command Injection.
- CVE-2020-12522CRITICALCVSS 10.0EG 10.02020-12-17
The reported vulnerability allows an attacker who has network access to the device to execute code with specially crafted packets in WAGO Series PFC 100 (750-81xx/xxx-xxx), Series PFC 200 (750-82xx/xxx-xxx), Series Wago Touch Panel 600 Sta…
- CVE-2020-12620HIGHCVSS 7.8EG 7.82020-07-30
Pi-hole 4.4 allows a user able to write to /etc/pihole/dns-servers.conf to escalate privileges through command injection (shell metacharacters after an IP address).
- CVE-2020-12641CRITICALCVSS 9.8EG 9.8⚠ KEV2020-05-04
rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.
- CVE-2020-12774HIGHCVSS 8.2EG 8.22020-07-22
D-Link DSL-7740C does not properly validate user input, which allows an authenticated LAN user to inject arbitrary command.
- CVE-2020-12775CRITICALCVSS 9.8EG 9.82022-03-01
Hicos citizen certificate client-side component does not filter special characters for command parameters in specific web URLs. An unauthenticated remote attacker can exploit this vulnerability to perform command injection attack to execut…
- CVE-2020-13122HIGHCVSS 8.8EG 8.82020-08-17
The novish command-line interface, included in NoviFlow NoviWare before NW500.2.12 and deployed on NoviSwitch devices, is vulnerable to command injection in the "show status destination ipaddr" command. This could be used by a read-only us…
- CVE-2020-13124HIGHCVSS 8.8EG 8.82020-08-11
SABnzbd 2.3.9 and 3.0.0Alpha2 has a command injection vulnerability in the web configuration interface that permits an authenticated user to execute arbitrary Python commands on the underlying operating system.
- CVE-2020-13151CRITICALCVSS 9.8EG 9.82020-08-05
Aerospike Community Edition 4.9.0.5 allows for unauthenticated submission and execution of user-defined functions (UDFs), written in Lua, as part of a database query. It attempts to restrict code execution by disabling os.execute() calls, …
- CVE-2020-13159CRITICALCVSS 9.8EG 9.82020-06-22
Artica Proxy before 4.30.000000 Community Edition allows OS command injection via the Netbios name, Server domain name, dhclient_mac, Hostname, or Alias field. NOTE: this may overlap CVE-2020-10818.
- CVE-2020-13167CRITICALCVSS 9.8EG 9.82020-05-19
Netsweeper through 6.4.3 allows unauthenticated remote code execution because webadmin/tools/unixlogin.php (with certain Referer headers) launches a command line with client-supplied parameters, and allows injection of shell metacharacters.
- CVE-2020-13252HIGHCVSS 8.8EG 8.82020-05-21
Centreon before 19.04.15 allows remote attackers to execute arbitrary OS commands by placing shell metacharacters in RRDdatabase_status_path (via a main.get.php request) and then visiting the include/views/graphs/graphStatus/displayService…
- CVE-2020-13378HIGHCVSS 8.8EG 8.82023-05-12
Loadbalancer.org Enterprise VA MAX through 8.3.8 has an OS Command Injection vulnerability that allows a remote authenticated attacker to execute arbitrary code.
- CVE-2020-13388CRITICALCVSS 9.8EG 9.82020-05-22
An exploitable vulnerability exists in the configuration-loading functionality of the jw.util package before 2.3 for Python. When loading a configuration with FromString or FromStream with YAML, one can execute arbitrary Python code, resul…
- CVE-2020-13404HIGHCVSS 8.8EG 8.82020-08-05
The ATOS/Sips (aka Atos-Magento) community module 3.0.0 to 3.0.5 for Magento allows command injection.
- CVE-2020-13448HIGHCVSS 8.8EG 8.82020-06-01
QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8 allows an authenticated remote attacker to execute code on the server via command injection in the servicestart parameter.
- CVE-2020-13619CRITICALCVSS 9.8EG 9.82020-07-01
php/exec/escapeshellarg in Locutus PHP through 2.0.11 allows an attacker to achieve code execution.
- CVE-2020-13694HIGHCVSS 8.8EG 8.82020-06-01
In QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8, the local www-data user can execute sudo mysql without a password, which means that the www-data user can execute arbitrary OS commands via the mysql -e option.
- CVE-2020-13712HIGHCVSS 7.8EG 7.82024-12-20
A command injection is possible through the user interface, allowing arbitrary command execution as the root user. oMG2000 running MGOS 3.15.1 or earlier is affected. MG90 running MGOS 4.2.1 or earlier is affected.
- CVE-2020-13778HIGHCVSS 8.8EG 8.82020-10-19
rConfig 3.9.4 and earlier allows authenticated code execution (of system commands) by sending a forged GET request to lib/ajaxHandlers/ajaxAddTemplate.php or lib/ajaxHandlers/ajaxEditTemplate.php.
- CVE-2020-13782HIGHCVSS 8.8EG 8.82020-06-03
D-Link DIR-865L Ax 1.20B01 Beta devices allow Command Injection.
- CVE-2020-13802CRITICALCVSS 9.8EG 9.82020-09-02
Rebar3 versions 3.0.0-beta.3 to 3.13.2 are vulnerable to OS command injection via URL parameter of dependency specification.
- CVE-2020-13851HIGHCVSS 8.8EG 9.02020-06-11
Artica Pandora FMS 7.44 allows remote command execution via the events feature.
- CVE-2020-13917CRITICALCVSS 9.8EG 9.82020-07-28
rkscli in Ruckus Wireless Unleashed through 200.7.10.92 allows a remote attacker to achieve command injection and jailbreak the CLI via a crafted CLI command. This affects C110, E510, H320, H510, M510, R320, R310, R500, R510 R600, R610, R7…
Map vulnerabilities like CWE-78 to your infrastructure
EchelonGraph correlates every CVE — across CWE-78 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →