CWE-78— OS Command Injection
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.— MITRE CWE catalog
6,261 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-78page 24 of 126
- CVE-2019-1959MEDIUMCVSS 4.4EG 4.42019-08-08
Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to read arbitrary files on the underlying operating system (OS) of an affected device. For more information about…
- CVE-2019-1960MEDIUMCVSS 4.4EG 4.42019-08-08
Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to read arbitrary files on the underlying operating system (OS) of an affected device. For more information about…
- CVE-2019-19604HIGHCVSS 7.8EG 7.82019-12-11
Arbitrary command execution is possible in Git before 2.20.2, 2.21.x before 2.21.1, 2.22.x before 2.22.2, 2.23.x before 2.23.1, and 2.24.x before 2.24.1 because a "git submodule update" operation can run commands found in the .gitmodules f…
- CVE-2019-19606CRITICALCVSS 9.8EG 9.82020-03-30
X-Plane before 11.41 has multiple improper path validations that could allow reading and writing files from/to arbitrary paths (or a leak of OS credentials to a remote system) via crafted network packets. This could be used to execute arbi…
- CVE-2019-19609HIGHCVSS 7.2EG 8.02019-12-05
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin components of the Admin panel, because it does not sanitize the plugin name, and attackers can inject arbitrary shell co…
- CVE-2019-19642HIGHCVSS 8.8EG 8.82019-12-08
On SuperMicro X8STi-F motherboards with IPMI firmware 2.06 and BIOS 02.68, the Virtual Media feature allows OS Command Injection by authenticated attackers who can send HTTP requests to the IPMI IP address. This requires a POST to /rpc/set…
- CVE-2019-1971CRITICALCVSS 9.8EG 9.82019-08-08
A vulnerability in the web portal of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an unauthenticated, remote attacker to perform a command injection attack and execute arbitrary commands with root privileges. The vulner…
- CVE-2019-19824HIGHCVSS 8.8EG 8.82020-01-27
On certain TOTOLINK Realtek SDK based routers, an authenticated attacker may execute arbitrary OS commands via the sysCmd parameter to the boafrm/formSysCmd URI, even if the GUI (syscmd.htm) is not available. This allows for full control o…
- CVE-2019-19838CRITICALCVSS 9.8EG 9.82020-01-23
emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=get-platform-depends to admin/_cmdstat.jsp via the uploadFile attribute.
- CVE-2019-19839CRITICALCVSS 9.8EG 9.82020-01-23
emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=import-category to admin/_cmdstat.jsp via the uploadFile attribute.
- CVE-2019-19841CRITICALCVSS 9.8EG 9.82020-01-22
emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=packet-capture to admin/_cmdstat.jsp via the mac attribute.
- CVE-2019-19842CRITICALCVSS 9.8EG 9.82020-01-22
emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST request with the attribute xcmd=spectra-analysis to admin/_cmdstat.jsp via the mac attribute.
- CVE-2019-19897CRITICALCVSS 9.8EG 9.82020-01-23
In IXP EasyInstall 6.2.13723, there is Remote Code Execution via the Agent Service. An unauthenticated attacker can communicate with the Agent Service over TCP port 20051, and execute code in the NT AUTHORITY\SYSTEM context of the target s…
- CVE-2019-19920HIGHCVSS 8.8EG 8.82019-12-22
sa-exim 4.2.1 allows attackers to execute arbitrary code if they can write a .cf file or a rule. This occurs because Greylisting.pm relies on eval (rather than direct parsing and/or use of the taint feature). This issue is similar to CVE-2…
- CVE-2019-19940HIGHCVSS 7.2EG 7.22020-03-16
Incorrect input sanitation in text-oriented user interfaces (telnet, ssh) in Swisscom Centro Grande before 6.16.12 allows remote authenticated users to execute arbitrary commands via command injection.
- CVE-2019-19994CRITICALCVSS 9.8EG 9.82020-02-26
An issue was discovered in Selesta Visual Access Manager (VAM) 4.15.0 through 4.29. It allows blind Command Injection. An attacker without authentication is able to execute arbitrary operating system command by injecting the vulnerable par…
- CVE-2019-20050MEDIUMCVSS 6.8EG 6.82020-01-30
Pandora FMS ≤ 7.42 suffers from a remote code execution vulnerability. To exploit the vulnerability, an authenticated user should create a new folder with a "tricky" name in the filemanager. The exploit works when the php-fileinfo extens…
- CVE-2019-20197HIGHCVSS 8.8EG 8.82019-12-31
In Nagios XI 5.6.9, an authenticated user is able to execute arbitrary OS commands via shell metacharacters in the id parameter to schedulereport.php, in the context of the web-server user account.
- CVE-2019-20215CRITICALCVSS 9.8EG 9.82020-01-29
D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via a urn: to the M-SEARCH method in ssdpcgi() in /htdocs/cgibin, because HTTP_ST is mishandled. The value of the urn: service/device is…
- CVE-2019-20216CRITICALCVSS 9.8EG 9.82020-01-29
D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via the urn: to the M-SEARCH method in ssdpcgi() in /htdocs/cgibin, because REMOTE_PORT is mishandled. The value of the urn: service/dev…
- CVE-2019-20217CRITICALCVSS 9.8EG 9.82020-01-29
D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via the urn: to the M-SEARCH method in ssdpcgi() in /htdocs/cgibin, because SERVER_ID is mishandled. The value of the urn: service/devic…
- CVE-2019-20224HIGHCVSS 8.8EG 8.92020-01-09
netflow_get_stats in functions_netflow.php in Pandora FMS 7.0NG allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ip_src parameter in an index.php?operation/netflow/nf_live_view request. Thi…
- CVE-2019-20348MEDIUMCVSS 6.8EG 6.82020-01-06
OKER G232V1 v1.03.02.20161129 devices provide a root terminal on a UART serial interface without proper access control. This allows attackers with physical access to interrupt the boot sequence in order to execute arbitrary commands with r…
- CVE-2019-20488CRITICALCVSS 9.8EG 9.82020-03-02
An issue was discovered on NETGEAR WNR1000V4 1.1.0.54 devices. Multiple actions within the web management interface (setup.cgi) are vulnerable to command injection, allowing remote attackers to execute arbitrary commands, as demonstrated b…
- CVE-2019-20499CRITICALCVSS 7.8EG 9.02020-03-05
D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Restore Configuration functionality in the Web interface, using shell metacharacters in the admin.cgi?action=config_restore configRes…
- CVE-2019-20500CRITICALCVSS 7.8EG 9.0⚠ KEV2020-03-05
D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Save Configuration functionality in the Web interface, using shell metacharacters in the admin.cgi?action=config_save configBackup or…
- CVE-2019-20501CRITICALCVSS 7.8EG 9.02020-03-05
D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Upgrade Firmware functionality in the Web interface, using shell metacharacters in the admin.cgi?action=upgrade firmwareRestore or fi…
- CVE-2019-20504CRITICALCVSS 9.8EG 9.82020-03-09
service/krashrpt.php in Quest KACE K1000 Systems Management Appliance before 6.4 SP3 (6.4.120822) allows a remote attacker to execute code via shell metacharacters in the kuid parameter.
- CVE-2019-20701HIGHCVSS 8.0EG 8.02020-04-16
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32.
- CVE-2019-20702HIGHCVSS 8.0EG 8.02020-04-16
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32.
- CVE-2019-20703HIGHCVSS 8.0EG 8.02020-04-16
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32.
- CVE-2019-20704HIGHCVSS 8.0EG 8.02020-04-16
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32.
- CVE-2019-20705HIGHCVSS 8.0EG 8.02020-04-16
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32.
- CVE-2019-20706HIGHCVSS 8.0EG 8.02020-04-16
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7800 before 1.0.2.60 and XR500 before 2.3.2.32.
- CVE-2019-20707HIGHCVSS 8.0EG 8.02020-04-16
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7800 before 1.0.2.60 and XR500 before 2.3.2.32.
- CVE-2019-20708HIGHCVSS 8.0EG 8.02020-04-16
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32.
- CVE-2019-20709HIGHCVSS 8.0EG 8.02020-04-16
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32.
- CVE-2019-20710HIGHCVSS 8.0EG 8.02020-04-16
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32.
- CVE-2019-20711HIGHCVSS 8.0EG 8.02020-04-16
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32.
- CVE-2019-20745MEDIUMCVSS 6.8EG 6.82020-04-16
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects WAC505 before 5.0.10.2 and WAC510 before 5.0.10.2.
- CVE-2019-20757MEDIUMCVSS 6.8EG 6.82020-04-16
NETGEAR R7800 devices before 1.0.2.62 are affected by command injection by an authenticated user.
- CVE-2019-20761HIGHCVSS 8.0EG 8.02020-04-16
NETGEAR R7800 devices before 1.0.2.62 are affected by command injection by an authenticated user.
- CVE-2019-20807MEDIUMCVSS 5.3EG 5.32020-05-28
In Vim before 8.1.0881, users can circumvent the rvim restricted mode and execute arbitrary OS commands via scripting interfaces (e.g., Python, Ruby, or Lua).
- CVE-2019-25022CRITICALCVSS 9.8EG 9.82021-02-27
An issue was discovered in Scytl sVote 2.1. An attacker can inject code that gets executed by creating an election-event and injecting a payload over an event alias, because the application calls Runtime.getRuntime().exec() without validat…
- CVE-2019-25024CRITICALCVSS 9.8EG 9.82021-02-19
OpenRepeater (ORP) before 2.2 allows unauthenticated command injection via shell metacharacters in the functions/ajax_system.php post_service parameter.
- CVE-2019-25065CRITICALCVSS 6.3EG 9.82022-06-09
A vulnerability was found in OpenNetAdmin 18.1.1. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation leads to privilege escalation. The attack may be launched remotely. The exploit has bee…
- CVE-2019-25066HIGHCVSS 6.3EG 8.82022-06-09
A vulnerability has been found in ajenti 2.1.31 and classified as critical. This vulnerability affects unknown code of the component API. The manipulation leads to privilege escalation. The attack can be initiated remotely. The exploit has…
- CVE-2019-25158MEDIUMCVSS 5.5EG 5.52023-12-19
A vulnerability has been found in pedroetb tts-api up to 2.1.4 and classified as critical. This vulnerability affects the function onSpeechDone of the file app.js. The manipulation leads to os command injection. Upgrading to version 2.2.0 …
- CVE-2019-25224CRITICALCVSS 9.8EG 9.82025-07-25
The WP Database Backup plugin for WordPress is vulnerable to OS Command Injection in versions before 5.2 via the mysqldump function. This vulnerability allows unauthenticated attackers to execute arbitrary commands on the host operating sy…
- CVE-2019-25243HIGHCVSS 8.8EG 8.82025-12-24
FaceSentry 6.4.8 contains an authenticated remote command injection vulnerability in pingTest.php and tcpPortTest.php scripts. Attackers can exploit unsanitized input parameters to inject and execute arbitrary shell commands with root priv…
Map vulnerabilities like CWE-78 to your infrastructure
EchelonGraph correlates every CVE — across CWE-78 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →