CWE-78— OS Command Injection
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.— MITRE CWE catalog
6,261 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-78page 30 of 126
- CVE-2020-15893CRITICALCVSS 9.8EG 9.82020-07-22
An issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. Universal Plug and Play (UPnP) is enabled by default on port 1900. An attacker can perform command injection by injecting a payload into the Search Target (ST) fi…
- CVE-2020-15916CRITICALCVSS 9.8EG 9.82020-07-23
goform/AdvSetLanip endpoint on Tenda AC15 AC1900 15.03.05.19 devices allows remote attackers to execute arbitrary system commands via shell metacharacters in the lanIp POST parameter.
- CVE-2020-15920CRITICALCVSS 9.8EG 9.82020-07-24
There is an OS Command Injection in Mida eFramework through 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) privileges. No authentication is required.
- CVE-2020-15922CRITICALCVSS 9.8EG 9.82020-07-24
There is an OS Command Injection in Mida eFramework 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) privileges. Authentication is required.
- CVE-2020-1602HIGHCVSS 7.1EG 7.12020-01-15
When a device using Juniper Network's Dynamic Host Configuration Protocol Daemon (JDHCPD) process on Junos OS or Junos OS Evolved which is configured in relay mode it vulnerable to an attacker sending crafted IPv4 packets who may remotely …
- CVE-2020-1605HIGHCVSS 8.8EG 8.82020-01-15
When a device using Juniper Network's Dynamic Host Configuration Protocol Daemon (JDHCPD) process on Junos OS or Junos OS Evolved which is configured in relay mode it vulnerable to an attacker sending crafted IPv4 packets who may then arbi…
- CVE-2020-1609HIGHCVSS 8.8EG 8.82020-01-15
When a device using Juniper Network's Dynamic Host Configuration Protocol Daemon (JDHCPD) process on Junos OS or Junos OS Evolved which is configured in relay mode it vulnerable to an attacker sending crafted IPv6 packets who may then arbi…
- CVE-2020-16147CRITICALCVSS 9.8EG 9.82020-09-24
The login page in Telmat AccessLog <= 6.0 (TAL_20180415) allows an attacker to get root shell access via Unauthenticated code injection over the network.
- CVE-2020-16148HIGHCVSS 7.2EG 7.22020-09-24
The ping page of the administration panel in Telmat AccessLog <= 6.0 (TAL_20180415) allows an attacker to get root shell access via authenticated code injection over the network.
- CVE-2020-16205HIGHCVSS 7.2EG 8.22020-08-14
Using a specially crafted URL command, a remote authenticated user can execute commands as root on the G-Cam and G-Code (Firmware Versions 1.12.0.25 and prior as well as the limited Versions 1.12.13.2 and 1.12.14.5).
- CVE-2020-16257CRITICALCVSS 9.8EG 9.82020-10-28
Winston 1.5.4 devices are vulnerable to command injection via the API.
- CVE-2020-16279CRITICALCVSS 9.8EG 9.82020-08-20
The Kommbox component in Rangee GmbH RangeeOS 8.0.4 is vulnerable to Remote Code Execution due to untrusted user supplied input being passed to the command line without sanitization.
- CVE-2020-16282HIGHCVSS 8.8EG 8.82020-08-20
In the default configuration of Rangee GmbH RangeeOS 8.0.4, all components are executed in the context of the privileged root user. This may allow a local attacker to break out of the restricted environment or inject malicious code into th…
- CVE-2020-16846CRITICALCVSS 9.8EG 9.8⚠ KEV2020-11-06
An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection.
- CVE-2020-17010HIGHCVSS 7.8EG 7.82020-11-11
Win32k Elevation of Privilege Vulnerability
- CVE-2020-1734HIGHCVSS 7.4EG 7.42020-03-03
A flaw was found in the pipe lookup plugin of ansible. Arbitrary commands can be run, when the pipe lookup plugin uses subprocess.Popen() with shell=True, by overwriting ansible facts and the variable is not escaped by quote plugin. An att…
- CVE-2020-17352HIGHCVSS 8.8EG 8.82020-08-07
Two OS command injection vulnerabilities in the User Portal of Sophos XG Firewall through 2020-08-05 potentially allow an authenticated attacker to remotely execute arbitrary code.
- CVE-2020-17363CRITICALCVSS 9.9EG 9.92020-12-31
USVN (aka User-friendly SVN) before 1.0.9 allows remote code execution via shell metacharacters in the number_start or number_end parameter to LastHundredRequest (aka lasthundredrequestAction) in the Timeline module. NOTE: this may overlap…
- CVE-2020-17367HIGHCVSS 7.8EG 7.82020-08-11
Firejail through 0.9.62 does not honor the -- end-of-options indicator after the --output option, which may lead to command injection.
- CVE-2020-17368CRITICALCVSS 9.8EG 9.82020-08-11
Firejail through 0.9.62 mishandles shell metacharacters during use of the --output or --output-stderr option, which may lead to command injection.
- CVE-2020-17384HIGHCVSS 7.2EG 7.22020-08-25
Cellopoint CelloOS v4.1.10 Build 20190922 does not validate URL inputted properly. With the cookie of the system administrator, attackers can inject and remotely execute arbitrary command to manipulate the system.
- CVE-2020-17406HIGHCVSS 8.8EG 8.82020-10-13
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microhard Bullet-LTE prior to v1.2.0-r1112. Authentication is required to exploit this vulnerability. The specific flaw exists within the han…
- CVE-2020-17456CRITICALCVSS 9.8EG 9.82020-08-20
SEOWON INTECH SLC-130 And SLR-120S devices allow Remote Code Execution via the ipAddr parameter to the system_log.cgi page.
- CVE-2020-17505CRITICALCVSS 8.8EG 9.02020-08-12
Artica Web Proxy 4.30.000000 allows an authenticated remote attacker to inject commands via the service-cmds parameter in cyrus.php. These commands are executed with root privileges via service_cmds_peform.
- CVE-2020-18568CRITICALCVSS 9.8EG 9.82021-02-02
The D-Link DSR-250 (3.14) DSR-1000N (2.11B201) UPnP service contains a command injection vulnerability, which can cause remote command execution.
- CVE-2020-19142CRITICALCVSS 9.8EG 9.82020-12-10
iCMS 7 attackers to execute arbitrary OS commands via shell metacharacters in the DB_PREFIX parameter to install/install.php.
- CVE-2020-1930HIGHCVSS 8.1EG 8.12020-01-30
A command execution issue was found in Apache SpamAssassin prior to 3.4.3. Carefully crafted nefarious rule configuration (.cf) files can be configured to run system commands similar to CVE-2018-11805. With this bug unpatched, exploits can…
- CVE-2020-1931HIGHCVSS 8.1EG 8.12020-01-30
A command execution issue was found in Apache SpamAssassin prior to 3.4.3. Carefully crafted nefarious Configuration (.cf) files can be configured to run system commands similar to CVE-2018-11805. This issue is less stealthy and attempts t…
- CVE-2020-19316HIGHCVSS 8.8EG 8.82021-12-20
OS Command injection vulnerability in function link in Filesystem.php in Laravel Framework before 5.8.17.
- CVE-2020-1946CRITICALCVSS 9.8EG 9.82021-03-25
In Apache SpamAssassin before 3.4.5, malicious rule configuration (.cf) files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to …
- CVE-2020-19527CRITICALCVSS 9.8EG 9.82020-12-10
iCMS 7.0.14 attackers to execute arbitrary OS commands via shell metacharacters in the DB_NAME parameter to install/install.php.
- CVE-2020-1956CRITICALCVSS 8.8EG 9.0⚠ KEV2020-05-22
Apache Kylin 2.3.0, and releases up to 2.6.5 and 3.0.1 has some restful apis which will concatenate os command with the user input string, a user is likely to be able to execute any os command without any protection or validation.
- CVE-2020-19664HIGHCVSS 8.8EG 8.82020-12-31
DrayTek Vigor2960 1.5.1 allows remote command execution via shell metacharacters in a toLogin2FA action to mainfunction.cgi.
- CVE-2020-1980HIGHCVSS 7.8EG 7.82020-03-11
A shell command injection vulnerability in the PAN-OS CLI allows a local authenticated user to escape the restricted shell and escalate privileges. This issue affects only PAN-OS 8.1 versions earlier than PAN-OS 8.1.13. This issue does not…
- CVE-2020-19907HIGHCVSS 8.8EG 8.82021-07-12
A command injection vulnerability in the sandcat plugin of Caldera 2.3.1 and earlier allows authenticated attackers to execute any command or service.
- CVE-2020-2000HIGHCVSS 7.2EG 7.22020-11-12
An OS command injection and memory corruption vulnerability in the PAN-OS management web interface that allows authenticated administrators to disrupt system processes and potentially execute arbitrary code and OS commands with root privil…
- CVE-2020-2007HIGHCVSS 7.2EG 7.22020-05-13
An OS command injection vulnerability in the management server component of PAN-OS allows an authenticated user to potentially execute arbitrary commands with root privileges. This issue affects: All PAN-OS 7.1 versions; PAN-OS 8.1 version…
- CVE-2020-2008HIGHCVSS 7.2EG 7.22020-05-13
An OS command injection and external control of filename vulnerability in Palo Alto Networks PAN-OS allows authenticated administrators to execute code with root privileges or delete arbitrary system files and impact the system's integrity…
- CVE-2020-2010HIGHCVSS 7.2EG 7.22020-05-13
An OS command injection vulnerability in PAN-OS management interface allows an authenticated administrator to execute arbitrary OS commands with root privileges. This issue affects: All versions of PAN-OS 7.1 and 8.0; PAN-OS 8.1 versions e…
- CVE-2020-2014HIGHCVSS 8.8EG 8.82020-05-13
An OS Command Injection vulnerability in PAN-OS management server allows authenticated users to inject and execute arbitrary shell commands with root privileges. This issue affects: All versions of PAN-OS 7.1 and 8.0; PAN-OS 8.1 versions e…
- CVE-2020-20184CRITICALCVSS 9.8EG 9.82020-12-14
GateOne allows remote attackers to execute arbitrary commands via shell metacharacters in the port field when attempting an SSH connection.
- CVE-2020-2028HIGHCVSS 7.2EG 7.22020-06-10
An OS Command Injection vulnerability in PAN-OS management server allows authenticated administrators to execute arbitrary OS commands with root privileges when uploading a new certificate in FIPS-CC mode. This issue affects: All versions …
- CVE-2020-2029HIGHCVSS 7.2EG 7.22020-06-10
An OS Command Injection vulnerability in the PAN-OS web management interface allows authenticated administrators to execute arbitrary OS commands with root privileges by sending a malicious request to generate new certificates for use in t…
- CVE-2020-2030HIGHCVSS 7.2EG 7.22020-07-08
An OS Command Injection vulnerability in the PAN-OS management interface that allows authenticated administrators to execute arbitrary OS commands with root privileges. This issue impacts PAN-OS 8.1 versions earlier than PAN-OS 8.1.15; and…
- CVE-2020-2034HIGHCVSS 8.1EG 8.12020-07-08
An OS Command Injection vulnerability in the PAN-OS GlobalProtect portal allows an unauthenticated network based attacker to execute arbitrary OS commands with root privileges. An attacker requires some knowledge of the firewall to exploit…
- CVE-2020-2037HIGHCVSS 7.2EG 7.22020-09-09
An OS Command Injection vulnerability in the PAN-OS management interface that allows authenticated administrators to execute arbitrary OS commands with root privileges. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS 8.1.16; PA…
- CVE-2020-2038CRITICALCVSS 7.2EG 9.02020-09-09
An OS Command Injection vulnerability in the PAN-OS management interface that allows authenticated administrators to execute arbitrary OS commands with root privileges. This issue impacts: PAN-OS 9.0 versions earlier than 9.0.10; PAN-OS 9.…
- CVE-2020-21583MEDIUMCVSS 6.7EG 6.72023-08-22
An issue was discovered in hwclock.13-v2.27 allows attackers to gain escalated privlidges or execute arbitrary commands via the path parameter when setting the date.
- CVE-2020-2159HIGHCVSS 8.8EG 8.82020-03-09
Jenkins CryptoMove Plugin 0.1.33 and earlier allows attackers with Job/Configure access to execute arbitrary OS commands on the Jenkins master as the OS user account running Jenkins.
- CVE-2020-21883HIGHCVSS 8.8EG 8.82021-04-09
Unibox U-50 2.4 and UniBox Enterprise Series 2.4 and UniBox Campus Series 2.4 contain a OS command injection vulnerability in /tools/ping, which can leads to complete device takeover.
Map vulnerabilities like CWE-78 to your infrastructure
EchelonGraph correlates every CVE — across CWE-78 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →