CWE-78— OS Command Injection
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.— MITRE CWE catalog
6,262 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-78page 36 of 126
- CVE-2020-7619CRITICALCVSS 9.8EG 9.82020-04-02
get-git-data through 1.3.1 is vulnerable to Command Injection. It is possible to inject arbitrary commands as part of the arguments provided to get-git-data.
- CVE-2020-7620CRITICALCVSS 9.8EG 9.82020-04-02
pomelo-monitor through 0.3.7 is vulnerable to Command Injection.It allows injection of arbitrary commands as part of 'pomelo-monitor' params.
- CVE-2020-7621CRITICALCVSS 9.8EG 9.82020-04-02
strong-nginx-controller through 1.0.2 is vulnerable to Command Injection. It allows execution of arbitrary command as part of the '_nginxCmd()' function.
- CVE-2020-7623CRITICALCVSS 9.8EG 9.82020-04-02
jscover through 1.0.0 is vulnerable to Command Injection. It allows execution of arbitrary command via the source argument.
- CVE-2020-7624CRITICALCVSS 9.8EG 9.82020-04-02
effect through 1.0.4 is vulnerable to Command Injection. It allows execution of arbitrary command via the options argument.
- CVE-2020-7625CRITICALCVSS 9.8EG 9.82020-04-02
op-browser through 1.0.6 is vulnerable to Command Injection. It allows execution of arbitrary commands via the url function.
- CVE-2020-7626CRITICALCVSS 9.8EG 9.82020-04-02
karma-mojo through 1.0.1 is vulnerable to Command Injection. It allows execution of arbitrary commands via the config argument.
- CVE-2020-7627CRITICALCVSS 9.8EG 9.82020-04-02
node-key-sender through 1.0.11 is vulnerable to Command Injection. It allows execution of arbitrary commands via the 'arrParams' argument in the 'execute()' function.
- CVE-2020-7628CRITICALCVSS 9.8EG 9.82020-04-02
umount through 1.1.6 is vulnerable to Command Injection. The argument device can be controlled by users without any sanitization.
- CVE-2020-7629CRITICALCVSS 9.8EG 9.82020-04-02
install-package through 0.4.0 is vulnerable to Command Injection. It allows execution of arbitrary commands via the options argument.
- CVE-2020-7630CRITICALCVSS 9.8EG 9.82020-04-02
git-add-remote through 1.0.0 is vulnerable to Command Injection. It allows execution of arbitrary commands via the name argument.
- CVE-2020-7631CRITICALCVSS 9.8EG 9.82020-04-06
diskusage-ng through 0.2.4 is vulnerable to Command Injection.It allows execution of arbitrary commands via the path argument.
- CVE-2020-7632CRITICALCVSS 9.8EG 9.82020-04-06
node-mpv through 1.4.3 is vulnerable to Command Injection. It allows execution of arbitrary commands via the options argument.
- CVE-2020-7633CRITICALCVSS 9.8EG 9.82020-04-06
apiconnect-cli-plugins through 6.0.1 is vulnerable to Command Injection.It allows execution of arbitrary commands via the pluginUri argument.
- CVE-2020-7634CRITICALCVSS 9.8EG 9.82020-04-06
heroku-addonpool through 0.1.15 is vulnerable to Command Injection.
- CVE-2020-7635CRITICALCVSS 9.8EG 9.82020-04-06
compass-compile through 0.0.1 is vulnerable to Command Injection.It allows execution of arbitrary commands via tha options argument.
- CVE-2020-7636CRITICALCVSS 9.8EG 9.82020-04-06
adb-driver through 0.1.8 is vulnerable to Command Injection.It allows execution of arbitrary commands via the command function.
- CVE-2020-7640CRITICALCVSS 9.8EG 9.82020-04-27
pixl-class prior to 1.0.3 allows execution of arbitrary commands. The members argument of the create function can be controlled by users without any sanitization.
- CVE-2020-7645CRITICALCVSS 9.8EG 9.82020-05-02
All versions of chrome-launcher allow execution of arbitrary commands, by controlling the $HOME environment variable in Linux operating systems.
- CVE-2020-7646CRITICALCVSS 9.8EG 9.82020-05-07
curlrequest through 1.0.1 allows reading any file by populating the file parameter with user input.
- CVE-2020-7688HIGHCVSS 8.4EG 8.42020-07-01
The issue occurs because tagName user input is formatted inside the exec function is executed without any checks.
- CVE-2020-7698HIGHCVSS 8.1EG 8.12020-07-29
This affects the package Gerapy from 0 and before 0.9.3. The input being passed to Popen, via the project_configure endpoint, isn’t being sanitized.
- CVE-2020-7712HIGHCVSS 7.2EG 7.22020-08-30
This affects the package json before 10.0.0. It is possible to inject arbritary commands using the parseLookup function.
- CVE-2020-7730CRITICALCVSS 9.8EG 9.82020-09-04
The package bestzip before 2.1.7 are vulnerable to Command Injection via the options param.
- CVE-2020-7735MEDIUMCVSS 6.6EG 6.62020-09-25
The package ng-packagr before 10.1.1 are vulnerable to Command Injection via the styleIncludePaths option.
- CVE-2020-7752HIGHCVSS 8.8EG 8.82020-10-26
This affects the package systeminformation before 4.27.11. This package is vulnerable to Command Injection. The attacker can concatenate curl's parameters to overwrite Javascript files and then execute any OS commands.
- CVE-2020-7775CRITICALCVSS 9.8EG 9.82021-02-02
This affects all versions of package freediskspace. The vulnerability arises out of improper neutralization of arguments in line 71 of freediskspace.js.
- CVE-2020-7778HIGHCVSS 7.3EG 7.32020-11-26
This affects the package systeminformation before 4.30.2. The attacker can overwrite the properties and functions of an object, which can lead to executing OS commands.
- CVE-2020-7781CRITICALCVSS 9.8EG 9.82020-12-16
This affects the package connection-tester before 0.2.1. The injection point is located in line 15 in index.js. The following PoC demonstrates the vulnerability:
- CVE-2020-7782CRITICALCVSS 9.8EG 9.82021-02-08
This affects all versions of package spritesheet-js. It depends on a vulnerable package platform-command. The injection point is located in line 32 in lib/generator.js, which is triggered by main entry of the package.
- CVE-2020-7784CRITICALCVSS 9.8EG 9.82021-01-08
This affects all versions of package ts-process-promises. The injection point is located in line 45 in main entry of package in lib/process-promises.js. The vulnerability is demonstrated with the following PoC:
- CVE-2020-7785CRITICALCVSS 9.8EG 9.82021-02-08
This affects all versions of package node-ps. The injection point is located in line 72 in lib/index.js.
- CVE-2020-7786CRITICALCVSS 9.8EG 9.82021-02-08
This affects all versions of package macfromip. The injection point is located in line 66 in macfromip.js.
- CVE-2020-7789MEDIUMCVSS 5.6EG 5.62020-12-11
This affects the package node-notifier before 9.0.0. It allows an attacker to run arbitrary commands on Linux machines due to the options params not being sanitised when being passed an array.
- CVE-2020-7794CRITICALCVSS 9.8EG 9.82021-01-08
This affects all versions of package buns. The injection point is located in line 678 in index file lib/index.js in the exported function install(requestedModule).
- CVE-2020-7804MEDIUMCVSS 6.4EG 6.42020-04-29
ActiveX Control(HShell.dll) in Handy Groupware 1.7.3.1 for Windows 7, 8, and 10 allows an attacker to execute arbitrary command via the ShellExec method.
- CVE-2020-7805CRITICALCVSS 9.8EG 9.82020-05-07
An issue was discovered on KT Slim egg IML500 (R7283, R8112, R8424) and IML520 (R8112, R8368, R8411) wifi device. This issue is a command injection allowing attackers to execute arbitrary OS commands.
- CVE-2020-7825HIGHCVSS 8.8EG 8.82020-07-17
A vulnerability exists that could allow the execution of operating system commands on systems running MiPlatform 2019.05.16 and earlier. An attacker could execute arbitrary remote command by sending parameters to WinExec function in ExtCom…
- CVE-2020-7879HIGHCVSS 8.8EG 8.82021-11-30
This issue was discovered when the ipTIME C200 IP Camera was synchronized with the ipTIME NAS. It is necessary to extract value for ipTIME IP camera because the ipTIME NAS send ans setCookie('[COOKIE]') . The value is transferred to the --…
- CVE-2020-7980CRITICALCVSS 9.8EG 9.82020-01-25
Intellian Aptus Web 1.24 allows remote attackers to execute arbitrary OS commands via the Q field within JSON data to the cgi-bin/libagent.cgi URI. NOTE: a valid sid cookie for a login to the intellian default account might be needed.
- CVE-2020-8007CRITICALCVSS 9.8EG 9.82024-11-08
The pwrstudio web application of EV Charger (in the server in Circontrol Raption through 5.6.2) is vulnerable to OS command injection via three fields of the configuration menu for ntpserver0, ntpserver1, and pingip.
- CVE-2020-8105CRITICALCVSS 9.6EG 9.62021-12-20
OS Command Injection vulnerability in the wirelessConnect handler of Abode iota All-In-One Security Kit allows an attacker to inject commands and gain root access. This issue affects: Abode iota All-In-One Security Kit versions prior to 1.…
- CVE-2020-8126HIGHCVSS 7.8EG 7.82020-02-07
A privilege escalation in the EdgeSwitch prior to version 1.7.1, an CGI script don't fully sanitize the user input resulting in local commands execution, allowing an operator user (Privilege-1) to escalate privileges and became administrat…
- CVE-2020-8130MEDIUMCVSS 6.4EG 6.42020-02-24
There is an OS command injection vulnerability in Ruby Rake < 12.3.3 in Rake::FileList when supplying a filename that begins with the pipe character `|`.
- CVE-2020-8171CRITICALCVSS 9.8EG 9.82020-05-26
We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilities found on AirMax AirOS v6.2.0 and prior TI, XW and XM boards, according to the description below:There are certain end…
- CVE-2020-8178CRITICALCVSS 9.8EG 9.82020-07-15
Insufficient input validation in npm package `jison` <= 0.4.18 may lead to OS command injection attacks.
- CVE-2020-8186CRITICALCVSS 9.8EG 9.82020-07-10
A command injection vulnerability in the `devcert` module may lead to remote code execution when users of the module pass untrusted input to the `certificateFor` function.
- CVE-2020-8188HIGHCVSS 8.8EG 8.82020-07-02
We have recently released new version of UniFi Protect firmware v1.13.3 and v1.14.10 for Unifi Cloud Key Gen2 Plus and UniFi Dream Machine Pro/UNVR respectively that fixes vulnerabilities found on Protect firmware v1.13.2, v1.14.9 and prio…
- CVE-2020-8233HIGHCVSS 8.8EG 8.82020-08-17
A command injection vulnerability exists in EdgeSwitch firmware <v1.9.0 that allowed an authenticated read-only user to execute arbitrary shell commands over the HTTP interface, allowing them to escalate privileges.
- CVE-2020-8270HIGHCVSS 8.8EG 8.82020-11-16
An unprivileged Windows user on the VDA or an SMB user can perform arbitrary command execution as SYSTEM in CVAD versions before 2009, 1912 LTSR CU1 hotfixes CTX285871 and CTX285872, 7.15 LTSR CU6 hotfix CTX285341 and CTX285342
Map vulnerabilities like CWE-78 to your infrastructure
EchelonGraph correlates every CVE — across CWE-78 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →