CWE-78— OS Command Injection
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.— MITRE CWE catalog
6,262 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-78page 43 of 126
- CVE-2021-31799HIGHCVSS 7.0EG 7.02021-07-30
In RDoc 3.11 through 6.x before 6.3.1, as distributed with Ruby through 3.0.1, it is possible to execute arbitrary code via | and tags in a filename.
- CVE-2021-31838CRITICALCVSS 8.4EG 9.12021-06-29
A command injection vulnerability in MVISION EDR (MVEDR) prior to 3.4.0 allows an authenticated MVEDR administrator to trigger the EDR client to execute arbitrary commands through PowerShell using the EDR functionality 'execute reaction'.
- CVE-2021-31854HIGHCVSS 7.7EG 7.82022-01-19
A command Injection Vulnerability in McAfee Agent (MA) for Windows prior to 5.7.5 allows local users to inject arbitrary shell code into the file cleanup.exe. The malicious clean.exe file is placed into the relevant folder and executed by …
- CVE-2021-31891CRITICALCVSS 10.0EG 10.02021-09-14
A vulnerability has been identified in Desigo CC (All versions with OIS Extension Module), GMA-Manager (All versions with OIS running on Debian 9 or earlier), Operation Scheduler (All versions with OIS running on Debian 9 or earlier), Sive…
- CVE-2021-3190CRITICALCVSS 9.8EG 9.82021-01-26
The async-git package before 1.13.2 for Node.js allows OS Command Injection via shell metacharacters, as demonstrated by git.reset and git.tag.
- CVE-2021-31915CRITICALCVSS 9.8EG 9.82021-05-11
In JetBrains TeamCity before 2020.2.4, OS command injection leading to remote code execution was possible.
- CVE-2021-3198MEDIUMCVSS 6.5EG 6.52021-07-22
By abusing the 'install rpm url' command, an attacker can escape the restricted clish shell on affected versions of Ivanti MobileIron Core. This issue was fixed in version 11.1.0.0.
- CVE-2021-32090CRITICALCVSS 9.8EG 9.82021-05-07
The dashboard component of StackLift LocalStack 0.12.6 allows attackers to inject arbitrary shell commands via the functionName parameter.
- CVE-2021-32305CRITICALCVSS 9.8EG 9.82021-05-18
WebSVN before 2.6.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search parameter.
- CVE-2021-32475MEDIUMCVSS 5.4EG 5.42022-03-11
ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk. Moodle 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, 3.5 to 3.5.17 and earlier unsupported versions are affected.
- CVE-2021-32512CRITICALCVSS 9.8EG 9.82021-07-07
QuickInstall in QSAN Storage Manager does not filter special parameters properly that allows remote unauthenticated attackers to inject and execute arbitrary commands. The referred vulnerability has been solved with the updated version of …
- CVE-2021-32513CRITICALCVSS 9.8EG 9.82021-07-07
QsanTorture in QSAN Storage Manager does not filter special parameters properly that allows remote unauthenticated attackers to inject and execute arbitrary commands. The referred vulnerability has been solved with the updated version of Q…
- CVE-2021-32524CRITICALCVSS 9.1EG 9.12021-07-07
Command injection vulnerability in QSAN Storage Manager allows remote privileged users to execute arbitrary commands. Suggest contacting with QSAN and refer to recommendations in QSAN Document.
- CVE-2021-32530CRITICALCVSS 9.8EG 9.82021-07-07
OS command injection vulnerability in Array function in QSAN XEVO allows remote unauthenticated attackers to execute arbitrary commands via status parameter. The referred vulnerability has been solved with the updated version of QSAN XEVO …
- CVE-2021-32531CRITICALCVSS 9.8EG 9.82021-07-07
OS command injection vulnerability in Init function in QSAN XEVO allows remote attackers to execute arbitrary commands without permissions. The referred vulnerability has been solved with the updated version of QSAN XEVO v2.1.0.
- CVE-2021-32533CRITICALCVSS 9.8EG 9.82021-07-07
The QSAN SANOS setting page does not filter special parameters. Remote attackers can use this vulnerability to inject and execute arbitrary commands without permissions. The referred vulnerability has been solved with the updated version o…
- CVE-2021-32534CRITICALCVSS 9.8EG 9.82021-07-07
QSAN SANOS factory reset function does not filter special parameters. Remote attackers can use this vulnerability to inject and execute arbitrary commands without permissions. The referred vulnerability has been solved with the updated ver…
- CVE-2021-32556LOWCVSS 3.8EG 3.82021-06-12
It was discovered that the get_modified_conffiles() function in backends/packaging-apt-dpkg.py allowed injecting modified package names in a manner that would confuse the dpkg(1) call.
- CVE-2021-32605CRITICALCVSS 9.8EG 9.82021-05-11
zzzcms zzzphp before 2.0.4 allows remote attackers to execute arbitrary OS commands by placing them in the keys parameter of a ?location=search URI, as demonstrated by an OS command within an "if" "end if" block.
- CVE-2021-32673HIGHCVSS 8.8EG 8.82021-06-08
reg-keygen-git-hash-plugin is a reg-suit plugin to detect the snapshot key to be compare with using Git commit hash. reg-keygen-git-hash-plugin through and including 0.10.15 allow remote attackers to execute of arbitrary commands. Upgrade …
- CVE-2021-32682CRITICALCVSS 9.8EG 9.82021-06-14
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Several vulnerabilities affect elFinder 2.1.58. These vulnerabilities can allow an attacker to execute arbitrary code and commands on the server hostin…
- CVE-2021-32692CRITICALCVSS 9.6EG 9.62022-12-23
Activity Watch is a free and open-source automated time tracker. Versions prior to 0.11.0 allow an attacker to execute arbitrary commands on any macOS machine with ActivityWatch running. The attacker can exploit this vulnerability by havin…
- CVE-2021-32749MEDIUMCVSS 6.1EG 6.12021-07-16
fail2ban is a daemon to ban hosts that cause multiple authentication errors. In versions 0.9.7 and prior, 0.10.0 through 0.10.6, and 0.11.0 through 0.11.2, there is a vulnerability that leads to possible remote code execution in the mailin…
- CVE-2021-32751HIGHCVSS 7.5EG 7.52021-07-20
Gradle is a build tool with a focus on build automation. In versions prior to 7.2, start scripts generated by the `application` plugin and the `gradlew` script are both vulnerable to arbitrary code execution when an attacker is able to cha…
- CVE-2021-32772HIGHCVSS 8.8EG 8.82021-08-03
Poddycast is a podcast app made with Electron. Prior to version 0.8.1, an attacker can create a podcast or episode with malicious characters and execute commands on the client machine. The application does not clean the HTML characters of …
- CVE-2021-32826MEDIUMCVSS 6.8EG 6.82021-08-16
Proxyee-Down is open source proxy software. An attacker being able to provide an extension script (eg: through a MiTM attack or by hosting a malicious extension) may be able to run arbitrary commands on the system running Proxyee-Down. For…
- CVE-2021-32830LOWCVSS 3.9EG 3.92021-08-17
The @diez/generation npm package is a client for Diez. The locateFont method of @diez/generation has a command injection vulnerability. Clients of the @diez/generation library are unlikely to be aware of this, so they might unwittingly wri…
- CVE-2021-32849HIGHCVSS 8.8EG 8.82022-01-26
Gerapy is a distributed crawler management framework. Prior to version 0.9.9, an authenticated user could execute arbitrary commands. This issue is fixed in version 0.9.9. There are no known workarounds.
- CVE-2021-3291HIGHCVSS 7.2EG 7.22021-01-26
Zen Cart 1.5.7b allows admins to execute arbitrary OS commands by inspecting an HTML radio input element (within the modules edit page) and inserting a command.
- CVE-2021-32933CRITICALCVSS 10.0EG 10.02022-04-01
An attacker could leverage an API to pass along a malicious file that could then manipulate the process creation command line in MDT AutoSave versions prior to v6.02.06 and run a command line argument. This could then be leveraged to run a…
- CVE-2021-32974CRITICALCVSS 9.8EG 9.82022-04-01
Improper input validation in the built-in web server in Moxa NPort IAW5000A-I/O series firmware version 2.2 or earlier may allow a remote attacker to execute commands.
- CVE-2021-33032CRITICALCVSS 10.0EG 10.02021-07-22
A Remote Code Execution (RCE) vulnerability in the WebUI component of the eQ-3 HomeMatic CCU2 firmware up to and including version 2.57.5 and CCU3 firmware up to and including version 3.57.5 allows remote unauthenticated attackers to execu…
- CVE-2021-33055CRITICALCVSS 9.8EG 9.82021-08-30
Zoho ManageEngine ADSelfService Plus through 6102 allows unauthenticated remote code execution in non-English editions.
- CVE-2021-3317HIGHCVSS 8.8EG 8.82021-01-26
KLog Server through 2.4.1 allows authenticated command injection. async.php calls shell_exec() on the original value of the source parameter.
- CVE-2021-33191CRITICALCVSS 9.8EG 9.82021-08-24
From Apache NiFi MiNiFi C++ version 0.5.0 the c2 protocol implements an "agent-update" command which was designed to patch the application binary. This "patching" command defaults to calling a trusted binary, but might be modified to an ar…
- CVE-2021-33357CRITICALCVSS 9.8EG 9.82021-06-09
A vulnerability exists in RaspAP 2.6 to 2.6.5 in the "iface" GET parameter in /ajax/networking/get_netcfg.php, when the "iface" parameter value contains special characters such as ";" which enables an unauthenticated attacker to execute ar…
- CVE-2021-33358HIGHCVSS 8.8EG 8.82021-06-09
Multiple vulnerabilities exist in RaspAP 2.3 to 2.6.5 in the "interface", "ssid" and "wpa_passphrase" POST parameters in /hostapd, when the parameter values contain special characters such as ";" or "$()" which enables an authenticated att…
- CVE-2021-3342CRITICALCVSS 9.8EG 9.82021-03-01
EPrints 3.4.2 allows remote attackers to read arbitrary files and possibly execute commands via crafted LaTeX input to a cgi/latex2png?latex= URI.
- CVE-2021-33514HIGHCVSS 8.8EG 8.82021-05-21
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker via the vulnerable /sqfs/lib/libsal.so.0.0 library used by a CGI application, as demonstrated by setup.cgi?token=';$HTTP_USER_AGENT;' with an OS comma…
- CVE-2021-33525HIGHCVSS 8.8EG 8.82021-05-24
EyesOfNetwork eonweb through 5.3-11 allows Remote Command Execution (by authenticated users) via shell metacharacters in the nagios_path parameter to lilac/export.php, as demonstrated by %26%26+curl to insert an "&& curl" substring for the…
- CVE-2021-33530HIGHCVSS 8.8EG 8.82021-06-25
In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in encrypted diagnostic script functionality of the devices. A specially crafted diagnostic script file can cause arbitrary b…
- CVE-2021-33532HIGHCVSS 8.8EG 8.82021-06-25
In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in the iw_webs functionality. A specially crafted diagnostic script file name can cause user input to be reflected in a subse…
- CVE-2021-33533HIGHCVSS 8.8EG 8.82021-06-25
In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in the iw_webs functionality. A specially crafted iw_serverip parameter can cause user input to be reflected in a subsequent …
- CVE-2021-33534HIGHCVSS 7.2EG 7.22021-06-25
In Weidmueller Industrial WLAN devices in multiple versions an exploitable command injection vulnerability exists in the hostname functionality. A specially crafted entry to network configuration information can cause execution of arbitrar…
- CVE-2021-33544CRITICALCVSS 7.2EG 9.02021-09-13
Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.
- CVE-2021-33548HIGHCVSS 7.2EG 8.12021-09-13
Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.
- CVE-2021-33550HIGHCVSS 7.2EG 8.12021-09-13
Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.
- CVE-2021-33551HIGHCVSS 7.2EG 7.82021-09-13
Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.
- CVE-2021-33552HIGHCVSS 7.2EG 7.82021-09-13
Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.
- CVE-2021-33553HIGHCVSS 7.2EG 7.82021-09-13
Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.
Map vulnerabilities like CWE-78 to your infrastructure
EchelonGraph correlates every CVE — across CWE-78 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →