CWE-78— OS Command Injection
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.— MITRE CWE catalog
6,262 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-78page 44 of 126
- CVE-2021-33554HIGHCVSS 7.2EG 8.12021-09-13
Multiple camera devices by UDP Technology, Geutebrück and other vendors are vulnerable to command injection, which may allow an attacker to remotely execute arbitrary code.
- CVE-2021-33633HIGHCVSS 7.3EG 7.32024-03-23
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in openEuler aops-ceres on Linux allows Command Injection. This vulnerability is associated with program files ceres/function/util.Py.…
- CVE-2021-33721HIGHCVSS 7.2EG 7.22021-08-10
A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2). The affected application incorrectly neutralizes special elements when creating batch operations which could lead to command injection. An authenticated remote att…
- CVE-2021-33827HIGHCVSS 7.2EG 7.22022-01-15
The files_antivirus component before 1.0.0 for ownCloud allows OS Command Injection via the administration settings.
- CVE-2021-33841CRITICALCVSS 10.0EG 10.02021-06-09
SGE-PLC1000 device, in its 0.9.2b firmware version, does not handle some requests correctly, allowing a remote attacker to inject code into the operating system with maximum privileges.
- CVE-2021-33962CRITICALCVSS 9.8EG 9.82022-01-14
China Mobile An Lianbao WF-1 router v1.0.1 is affected by an OS command injection vulnerability in the web interface /api/ZRUsb/pop_usb_device component.
- CVE-2021-33990CRITICALCVSS 9.8EG 9.82023-04-16
Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists. NOTE: The vendor disputes this issue because the exploit reference link only shows frmfolders.html is accessible and does not de…
- CVE-2021-34078HIGHCVSS 8.8EG 8.82022-06-02
lifion-verify-dependencies through 1.1.0 is vulnerable to OS command injection via a crafted dependency name on the scanned project's package.json file.
- CVE-2021-34079CRITICALCVSS 9.8EG 9.82022-06-02
OS Command injection vulnerability in Mintzo Docker-Tester through 1.2.1 allows attackers to execute arbitrary commands via shell metacharacters in the 'ports' entry of a crafted docker-compose.yml file.
- CVE-2021-34080CRITICALCVSS 9.8EG 9.82022-06-02
OS Command Injection vulnerability in es128 ssl-utils 1.0.0 for Node.js allows attackers to execute arbitrary commands via unsanitized shell metacharacters provided to the createCertRequest() and the createCert() functions.
- CVE-2021-34081HIGHCVSS 8.8EG 8.82022-06-02
OS Command Injection vulnerability in bbultman gitsome through 0.2.3 allows attackers to execute arbitrary commands via a crafted tag name of the target git repository.
- CVE-2021-34082CRITICALCVSS 9.8EG 9.82022-06-02
OS Command Injection vulnerability in allenhwkim proctree through 0.1.1 and commit 0ac10ae575459457838f14e21d5996f2fa5c7593 for Node.js, allows attackers to execute arbitrary commands via the fix function.
- CVE-2021-34083HIGHCVSS 8.1EG 8.12022-06-02
Google-it is a Node.js package which allows its users to send search queries to Google and receive the results in a JSON format. When using the 'Open in browser' option in versions up to 1.6.2, google-it will unsafely concat the result's l…
- CVE-2021-34084CRITICALCVSS 9.8EG 9.82022-06-02
OS command injection vulnerability in Turistforeningen node-s3-uploader through 2.0.3 for Node.js allows attackers to execute arbitrary commands via the metadata() function.
- CVE-2021-34111CRITICALCVSS 9.8EG 9.82022-05-20
Thecus 4800Eco was discovered to contain a command injection vulnerability via the username parameter in /adm/setmain.php.
- CVE-2021-34348CRITICALCVSS 9.8EG 9.82021-09-27
A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability could allow remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following versi…
- CVE-2021-34349HIGHCVSS 7.2EG 7.22021-09-27
A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability could allow remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following versi…
- CVE-2021-34351CRITICALCVSS 9.8EG 9.82021-09-27
A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability could allow remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following versi…
- CVE-2021-34352HIGHCVSS 7.2EG 7.22021-10-01
A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability could allow remote attackers to run arbitrary commands. We have already fixed this vulnerability in the following versi…
- CVE-2021-34362HIGHCVSS 8.7EG 8.72021-10-22
A command injection vulnerability has been reported to affect QNAP device running Media Streaming add-on. If exploited, this vulnerability allow remote attackers to run arbitrary commands. We have already fixed this vulnerability in the fo…
- CVE-2021-3459MEDIUMCVSS 6.8EG 6.82021-08-17
A privilege escalation vulnerability was reported in the MM1000 device configuration web server, which could allow privileged shell access and/or arbitrary privileged commands to be executed on the adapter.
- CVE-2021-34602HIGHCVSS 8.8EG 8.82022-04-27
In Bender/ebee Charge Controllers in multiple versions are prone to Command injection via Web interface. An authenticated attacker could enter shell commands into some input fields that are executed with root privileges.
- CVE-2021-34610HIGHCVSS 7.2EG 7.22021-07-08
A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this security vulnerabili…
- CVE-2021-34611HIGHCVSS 7.2EG 7.22021-07-08
A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this security vulnerabili…
- CVE-2021-34612MEDIUMCVSS 6.3EG 6.32021-07-08
A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this security vulnerabili…
- CVE-2021-34613MEDIUMCVSS 6.3EG 6.32021-07-08
A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this security vulnerabili…
- CVE-2021-34614MEDIUMCVSS 6.3EG 6.32021-07-08
A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this security vulnerabili…
- CVE-2021-34615MEDIUMCVSS 6.3EG 6.32021-07-08
A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this security vulnerabili…
- CVE-2021-34616MEDIUMCVSS 6.3EG 6.32021-07-08
A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this security vulnerabili…
- CVE-2021-34710HIGHCVSS 8.8EG 8.82021-10-06
Multiple vulnerabilities in the Cisco ATA 190 Series Analog Telephone Adapter Software could allow an attacker to perform a command injection attack resulting in remote code execution or cause a denial of service (DoS) condition on an affe…
- CVE-2021-34719HIGHCVSS 7.8EG 7.82021-09-09
Multiple vulnerabilities in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker with a low-privileged account to elevate privileges on an affected device. For more information about these vulnerabilities, see the …
- CVE-2021-34721MEDIUMCVSS 6.7EG 6.72021-09-09
Multiple vulnerabilities in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to gain access to the underlying root shell of an affected device and execute arbitrary commands with root privileges. For more infor…
- CVE-2021-34722MEDIUMCVSS 6.7EG 6.72021-09-09
Multiple vulnerabilities in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to gain access to the underlying root shell of an affected device and execute arbitrary commands with root privileges. For more infor…
- CVE-2021-34725MEDIUMCVSS 6.7EG 6.72021-09-23
A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands to be executed with root-level privileges on the underlying operating system. This vulnerability is due to…
- CVE-2021-34726MEDIUMCVSS 6.7EG 6.72021-09-23
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands to be executed with root-level privileges on the underlying operating system of an affected device. This vulnerab…
- CVE-2021-34728HIGHCVSS 7.8EG 7.82021-09-09
Multiple vulnerabilities in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker with a low-privileged account to elevate privileges on an affected device. For more information about these vulnerabilities, see the …
- CVE-2021-34729MEDIUMCVSS 6.7EG 6.72021-09-23
A vulnerability in the CLI of Cisco IOS XE SD-WAN Software and Cisco IOS XE Software could allow an authenticated, local attacker to execute arbitrary commands with elevated privileges on an affected device. This vulnerability is due to in…
- CVE-2021-34748HIGHCVSS 8.8EG 8.82021-10-06
A vulnerability in the web-based management interface of Cisco Intersight Virtual Appliance could allow an authenticated, remote attacker to perform a command injection attack on an affected device. This vulnerability is due to insufficien…
- CVE-2021-34755HIGHCVSS 6.7EG 7.82021-10-27
Multiple vulnerabilities in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges. For more information about these vulnerabilities, see the…
- CVE-2021-34756HIGHCVSS 6.7EG 7.82021-10-27
Multiple vulnerabilities in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges. For more information about these vulnerabilities, see the…
- CVE-2021-35028HIGHCVSS 7.3EG 7.32021-09-29
A command injection vulnerability in the CGI program of the Zyxel VPN2S firmware version 1.12 could allow an authenticated, local user to execute arbitrary OS commands.
- CVE-2021-35031MEDIUMCVSS 6.8EG 6.82021-12-28
A vulnerability in the TFTP client of Zyxel GS1900 series firmware, XGS1210 series firmware, and XGS1250 series firmware, which could allow an authenticated LAN user to execute arbitrary OS commands via the GUI of the vulnerable device.
- CVE-2021-35032MEDIUMCVSS 6.4EG 6.42021-12-28
A vulnerability in the 'libsal.so' of the Zyxel GS1900 series firmware version 2.60 could allow an authenticated local user to execute arbitrary OS commands via a crafted function call.
- CVE-2021-35047CRITICALCVSS 9.9EG 9.92021-06-25
Vulnerability in the CommandPost, Collector, and Sensor components of Fidelis Network and Deception enables an attacker with user level access to the CLI to inject root level commands into the component and neighboring Fidelis components. …
- CVE-2021-35049CRITICALCVSS 9.9EG 9.92021-06-25
Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface. The vulnerability could allow a specially crafted HTTP request to execute system commands on the CommandPost and …
- CVE-2021-35062HIGHCVSS 8.1EG 8.12021-08-30
A Shell Metacharacter Injection vulnerability in result.php in DRK Odenwaldkreis Testerfassung March-2021 allow an attacker with a valid token of a COVID-19 test result to execute shell commands with the permissions of the web server.
- CVE-2021-3515MEDIUMCVSS 6.7EG 6.72021-06-01
A shell injection flaw was found in pglogical in versions before 2.3.4 and before 3.6.26. An attacker with CREATEDB privileges on a PostgreSQL server can craft a database name that allows execution of shell commands as the postgresql user …
- CVE-2021-35394CRITICALCVSS 9.8EG 9.8⚠ KEV2021-08-16
Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as 'UDPServer' binary. The binary is affected by multiple memory corruption vulnerabilities and an arbitrary command inje…
- CVE-2021-35402CRITICALCVSS 10.0EG 10.02026-02-20
PROLiNK PRC2402M 20190909 before 2021-06-13 allows live_api.cgi?page=satellite_list OS command injection via shell metacharacters in the ip parameter (for satellite_status).
- CVE-2021-35531MEDIUMCVSS 6.7EG 6.72022-06-07
Improper Input Validation vulnerability in a particular configuration setting field of Hitachi Energy TXpert Hub CoreTec 4 product, allows an attacker with access to an authorized user with ADMIN or ENGINEER role rights to inject an OS com…
Map vulnerabilities like CWE-78 to your infrastructure
EchelonGraph correlates every CVE — across CWE-78 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →