CWE-78— OS Command Injection
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.— MITRE CWE catalog
6,263 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-78page 49 of 126
- CVE-2022-20877HIGHCVSS 4.7EG 7.22022-07-21
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the dev…
- CVE-2022-20878HIGHCVSS 4.7EG 7.22022-07-21
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the dev…
- CVE-2022-20879HIGHCVSS 4.7EG 7.22022-07-21
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the dev…
- CVE-2022-20880HIGHCVSS 4.7EG 7.22022-07-21
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the dev…
- CVE-2022-20881HIGHCVSS 4.7EG 7.22022-07-21
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the dev…
- CVE-2022-20882HIGHCVSS 4.7EG 7.22022-07-21
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the dev…
- CVE-2022-20883HIGHCVSS 4.7EG 7.22022-07-21
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the dev…
- CVE-2022-20884HIGHCVSS 4.7EG 7.22022-07-21
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the dev…
- CVE-2022-20885HIGHCVSS 4.7EG 7.22022-07-21
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the dev…
- CVE-2022-20886HIGHCVSS 4.7EG 7.22022-07-21
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the dev…
- CVE-2022-20887HIGHCVSS 4.7EG 7.22022-07-21
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the dev…
- CVE-2022-20888HIGHCVSS 4.7EG 7.22022-07-21
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the dev…
- CVE-2022-20910HIGHCVSS 4.7EG 7.22022-07-22
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W Routers could allow an authenticated, remote attacker to execute arbitrary code on an affected device or cause the dev…
- CVE-2022-20925HIGHCVSS 6.3EG 7.22022-11-15
A vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. The vulnerability is…
- CVE-2022-20926HIGHCVSS 6.3EG 8.82022-11-15
A vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. The vulnerability is…
- CVE-2022-20930MEDIUMCVSS 6.7EG 6.72022-09-30
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to overwrite and possibly corrupt files on an affected system. This vulnerability is due to insufficient input validation. An attacker could e…
- CVE-2022-20934MEDIUMCVSS 6.0EG 6.72022-11-15
A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software and Cisco FXOS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system as root. This vulnerabilit…
- CVE-2022-20964HIGHCVSS 6.3EG 8.82023-01-20
A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, remote attacker to inject arbitrary commands on the underlying operating system. This vulnerability is due to improper…
- CVE-2022-21129HIGHCVSS 7.4EG 7.42023-01-31
Versions of the package nemo-appium before 0.0.9 are vulnerable to Command Injection due to improper input sanitization in the 'module.exports.setup' function. **Note:** In order to exploit this vulnerability appium-running 0.1.3 has to…
- CVE-2022-21143HIGHCVSS 7.5EG 7.52022-02-18
MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does not properly sanitize user input on several locations, which may allow an attacker to inj…
- CVE-2022-21173HIGHCVSS 8.8EG 8.82022-02-08
Hidden functionality vulnerability in ELECOM LAN routers (WRH-300BK3 firmware v1.05 and earlier, WRH-300WH3 firmware v1.05 and earlier, WRH-300BK3-S firmware v1.05 and earlier, WRH-300DR3-S firmware v1.05 and earlier, WRH-300LB3-S firmware…
- CVE-2022-21178CRITICALCVSS 9.8EG 9.82022-08-05
An os command injection vulnerability exists in the confsrv ucloud_add_new_node functionality of TCL LinkHub Mesh Wifi MS1G_00_01.00_14. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a mal…
- CVE-2022-21191HIGHCVSS 7.4EG 7.42023-01-13
Versions of the package global-modules-path before 3.0.0 are vulnerable to Command Injection due to missing input sanitization or other checks and sandboxes being employed to the getPath function.
- CVE-2022-21668HIGHCVSS 8.0EG 8.02022-01-10
pipenv is a Python development workflow tool. Starting with version 2018.10.9 and prior to version 2022.1.8, a flaw in pipenv's parsing of requirements files allows an attacker to insert a specially crafted string inside a comment anywhere…
- CVE-2022-21810HIGHCVSS 7.4EG 7.82023-01-26
All versions of the package smartctl are vulnerable to Command Injection via the info method due to improper input sanitization.
- CVE-2022-2185CRITICALCVSS 9.9EG 9.92022-07-01
A critical issue has been discovered in GitLab affecting all versions starting from 14.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 where an authenticated user authorized to import projects could import a maliciously …
- CVE-2022-22140CRITICALCVSS 9.8EG 9.82022-08-05
An os command injection vulnerability exists in the confsrv ucloud_add_node functionality of TCL LinkHub Mesh Wi-Fi MS1G_00_01.00_14. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a malici…
- CVE-2022-22273CRITICALCVSS 9.8EG 9.82022-03-17
Improper neutralization of Special Elements leading to OS Command Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products and older firmware versions of Secure Mobile Access (SMA) 100 series products, specifically…
- CVE-2022-22298MEDIUMCVSS 6.7EG 6.72023-10-10
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiIsolator version 1.0.0, FortiIsolator version 1.1.0, FortiIsolator version 1.2.0 through 1.2.2, FortiIsolator version 2.0.0 throu…
- CVE-2022-22301HIGHCVSS 7.8EG 7.82022-03-02
An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] in FortiAP-C console 5.4.0 through 5.4.3, 5.2.0 through 5.2.1 may allow an authenticated attacker to execute unauthorized commands by running CLI c…
- CVE-2022-2234CRITICALCVSS 9.9EG 9.92022-08-24
An authenticated mySCADA myPRO 8.26.0 user may be able to modify parameters to run commands directly in the operating system.
- CVE-2022-22454HIGHCVSS 7.8EG 7.82022-05-10
IBM InfoSphere Information Server 11.7 could allow a locally authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request.
- CVE-2022-2251HIGHCVSS 4.8EG 8.02023-01-17
Improper sanitization of branch names in GitLab Runner affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows a user who creates a branch with a specially crafted name and gets another user to trigger…
- CVE-2022-2253CRITICALCVSS 9.1EG 9.12022-07-01
A user with administrative privileges in Distributed Data Systems WebHMI 4.1.1.7662 may send OS commands to execute on the host server.
- CVE-2022-22555MEDIUMCVSS 6.0EG 6.72022-07-21
Dell EMC PowerStore, contains an OS command injection Vulnerability. A locally authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the PowerStore underlying OS, with the…
- CVE-2022-22684HIGHCVSS 7.2EG 8.82022-07-28
Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in task management component in Synology DiskStation Manager (DSM) before 6.2.4-25553 allows remote authenticated users to execute arb…
- CVE-2022-22945HIGHCVSS 7.8EG 7.82022-02-16
VMware NSX Edge contains a CLI shell injection vulnerability. A malicious actor with SSH access to an NSX-Edge appliance can execute arbitrary commands on the operating system as root.
- CVE-2022-22951CRITICALCVSS 9.1EG 9.12022-03-23
VMware Carbon Black App Control (8.5.x prior to 8.5.14, 8.6.x prior to 8.6.6, 8.7.x prior to 8.7.4 and 8.8.x prior to 8.8.2) contains an OS command injection vulnerability. An authenticated, high privileged malicious actor with network acc…
- CVE-2022-22984MEDIUMCVSS 5.0EG 5.02022-11-30
The package snyk before 1.1064.0; the package snyk-mvn-plugin before 2.31.3; the package snyk-gradle-plugin before 3.24.5; the package @snyk/snyk-cocoapods-plugin before 2.5.3; the package snyk-sbt-plugin before 2.16.2; the package snyk-py…
- CVE-2022-22986HIGHCVSS 8.8EG 8.82022-03-31
Netcommunity OG410X and OG810X series (Netcommunity OG410Xa, OG410Xi, OG810Xa, and OG810Xi firmware Ver.2.28 and earlier) allow an attacker on the adjacent network to execute an arbitrary OS command via a specially crafted config file.
- CVE-2022-22991HIGHCVSS 7.8EG 7.82022-01-13
A malicious user on the same LAN could use DNS spoofing followed by a command injection attack to trick a NAS device into loading through an unsecured HTTP call. Addressed this vulnerability by disabling checks for internet connectivity us…
- CVE-2022-22997CRITICALCVSS 6.8EG 9.82022-07-12
Addressed a remote code execution vulnerability by resolving a command injection vulnerability and closing an AWS S3 bucket that potentially allowed an attacker to execute unsigned code on My Cloud Home devices.
- CVE-2022-23100CRITICALCVSS 9.8EG 9.82022-07-27
OX App Suite through 7.10.6 allows OS Command Injection via Documentconverter (e.g., through an email attachment).
- CVE-2022-2314CRITICALCVSS 9.8EG 9.82022-08-15
The VR Calendar WordPress plugin through 2.3.2 lets any user execute arbitrary PHP functions on the site.
- CVE-2022-23389CRITICALCVSS 9.8EG 9.82022-02-14
PublicCMS v4.0 was discovered to contain a remote code execution (RCE) vulnerability via the cmdarray parameter.
- CVE-2022-23611HIGHCVSS 8.1EG 8.12022-02-04
iTunesRPC-Remastered is a Discord Rich Presence for iTunes on Windows utility. In affected versions iTunesRPC-Remastered did not properly sanitize image file paths leading to OS level command injection. This issue has been patched in commi…
- CVE-2022-23661CRITICALCVSS 9.1EG 9.12022-05-16
A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Man…
- CVE-2022-23662CRITICALCVSS 9.1EG 9.12022-05-16
A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Man…
- CVE-2022-23663CRITICALCVSS 9.1EG 9.12022-05-16
A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Man…
- CVE-2022-23664CRITICALCVSS 9.1EG 9.12022-05-16
A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Man…
Map vulnerabilities like CWE-78 to your infrastructure
EchelonGraph correlates every CVE — across CWE-78 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →