CWE-78— OS Command Injection
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.— MITRE CWE catalog
6,263 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-78page 50 of 126
- CVE-2022-23665CRITICALCVSS 9.1EG 9.12022-05-16
A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Man…
- CVE-2022-23666CRITICALCVSS 9.1EG 9.12022-05-16
A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Man…
- CVE-2022-23667HIGHCVSS 7.2EG 7.22022-05-16
A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Man…
- CVE-2022-23672HIGHCVSS 7.2EG 7.22022-05-17
A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Man…
- CVE-2022-23673HIGHCVSS 7.2EG 7.22022-05-17
A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Man…
- CVE-2022-23681HIGHCVSS 7.8EG 7.82022-09-06
Multiple vulnerabilities exist in the AOS-CX command line interface that could lead to authenticated command injection. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system l…
- CVE-2022-23682HIGHCVSS 7.8EG 7.82022-09-06
Multiple vulnerabilities exist in the AOS-CX command line interface that could lead to authenticated command injection. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system l…
- CVE-2022-23683HIGHCVSS 7.2EG 7.22022-09-06
Authenticated command injection vulnerabilities exist in the AOS-CX Network Analytics Engine via NAE scripts. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the …
- CVE-2022-23900CRITICALCVSS 9.8EG 9.82022-04-07
A command injection vulnerability in the API of the Wavlink WL-WN531P3 router, version M31G3.V5030.201204, allows an attacker to achieve unauthorized remote code execution via a malicious POST request through /cgi-bin/adm.cgi.
- CVE-2022-23935CRITICALCVSS 7.8EG 9.82022-01-25
lib/Image/ExifTool.pm in ExifTool before 12.38 mishandles a $file =~ /\|$/ check, leading to command injection.
- CVE-2022-24065HIGHCVSS 8.1EG 8.12022-06-08
The package cookiecutter before 2.1.1 are vulnerable to Command Injection via hg argument injection. When calling the cookiecutter function from Python code with the checkout parameter, it is passed to the hg checkout command in a way that…
- CVE-2022-24193CRITICALCVSS 9.8EG 9.82022-03-10
CasaOS before v0.2.7 was discovered to contain a command injection vulnerability.
- CVE-2022-24237HIGHCVSS 8.8EG 8.82022-03-21
The snaptPowered2 component of Snapt Aria v12.8 was discovered to contain a command injection vulnerability. This vulnerability allows authenticated attackers to execute arbitrary commands.
- CVE-2022-24288CRITICALCVSS 8.8EG 9.02022-02-25
In Apache Airflow, prior to version 2.2.4, some example DAGs did not properly sanitize user-provided params, making them susceptible to OS Command Injection from the web UI.
- CVE-2022-24377HIGHCVSS 7.4EG 7.42022-12-14
The package cycle-import-check before 1.3.2 are vulnerable to Command Injection via the writeFileToTmpDirAndOpenIt function due to improper user-input sanitization.
- CVE-2022-24388HIGHCVSS 8.8EG 8.82022-05-17
Vulnerability in rconfig “date” enables an attacker with user level access to the CLI to inject root level commands into Fidelis Network and Deception CommandPost, Collector, Sensor, and Sandbox components as well as neighboring Fideli…
- CVE-2022-24389HIGHCVSS 8.8EG 8.82022-05-17
Vulnerability in rconfig “cert_utils” enables an attacker with user level access to the CLI to inject root level commands into Fidelis Network and Deception CommandPost, Collector, Sensor, and Sandbox components as well as neighboring …
- CVE-2022-24390HIGHCVSS 8.8EG 8.82022-05-17
Vulnerability in rconfig “remote_text_file” enables an attacker with user level access to the CLI to inject user level commands into Fidelis Network and Deception CommandPost, Collector, Sensor, and Sandbox components as well as neighb…
- CVE-2022-24392HIGHCVSS 8.8EG 8.82022-05-17
Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface using the “feed_comm_test” value for the “feed” parameter. The vulnerability could allow a specially craft…
- CVE-2022-24393HIGHCVSS 8.8EG 8.82022-05-17
Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface using the “check_vertica_upgrade” value for the “cpIp” parameter. The vulnerability could allow a speciall…
- CVE-2022-24394HIGHCVSS 8.8EG 8.82022-05-17
Vulnerability in Fidelis Network and Deception CommandPost enables authenticated command injection through the web interface using the “update_checkfile” value for the “filename” parameter. The vulnerability could allow a specially…
- CVE-2022-24405CRITICALCVSS 9.8EG 9.82022-07-27
OX App Suite through 7.10.6 allows OS Command Injection via a serialized Java class to the Documentconverter API.
- CVE-2022-24431HIGHCVSS 7.4EG 7.42022-12-21
All versions of package abacus-ext-cmdline are vulnerable to Command Injection via the execute function due to improper user-input sanitization.
- CVE-2022-24441MEDIUMCVSS 5.8EG 5.82022-11-30
The package snyk before 1.1064.0 are vulnerable to Code Injection when analyzing a project. An attacker who can convince a user to scan a malicious project can include commands in a build file such as build.gradle or gradle-wrapper.jar, wh…
- CVE-2022-24552CRITICALCVSS 9.8EG 9.82022-02-06
A flaw was found in the REST API in StarWind Stack. REST command, which manipulates a virtual disk, doesn’t check input parameters. Some of them go directly to bash as part of a script. An attacker with non-root user access can inject ar…
- CVE-2022-24697CRITICALCVSS 9.8EG 9.82022-10-13
Kylin's cube designer function has a command injection vulnerability when overwriting system parameters in the configuration overwrites menu. RCE can be implemented by closing the single quotation marks around the parameter value of “-- …
- CVE-2022-24725MEDIUMCVSS 6.2EG 6.22022-03-03
Shescape is a shell escape package for JavaScript. An issue in versions 1.4.0 to 1.5.1 allows for exposure of the home directory on Unix systems when using Bash with the `escape` or `escapeAll` functions from the _shescape_ API with the `i…
- CVE-2022-24753HIGHCVSS 7.7EG 7.72022-03-09
Stripe CLI is a command-line tool for the Stripe eCommerce platform. A vulnerability in Stripe CLI exists on Windows when certain commands are run in a directory where an attacker has planted files. The commands are `stripe login`, `stripe…
- CVE-2022-24796CRITICALCVSS 10.0EG 10.02022-03-31
RaspberryMatic is a free and open-source operating system for running a cloud-free smart-home using the homematicIP / HomeMatic hardware line of IoT devices. A Remote Code Execution (RCE) vulnerability in the file upload facility of the We…
- CVE-2022-24803CRITICALCVSS 10.0EG 10.02022-04-01
Asciidoctor-include-ext is Asciidoctor’s standard include processor reimplemented as an extension. Versions prior to 0.4.0, when used to render user-supplied input in AsciiDoc markup, may allow an attacker to execute arbitrary system com…
- CVE-2022-2486CRITICALCVSS 8.0EG 9.82022-07-20
A vulnerability, which was classified as critical, was found in WAVLINK WN535K2 and WN535K3. This affects an unknown part of the file /cgi-bin/mesh.cgi?page=upgrade. The manipulation of the argument key leads to os command injection. The e…
- CVE-2022-2487CRITICALCVSS 8.0EG 9.82022-07-20
A vulnerability has been found in WAVLINK WN535K2 and WN535K3 and classified as critical. This vulnerability affects unknown code of the file /cgi-bin/nightled.cgi. The manipulation of the argument start_hour leads to os command injection.…
- CVE-2022-2488CRITICALCVSS 8.0EG 9.82022-07-20
A vulnerability was found in WAVLINK WN535K2 and WN535K3 and classified as critical. This issue affects some unknown processing of the file /cgi-bin/touchlist_sync.cgi. The manipulation of the argument IP leads to os command injection. The…
- CVE-2022-25017CRITICALCVSS 9.1EG 9.12022-04-01
Hitron CHITA 7.2.2.0.3b6-CD devices contain a command injection vulnerability via the Device/DDNS ddnsUsername field.
- CVE-2022-25048HIGHCVSS 8.8EG 8.82022-07-07
Command injection vulnerability in CWP v0.9.8.1126 that allows normal users to run commands as the root user.
- CVE-2022-25060CRITICALCVSS 9.8EG 9.82022-02-25
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing.
- CVE-2022-25061CRITICALCVSS 9.8EG 9.82022-02-25
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_setIp6DefaultRoute.
- CVE-2022-25064CRITICALCVSS 9.8EG 9.82022-02-25
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a remote code execution (RCE) vulnerability via the function oal_wan6_setIpAddr.
- CVE-2022-25075CRITICALCVSS 9.8EG 9.82022-02-24
TOTOLink A3000RU V5.9c.2280_B20180512 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.
- CVE-2022-25076CRITICALCVSS 9.8EG 9.82022-02-24
TOTOLink A800R V4.1.2cu.5137_B20200730 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.
- CVE-2022-25077CRITICALCVSS 9.8EG 9.82022-02-24
TOTOLink A3100R V4.1.2cu.5050_B20200504 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.
- CVE-2022-25078CRITICALCVSS 9.8EG 9.82022-02-24
TOTOLink A3600R V4.1.2cu.5182_B20201102 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.
- CVE-2022-25079CRITICALCVSS 9.8EG 9.82022-02-24
TOTOLink A810R V4.1.2cu.5182_B20201026 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.
- CVE-2022-25080CRITICALCVSS 9.8EG 9.82022-02-24
TOTOLink A830R V5.9c.4729_B20191112 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.
- CVE-2022-25081CRITICALCVSS 9.8EG 9.82022-02-24
TOTOLink T10 V5.9c.5061_B20200511 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.
- CVE-2022-25082CRITICALCVSS 9.8EG 9.82022-02-24
TOTOLink A950RG V5.9c.4050_B20190424 and V4.1.2cu.5204_B20210112 were discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING pa…
- CVE-2022-25083CRITICALCVSS 9.8EG 9.82022-02-24
TOTOLink A860R V4.1.2cu.5182_B20201027 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.
- CVE-2022-25084CRITICALCVSS 9.8EG 9.82022-02-24
TOTOLink T6 V5.9c.4085_B20190428 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.
- CVE-2022-25168CRITICALCVSS 9.8EG 9.82022-08-04
Apache Hadoop's FileUtil.unTar(File, File) API does not escape the input file name before being passed to the shell. An attacker can inject arbitrary commands. This is only used in Hadoop 3.3 InMemoryAliasMap.completeBootstrapTransfer, whi…
- CVE-2022-25171HIGHCVSS 7.4EG 7.42022-12-20
The package p4 before 0.0.7 are vulnerable to Command Injection via the run() function due to improper input sanitization
Map vulnerabilities like CWE-78 to your infrastructure
EchelonGraph correlates every CVE — across CWE-78 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →