CWE-77— Command Injection
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.— MITRE CWE catalog
4,102 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-77page 43 of 83
- CVE-2023-50445HIGHCVSS 7.8EG 7.82023-12-28
Shell Injection vulnerability GL.iNet A1300 v4.4.6, AX1800 v4.4.6, AXT1800 v4.4.6, MT3000 v4.4.6, MT2500 v4.4.6, MT6000 v4.5.0, MT1300 v4.3.7, MT300N-V2 v4.3.7, AR750S v4.3.7, AR750 v4.3.7, AR300M v4.3.7, and B1300 v4.3.7., allows local at…
- CVE-2023-50917CRITICALCVSS 9.8EG 9.82023-12-15
MajorDoMo (aka Major Domestic Module) before 0662e5e allows command execution via thumb.php shell metacharacters. NOTE: this is unrelated to the Majordomo mailing-list manager.
- CVE-2023-50983CRITICALCVSS 9.8EG 9.82023-12-20
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerability via the sysScheduleRebootSet function.
- CVE-2023-50989CRITICALCVSS 9.8EG 9.82023-12-20
Tenda i29 v1.0 V1.0.0.5 was discovered to contain a command injection vulnerability via the pingSet function.
- CVE-2023-51014CRITICALCVSS 9.8EG 9.82023-12-22
TOTOLINK EX1800T V9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the lanSecDns parameter’ of the setLanConfig interface of the cstecgi .cgi
- CVE-2023-51016CRITICALCVSS 9.8EG 9.82023-12-22
TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the setRebootScheCfg interface of the cstecgi .cgi.
- CVE-2023-51025CRITICALCVSS 9.8EG 9.82023-12-22
TOTOlink EX1800T V9.1.0cu.2112_B20220316 is vulnerable to an unauthorized arbitrary command execution in the ‘admuser’ parameter of the setPasswordCfg interface of the cstecgi .cgi.
- CVE-2023-51126CRITICALCVSS 9.8EG 9.82024-01-10
Command injection vulnerability in /usr/www/res.php in FLIR AX8 up to 1.46.16 allows attackers to run arbitrary commands via the value parameter. NOTE: The vendor has stated that with the introduction of firmware version 1.49.16 (Jan 2023)…
- CVE-2023-51295MEDIUMCVSS 6.5EG 6.52025-05-08
PHPJabbers Event Booking Calendar v4.0 is vulnerable to Multiple HTML Injection in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key, title" parameters.
- CVE-2023-51664CRITICALCVSS 9.8EG 9.82023-12-27
tj-actions/changed-files is a Github action to retrieve all files and directories. Prior to 41.0.0, the `tj-actions/changed-files` workflow allows for command injection in changed filenames, allowing an attacker to execute arbitrary code a…
- CVE-2023-51707CRITICALCVSS 9.8EG 9.82023-12-22
MotionPro in Array ArrayOS AG before 9.4.0.505 on AG and vxAG allows remote command execution via crafted packets. AG and vxAG 9.3.0.259.x are unaffected.
- CVE-2023-51812CRITICALCVSS 9.8EG 9.82024-01-04
Tenda AX3 v16.03.12.11 was discovered to contain a remote code execution (RCE) vulnerability via the list parameter at /goform/SetNetControlList.
- CVE-2023-51833HIGHCVSS 8.1EG 8.12024-01-25
A command injection issue in TRENDnet TEW-411BRPplus v.2.07_eu that allows a local attacker to execute arbitrary code via the data1 parameter in the debug.cgi page.
- CVE-2023-51835MEDIUMCVSS 6.8EG 6.82024-02-29
An issue in TRENDnet TEW-822DRE v.1.03B02 allows a local attacker to execute arbitrary code via the parameters ipv4_ping in the /boafrm/formSystemCheck.
- CVE-2023-51887CRITICALCVSS 9.8EG 9.82024-01-24
Command Injection vulnerability in Mathtex v.1.05 and before allows a remote attacker to execute arbitrary code via crafted string in application URL.
- CVE-2023-51972CRITICALCVSS 9.8EG 9.82024-01-10
Tenda AX1803 v1.0.0.1 was discovered to contain a command injection vulnerability via the function fromAdvSetLanIp.
- CVE-2023-52027CRITICALCVSS 9.8EG 9.82024-01-11
TOTOlink A3700R v9.1.2u.5822_B20200513 was discovered to contain a remote command execution (RCE) vulnerability via the NTPSyncWithHost function.
- CVE-2023-52038CRITICALCVSS 9.8EG 9.82024-01-24
An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415C80 function.
- CVE-2023-52039CRITICALCVSS 9.8EG 9.82024-01-24
An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415AA4 function.
- CVE-2023-52040CRITICALCVSS 9.8EG 9.82024-01-24
An issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_41284C function.
- CVE-2023-52042CRITICALCVSS 9.8EG 9.82024-01-16
An issue discovered in sub_4117F8 function in TOTOLINK X6000R V9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the 'lang' parameter.
- CVE-2023-52137HIGHCVSS 8.8EG 8.82023-12-29
The [`tj-actions/verify-changed-files`](https://github.com/tj-actions/verify-changed-files) action allows for command injection in changed filenames, allowing an attacker to execute arbitrary code and potentially leak secrets. The [`verify…
- CVE-2023-52291MEDIUMCVSS 4.7EG 4.72024-07-17
In streampark, the project module integrates Maven's compilation capabilities. The input parameter validation is not strict, allowing attackers to insert commands for remote command execution, The prerequisite for a successful attack is th…
- CVE-2023-52624HIGHCVSS 7.8EG 7.82024-03-26
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Wake DMCUB before executing GPINT commands [Why] DMCUB can be in idle when we attempt to interface with the HW through the GPINT mailbox resulting in a …
- CVE-2023-5752LOWCVSS 3.3EG 3.32023-10-25
When installing a package from a Mercurial VCS URL (ie "pip install hg+...") with pip prior to v23.3, the specified Mercurial revision could be used to inject arbitrary configuration options to the "hg clone" call (ie "--config"). Cont…
- CVE-2023-5878CRITICALCVSS 9.4EG 9.42025-02-06
Honeywell OneWireless Wireless Device Manager (WDM) for the following versions R310.x, R320.x, R321.x, R322.1, R322.2, R323.x, R330.1 contains a command injection vulnerability. An attacker who is authenticated could use the firmware up…
- CVE-2023-6071HIGHCVSS 7.2EG 8.42023-11-30
An Improper Neutralization of Special Elements used in a command vulnerability in ESM prior to version 11.6.9 allows a remote administrator to execute arbitrary code as root on the ESM. This is possible as the input isn't correctly saniti…
- CVE-2023-6321HIGHCVSS 7.2EG 7.22024-05-15
A command injection vulnerability exists in the IOCTL that manages OTA updates. A specially crafted command can lead to command execution as the root user. An attacker can make authenticated requests to trigger this vulnerability.
- CVE-2023-6572HIGHCVSS 8.1EG 8.12023-12-14
Command Injection in GitHub repository gradio-app/gradio prior to main.
- CVE-2023-6634HIGHCVSS 8.1EG 8.12024-01-11
The LearnPress plugin for WordPress is vulnerable to Command Injection in all versions up to, and including, 4.2.5.7 via the get_content function. This is due to the plugin making use of the call_user_func function with user input. This ma…
- CVE-2023-6848CRITICALCVSS 9.8EG 9.82023-12-16
A vulnerability was found in kalcaddle kodbox up to 1.48. It has been declared as critical. Affected by this vulnerability is the function check of the file plugins/officeViewer/controller/libreOffice/index.class.php. The manipulation of t…
- CVE-2023-6940HIGHCVSS 8.8EG 8.82023-12-19
with only one user interaction(download a malicious config), attackers can gain full command execution on the victim system.
- CVE-2023-6999HIGHCVSS 8.8EG 8.82024-04-09
The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Remote Code Exxecution via shortcode in all versions up to, and including, 3.0.10 (with the exception of 2.7.31.2, 2.8.23.2, 2.9.19.2). This makes it possib…
- CVE-2023-7227CRITICALCVSS 9.8EG 9.82024-01-25
SystemK NVR 504/508/516 versions 2.3.5SK.30084998 and prior are vulnerable to a command injection vulnerability in the dynamic domain name system (DDNS) settings that could allow an attacker to execute arbitrary commands with root privile…
- CVE-2024-0005CRITICALCVSS 9.1EG 9.12024-09-23
A condition exists in FlashArray and FlashBlade Purity whereby a malicious user could execute arbitrary commands remotely through a specifically crafted SNMP configuration.
- CVE-2024-0291HIGHCVSS 8.8EG 8.82024-01-08
A vulnerability was found in Totolink LR1200GB 9.1.0u.6619_B20230130. It has been rated as critical. This issue affects the function UploadFirmwareFile of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument FileName leads to co…
- CVE-2024-0325LOWCVSS 3.6EG 3.62024-02-01
In Helix Sync versions prior to 2024.1, a local command injection was identified. Reported by Bryan Riggins.
- CVE-2024-0507HIGHCVSS 6.5EG 8.12024-01-16
An attacker with access to a Management Console user account with the editor role could escalate privileges through a command injection vulnerability in the Management Console. This vulnerability affected all versions of GitHub Enterprise …
- CVE-2024-0579MEDIUMCVSS 6.3EG 6.32024-01-16
A vulnerability classified as critical was found in Totolink X2000R 1.0.0-B20221212.1452. Affected by this vulnerability is the function formMapDelDevice of the file /boafrm/formMapDelDevice. The manipulation of the argument macstr leads t…
- CVE-2024-0740CRITICALCVSS 9.8EG 9.82024-04-26
Eclipse Target Management: Terminal and Remote System Explorer (RSE) version <= 4.5.400 has a remote code execution vulnerability that does not require authentication. The fixed version is included in Eclipse IDE 2024-03
- CVE-2024-0817HIGHCVSS 7.8EG 7.82024-03-07
Command injection in IrGraph.draw in paddlepaddle/paddle 2.6.0
- CVE-2024-0919HIGHCVSS 8.8EG 8.82024-01-26
A vulnerability was found in TRENDnet TEW-815DAP 1.0.2.0. It has been classified as critical. This affects the function do_setNTP of the component POST Request Handler. The manipulation of the argument NtpDstStart/NtpDstEnd leads to comman…
- CVE-2024-0920HIGHCVSS 7.2EG 7.22024-01-26
A vulnerability was found in TRENDnet TEW-822DRE 1.03B02. It has been declared as critical. This vulnerability affects unknown code of the file /admin_ping.htm of the component POST Request Handler. The manipulation of the argument ipv4_pi…
- CVE-2024-10035CRITICALCVSS 9.8EG 9.82024-11-04
Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Special Elements used in a Command ('Command Injection'), Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vuln…
- CVE-2024-10131CRITICALCVSS 8.8EG 9.82024-10-19
The `add_llm` function in `llm_app.py` in infiniflow/ragflow version 0.11.0 contains a remote code execution (RCE) vulnerability. The function uses user-supplied input `req['llm_factory']` and `req['llm_name']` to dynamically instantiate c…
- CVE-2024-10190CRITICALCVSS 9.8EG 9.82025-03-20
Horovod versions up to and including v0.28.1 are vulnerable to unauthenticated remote code execution. The vulnerability is due to improper handling of base64-encoded data in the `ElasticRendezvousHandler`, a subclass of `KVStoreHandler`. S…
- CVE-2024-10193MEDIUMCVSS 4.7EG 4.72024-10-20
A vulnerability was found in WAVLINK WN530H4, WN530HG4 and WN572HG3 up to 20221028 and classified as critical. This issue affects the function ping_ddns of the file internet.cgi. The manipulation of the argument DDNS leads to command injec…
- CVE-2024-10428HIGHCVSS 7.2EG 7.22024-10-27
A vulnerability was found in WAVLINK WN530H4, WN530HG4 and WN572HG3 up to 20221028. It has been rated as critical. This issue affects the function set_ipv6 of the file firewall.cgi. The manipulation of the argument dhcpGateway leads to com…
- CVE-2024-10429HIGHCVSS 7.2EG 7.22024-10-27
A vulnerability classified as critical has been found in WAVLINK WN530H4, WN530HG4 and WN572HG3 up to 20221028. Affected is the function set_ipv6 of the file internet.cgi. The manipulation of the argument IPv6OpMode/IPv6IPAddr/IPv6WANIPAdd…
- CVE-2024-10435MEDIUMCVSS 6.3EG 6.32024-10-28
A vulnerability was found in didi Super-Jacoco 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /cov/triggerEnvCov. The manipulation of the argument uuid leads to command injection. The attack can …
Map vulnerabilities like CWE-77 to your infrastructure
EchelonGraph correlates every CVE — across CWE-77 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →