CWE-77— Command Injection
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.— MITRE CWE catalog
4,102 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-77page 44 of 83
- CVE-2024-10443CRITICALCVSS 9.8EG 9.82024-11-15
Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Task Manager component in Synology BeePhotos before 1.0.2-10026 and 1.1.0-10053 and Synology Photos before 1.6.2-0720 and 1.7.0-079…
- CVE-2024-10697MEDIUMCVSS 6.3EG 6.32024-11-02
A vulnerability has been found in Tenda AC6 15.03.05.19 and classified as critical. Affected by this vulnerability is the function formWriteFacMac of the file /goform/WriteFacMac of the component API Endpoint. The manipulation of the argum…
- CVE-2024-10954HIGHCVSS 8.8EG 8.82025-03-20
In the `manim` plugin of binary-husky/gpt_academic, versions prior to the fix, a vulnerability exists due to improper handling of user-provided prompts. The root cause is the execution of untrusted code generated by the LLM without a prope…
- CVE-2024-10966MEDIUMCVSS 6.3EG 6.32024-11-07
A vulnerability, which was classified as critical, has been found in TOTOLINK X18 9.1.0cu.2024_B20220329. Affected by this issue is some unknown functionality of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument enable leads …
- CVE-2024-11013HIGHCVSS 7.2EG 7.22024-11-29
Command Injection vulnerability in NEC Corporation UNIVERGE IX from Ver9.2 to Ver10.10.21, for Ver10.8 up to Ver10.8.27, for Ver10.9 up to Ver10.9.14 and UNIVERGE IX-R/IX-V Ver1.2.15 and earlier allows a attacker to inject an arbitrary CLI…
- CVE-2024-11046MEDIUMCVSS 6.3EG 6.32024-11-10
A vulnerability was found in D-Link DI-8003 16.07.16A1. It has been classified as critical. Affected is the function upgrade_filter_asp of the file /upgrade_filter.asp. The manipulation of the argument path leads to os command injection. I…
- CVE-2024-11320CRITICALCVSS 9.8EG 9.82024-11-21
Arbitrary commands execution on the server by exploiting a command injection vulnerability in the LDAP authentication mechanism. This issue affects Pandora FMS: from 700 through <=777.4
- CVE-2024-11634CRITICALCVSS 9.1EG 9.12024-12-10
Command injection in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to achieve remote code execution. (Not applicable to 9.1Rx)
- CVE-2024-11651HIGHCVSS 4.7EG 7.22024-11-25
A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. It has been classified as critical. Affected is an unknown function of the file /admin/network/wifi_schedule. The manipulation of the argument wifi_s…
- CVE-2024-11652HIGHCVSS 4.7EG 7.22024-11-25
A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/sn_package/sn_https. The manipulation…
- CVE-2024-11653MEDIUMCVSS 4.7EG 4.72024-11-25
A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/network/diag_traceroute. The manipulation of t…
- CVE-2024-11654MEDIUMCVSS 4.7EG 4.72024-11-25
A vulnerability classified as critical has been found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. This affects an unknown part of the file /admin/network/diag_traceroute6. The manipulation of the argument diag_tracerout…
- CVE-2024-11655MEDIUMCVSS 4.7EG 4.72024-11-25
A vulnerability classified as critical was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. This vulnerability affects unknown code of the file /admin/network/diag_pinginterface. The manipulation of the argument diag_p…
- CVE-2024-11656MEDIUMCVSS 4.7EG 4.72024-11-25
A vulnerability, which was classified as critical, has been found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. This issue affects some unknown processing of the file /admin/network/diag_ping6. The manipulation of the arg…
- CVE-2024-11657MEDIUMCVSS 4.7EG 4.72024-11-25
A vulnerability, which was classified as critical, was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. Affected is an unknown function of the file /admin/network/diag_nslookup. The manipulation of the argument diag_ns…
- CVE-2024-11658MEDIUMCVSS 4.7EG 4.72024-11-25
A vulnerability has been found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/network/ajax_getChannelList. The manipu…
- CVE-2024-11659MEDIUMCVSS 4.7EG 4.72024-11-25
A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/network/diag_iperf. The manipulation of the argume…
- CVE-2024-11665HIGHCVSS 8.8EG 8.82024-11-24
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in hardy-barth cph2_echarge_firmware allows OS Command Injection.This issue affects cph2_echarge_firmware: through 2.0.4.
- CVE-2024-11772CRITICALCVSS 9.1EG 9.12024-12-10
Command injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
- CVE-2024-11861CRITICALCVSS 9.8EG 9.82025-05-09
EnerSys AMPA 22.09 and prior versions are vulnerable to command injection leading to privileged remote shell access.
- CVE-2024-12111HIGHCVSS 8.0EG 8.02024-12-19
In a specific scenario a LDAP user can abuse the authentication process using injection attack in OpenText Privileged Access Manager that allows authentication bypass. This issue affects Privileged Access Manager version 23.3(4.4); 24.3(…
- CVE-2024-12251HIGHCVSS 7.8EG 7.82025-02-12
In Progress Telerik UI for WinUI versions prior to 2025 Q1 (3.0.0), a command injection attack is possible through improper neutralization of hyperlink elements.
- CVE-2024-12350MEDIUMCVSS 6.3EG 6.32024-12-09
A vulnerability was found in JFinalCMS 1.0. It has been rated as critical. Affected by this issue is the function update of the file \src\main\java\com\cms\controller\admin\TemplateController.java of the component Template Handler. The man…
- CVE-2024-12356CRITICALCVSS 9.8EG 9.8⚠ KEV2024-12-17
A critical vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) products which can allow an unauthenticated attacker to inject commands that are run as a site user.
- CVE-2024-12358MEDIUMCVSS 6.3EG 6.32024-12-09
A vulnerability was found in WeiYe-Jing datax-web 2.1.1. It has been classified as critical. This affects an unknown part of the file /api/job/add/. The manipulation of the argument glueSource leads to os command injection. It is possible …
- CVE-2024-12442CRITICALCVSS 9.8EG 9.82025-05-09
EnerSys AMPA versions 24.04 through 24.16, inclusive, are vulnerable to command injection leading to privileged remote shell access.
- CVE-2024-12450CRITICALCVSS 9.8EG 9.82025-03-20
In infiniflow/ragflow versions 0.12.0, the `web_crawl` function in `document_app.py` contains multiple vulnerabilities. The function does not filter URL parameters, allowing attackers to exploit Full Read SSRF by accessing internal network…
- CVE-2024-12912HIGHCVSS 7.2EG 7.22025-01-02
An improper input insertion vulnerability in AiCloud on certain router models may lead to arbitrary command execution. Refer to the '01/02/2025 ASUS Router AiCloud vulnerability' section on the ASUS Security Advisory for more information.
- CVE-2024-12971HIGHCVSS 8.8EG 8.92025-03-17
Improper Neutralization of Special Elements used in a Command vulnerability allows OS Command Injection.This issue affects Pandora FMS from 700 to 777.6
- CVE-2024-12985MEDIUMCVSS 6.3EG 6.32024-12-27
A vulnerability classified as critical was found in Overtek OT-E801G OTE801G65.1.1.0. This vulnerability affects unknown code of the file /diag_ping.cmd?action=test&interface=ppp0.1&ipaddr=8.8.8.8%26%26cat%20/etc/passwd&ipversion=4&session…
- CVE-2024-12986HIGHCVSS 7.3EG 7.42024-12-27
A vulnerability, which was classified as critical, has been found in DrayTek Vigor2960 and Vigor300B 1.5.1.3/1.5.1.4. This issue affects some unknown processing of the file /cgi-bin/mainfunction.cgi/apmcfgupptim of the component Web Manage…
- CVE-2024-12987CRITICALCVSS 7.3EG 9.0⚠ KEV2024-12-27
A vulnerability, which was classified as critical, was found in DrayTek Vigor2960 and Vigor300B 1.5.1.4. Affected is an unknown function of the file /cgi-bin/mainfunction.cgi/apmcfgupload of the component Web Management Interface. The mani…
- CVE-2024-12992CRITICALCVSS 9.8EG 9.82025-03-17
Improper Neutralization of Special Elements used in a Command vulnerability allows OS Command Injection via RCE. This issue affects Pandora FMS from 700 to 777.6 .
- CVE-2024-13062HIGHCVSS 7.2EG 7.22025-01-02
An unintended entry point vulnerability has been identified in certain router models, which may allow for arbitrary command execution. Refer to the ' 01/02/2025 ASUS Router AiCloud vulnerability' section on the ASUS Security Advisory for …
- CVE-2024-13129HIGHCVSS 8.8EG 8.82025-01-03
A vulnerability was found in Roxy-WI up to 8.1.3. It has been declared as critical. Affected by this vulnerability is the function action_service of the file app/modules/roxywi/roxy.py. The manipulation of the argument action/service leads…
- CVE-2024-1354HIGHCVSS 8.0EG 8.02024-02-13
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance via the `syslog-ng` configuration file. Exploita…
- CVE-2024-1355CRITICALCVSS 9.1EG 9.12024-02-13
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance via the actions-console docker container while s…
- CVE-2024-1356HIGHCVSS 7.2EG 7.22024-03-05
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operat…
- CVE-2024-1359CRITICALCVSS 9.1EG 9.12024-02-13
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance when setting up an HTTP proxy. Exploitation of th…
- CVE-2024-1369CRITICALCVSS 9.1EG 9.12024-02-13
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance when setting the username and password for collec…
- CVE-2024-1372CRITICALCVSS 9.1EG 9.12024-02-13
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance when configuring SAML settings. Exploitation of t…
- CVE-2024-1374CRITICALCVSS 9.1EG 9.12024-02-13
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance via nomad templates when configuring audit log f…
- CVE-2024-1378CRITICALCVSS 9.1EG 9.12024-02-13
A command injection vulnerability was identified in GitHub Enterprise Server that allowed an attacker with an editor role in the Management Console to gain admin SSH access to the appliance via nomad templates when configuring SMTP option…
- CVE-2024-13871HIGHCVSS 8.8EG 8.82025-03-12
A command injection vulnerability exists in the /check_image_and_trigger_recovery API endpoint of Bitdefender Box 1 (firmware version 1.3.11.490). This flaw allows an unauthenticated, network-adjacent attacker to execute arbitrary command…
- CVE-2024-13892HIGHCVSS 7.7EG 7.72025-03-06
Smartwares cameras CIP-37210AT and C724IP, as well as others which share the same firmware in versions up to 3.3.0, are vulnerable to command injection. During the initialization process, a user has to use a mobile app to provide device…
- CVE-2024-1417HIGHCVSS 7.8EG 7.82024-05-16
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in WatchGuard AuthPoint Password Manager on MacOS allows an a adversary with local access to execute code under the context of the AuthPoint …
- CVE-2024-1540HIGHCVSS 8.2EG 8.22024-03-27
A command injection vulnerability exists in the deploy+test-visual.yml workflow of the gradio-app/gradio repository, due to improper neutralization of special elements used in a command. This vulnerability allows attackers to execute unaut…
- CVE-2024-1781MEDIUMCVSS 6.3EG 6.32024-02-23
A vulnerability was found in Totolink X6000R AX3000 9.4.0cu.852_20230719. It has been rated as critical. This issue affects the function setWizardCfg of the file /cgi-bin/cstecgi.cgi of the component shttpd. The manipulation leads to comma…
- CVE-2024-20287MEDIUMCVSS 6.5EG 6.52024-01-17
A vulnerability in the web-based management interface of the Cisco WAP371 Wireless-AC/N Dual Radio Access Point (AP) with Single Point Setup could allow an authenticated, remote attacker to perform command injection attacks against an affe…
- CVE-2024-20326HIGHCVSS 7.8EG 7.82024-05-16
A vulnerability in the ConfD CLI and the Cisco Crosswork Network Services Orchestrator CLI could allow an authenticated, low-privileged, local attacker to read and write arbitrary files as root on the underlying operating system. This v…
Map vulnerabilities like CWE-77 to your infrastructure
EchelonGraph correlates every CVE — across CWE-77 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →