CWE-77— Command Injection
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.— MITRE CWE catalog
4,102 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-77page 45 of 83
- CVE-2024-20365MEDIUMCVSS 6.5EG 6.52024-10-02
A vulnerability in the Redfish API of Cisco UCS B-Series, Cisco UCS Managed C-Series, and Cisco UCS X-Series Servers could allow an authenticated, remote attacker with administrative privileges to perform command injection attacks on an af…
- CVE-2024-20418CRITICALCVSS 10.0EG 10.02024-11-06
A vulnerability in the web-based management interface of Cisco Unified Industrial Wireless Software for Cisco Ultra-Reliable Wireless Backhaul (URWB) Access Points could allow an unauthenticated, remote attacker to perform command injectio…
- CVE-2024-20432CRITICALCVSS 9.9EG 9.92024-10-02
A vulnerability in the REST API and web UI of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, low-privileged, remote attacker to perform a command injection attack against an affected device. This vuln…
- CVE-2024-20492MEDIUMCVSS 6.0EG 6.02024-10-02
A vulnerability in the restricted shell of Cisco Expressway Series could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnera…
- CVE-2024-20667HIGHCVSS 7.5EG 7.52024-02-13
Azure DevOps Server Remote Code Execution Vulnerability
- CVE-2024-20676HIGHCVSS 8.0EG 8.02024-01-09
Azure Storage Mover Remote Code Execution Vulnerability
- CVE-2024-21117MEDIUMCVSS 5.3EG 5.32024-04-16
Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). Supported versions that are affected are 8.5.6 and 8.5.7. Easily exploitable vulnerability allows low privileged attacker…
- CVE-2024-21322HIGHCVSS 7.2EG 7.22024-04-09
Microsoft Defender for IoT Remote Code Execution Vulnerability
- CVE-2024-21488HIGHCVSS 7.3EG 7.32024-01-30
Versions of the package network before 0.7.0 are vulnerable to Arbitrary Command Injection due to use of the child_process exec function without input sanitization. If (attacker-controlled) user input is given to the mac_address_for functi…
- CVE-2024-21663HIGHCVSS 8.8EG 8.82024-01-09
Discord-Recon is a Discord bot created to automate bug bounty recon, automated scans and information gathering via a discord server. Discord-Recon is vulnerable to remote code execution. An attacker is able to execute shell commands in the…
- CVE-2024-21878CRITICALCVSS 9.8EG 9.82024-08-12
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Enphase IQ Gateway (formerly known as Envoy) allows OS Command Injection. This vulnerability is present in an internal script.This issue a…
- CVE-2024-21879HIGHCVSS 8.8EG 8.82024-08-12
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability through an url parameter of an authenticated enpoint in Enphase IQ Gateway (formerly known as Envoy) allows OS Command Injection.This issue a…
- CVE-2024-21880HIGHCVSS 7.2EG 7.22024-08-12
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability via the url parameter of an authenticated enpoint in Enphase IQ Gateway (formerly known as Enphase) allows OS Command Injection.This issue af…
- CVE-2024-21887CRITICALCVSS 9.1EG 9.1⚠ KEV2024-01-12
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the a…
- CVE-2024-21903MEDIUMCVSS 6.6EG 6.62024-09-06
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed th…
- CVE-2024-22061CRITICALCVSS 9.8EG 9.82024-04-19
A Heap Overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows a remote unauthenticated attacker to execute arbitrary commands
- CVE-2024-22093HIGHCVSS 8.7EG 8.72024-02-14
When running in appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint on multi-bladed systems. A successful exploit can allow the attacker to cross a security boundary. No…
- CVE-2024-22107HIGHCVSS 7.2EG 7.22024-02-02
An issue was discovered in GTB Central Console 15.17.1-30814.NG. The method systemSettingsDnsDataAction at /opt/webapp/src/AppBundle/Controller/React/SystemSettingsController.php is vulnerable to command injection via the /old/react/v1/api…
- CVE-2024-22122LOWCVSS 3.0EG 3.02024-08-12
Zabbix allows to configure SMS notifications. AT command injection occurs on "Zabbix Server" because there is no validation of "Number" field on Web nor on Zabbix server side. Attacker can run test of SMS providing specially crafted phone …
- CVE-2024-22127CRITICALCVSS 9.1EG 9.12024-03-12
SAP NetWeaver Administrator AS Java (Administrator Log Viewer plug-in) - version 7.50, allows an attacker with high privileges to upload potentially dangerous files which leads to command injection vulnerability. This would enable the att…
- CVE-2024-22197HIGHCVSS 7.7EG 7.72024-01-11
Nginx-ui is online statistics for Server Indicators Monitor CPU usage, memory usage, load average, and disk usage in real-time. The `Home > Preference` page exposes a small list of nginx settings such as `Nginx Access Log Path` and `…
- CVE-2024-22198HIGHCVSS 7.1EG 7.12024-01-11
Nginx-UI is a web interface to manage Nginx configurations. It is vulnerable to arbitrary command execution by abusing the configuration settings. The `Home > Preference` page exposes a list of system settings such as `Run Mode`, `Jwt Secr…
- CVE-2024-22246HIGHCVSS 7.4EG 7.42024-04-02
VMware SD-WAN Edge contains an unauthenticated command injection vulnerability potentially leading to remote code execution. A malicious actor with local access to the Edge Router UI during activation may be able to perform a command inj…
- CVE-2024-22529CRITICALCVSS 9.8EG 9.82024-01-25
TOTOLINK X2000R_V2 V2.0.0-B20230727.10434 has a command injection vulnerability in the sub_449040 (handle function of formUploadFile) of /bin/boa.
- CVE-2024-22544HIGHCVSS 8.0EG 8.02024-02-27
An issue was discovered in Linksys Router E1700 version 1.0.04 (build 3), allows authenticated attackers to execute arbitrary code via the setDateTime function.
- CVE-2024-22545HIGHCVSS 7.8EG 7.82024-01-26
An issue was discovered in TRENDnet TEW-824DRU version 1.04b01, allows unauthenticated attackers to execute arbitrary code via the system.ntp.server parameter in the sub_420AE0() function. The attack can be launched remotely.
- CVE-2024-22546MEDIUMCVSS 6.4EG 6.42024-04-30
TRENDnet TEW-815DAP 1.0.2.0 is vulnerable to Command Injection via the do_setNTP function. An authenticated attacker with administrator privileges can leverage this vulnerability over the network via a malicious POST request.
- CVE-2024-22651CRITICALCVSS 9.8EG 9.82024-01-24
There is a command injection vulnerability in the ssdpcgi_main function of cgibin binary in D-Link DIR-815 router firmware v1.04.
- CVE-2024-22663CRITICALCVSS 9.8EG 9.82024-01-23
TOTOLINK_A3700R_V9.1.2u.6165_20211012has a command Injection vulnerability via setOpModeCfg
- CVE-2024-22729CRITICALCVSS 9.8EG 9.82024-01-25
NETIS SYSTEMS MW5360 V1.0.1.3031 was discovered to contain a command injection vulnerability via the password parameter on the login page.
- CVE-2024-22900HIGHCVSS 8.8EG 8.82024-02-02
Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the setNetworkCardInfo function.
- CVE-2024-22903HIGHCVSS 8.8EG 8.82024-02-02
Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the deleteUpdateAPK function.
- CVE-2024-23049CRITICALCVSS 9.8EG 9.82024-02-05
An issue in symphony v.3.6.3 and before allows a remote attacker to execute arbitrary code via the log4j component.
- CVE-2024-23247HIGHCVSS 7.8EG 7.82024-03-08
The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5. Processing a file may lead to unexpected app termination or arbitrary code execution.
- CVE-2024-23346CRITICALCVSS 9.3EG 9.32024-02-21
Pymatgen (Python Materials Genomics) is an open-source Python library for materials analysis. A critical security vulnerability exists in the `JonesFaithfulTransformation.from_transformation_str()` method within the `pymatgen` library prio…
- CVE-2024-2352MEDIUMCVSS 6.3EG 6.32024-03-10
A vulnerability, which was classified as critical, has been found in 1Panel up to 1.10.1-lts. Affected by this issue is the function baseApi.UpdateDeviceSwap of the file /api/v1/toolbox/device/update/swap. The manipulation of the argument …
- CVE-2024-23624CRITICALCVSS 9.6EG 9.62024-01-26
A command injection vulnerability exists in the gena.cgi module of D-Link DAP-1650 devices. An unauthenticated attacker can exploit this vulnerability to gain command execution on the device as root.
- CVE-2024-23625CRITICALCVSS 9.6EG 9.62024-01-26
A command injection vulnerability exists in D-Link DAP-1650 devices when handling UPnP SUBSCRIBE messages. An unauthenticated attacker can exploit this vulnerability to gain command execution on the device as root.
- CVE-2024-23626CRITICALCVSS 9.0EG 9.02024-01-26
A command injection vulnerability exists in the ‘SaveSysLogParams’ parameter of the Motorola MR2600. A remote attacker can exploit this vulnerability to achieve command execution. Authentication is required, however can be bypassed.
- CVE-2024-23627CRITICALCVSS 9.0EG 9.02024-01-26
A command injection vulnerability exists in the 'SaveStaticRouteIPv4Params' parameter of the Motorola MR2600. A remote attacker can exploit this vulnerability to achieve command execution. Authentication is required, however can be bypasse…
- CVE-2024-23628CRITICALCVSS 9.0EG 9.02024-01-26
A command injection vulnerability exists in the 'SaveStaticRouteIPv6Params' parameter of the Motorola MR2600. A remote attacker can exploit this vulnerability to achieve command execution. Authentication is required, however can be bypa…
- CVE-2024-2366CRITICALCVSS 9.0EG 9.02024-05-16
A remote code execution vulnerability exists in the parisneo/lollms-webui application, specifically within the reinstall_binding functionality in lollms_core/lollms/server/endpoints/lollms_binding_infos.py of the latest version. The vulner…
- CVE-2024-23745CRITICALCVSS 9.8EG 9.82024-01-31
In Notion Web Clipper 1.0.3(7), a .nib file is susceptible to the Dirty NIB attack. NIB files can be manipulated to execute arbitrary commands. Additionally, even if a NIB file is modified within an application, Gatekeeper may still permit…
- CVE-2024-23749HIGHCVSS 7.8EG 7.82024-02-09
KiTTY versions 0.76.1.13 and before is vulnerable to command injection via the filename variable, occurs due to insufficient input sanitization and validation, failure to escape special characters, and insecure system calls (at lines 2369-…
- CVE-2024-23971HIGHCVSS 8.8EG 8.82025-01-31
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists wi…
- CVE-2024-24216CRITICALCVSS 9.8EG 9.82024-02-08
Zentao v18.0 to v18.10 was discovered to contain a remote code execution (RCE) vulnerability via the checkConnection method of /app/zentao/module/repo/model.php.
- CVE-2024-24301HIGHCVSS 8.8EG 8.82024-02-14
Command Injection vulnerability discovered in 4ipnet EAP-767 device v3.42.00 within the web interface of the device allows attackers with valid credentials to inject arbitrary shell commands to be executed by the device with root privilege…
- CVE-2024-24321CRITICALCVSS 9.8EG 9.82024-02-08
An issue in Dlink DIR-816A2 v.1.10CNB05 allows a remote attacker to execute arbitrary code via the wizardstep4_ssid_2 parameter in the sub_42DA54 function.
- CVE-2024-24377CRITICALCVSS 9.8EG 9.82024-02-16
An issue in idocv v.14.1.3_20231228 allows a remote attacker to execute arbitrary code and obtain sensitive information via a crafted script.
- CVE-2024-24550HIGHCVSS 8.1EG 8.12024-06-24
A security vulnerability has been identified in Bludit, allowing attackers with knowledge of the API token to upload arbitrary files through the File API which leads to arbitrary code execution on the server. This vulnerability arises from…
Map vulnerabilities like CWE-77 to your infrastructure
EchelonGraph correlates every CVE — across CWE-77 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →