CWE-77— Command Injection
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.— MITRE CWE catalog
4,102 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-77page 46 of 83
- CVE-2024-24551HIGHCVSS 8.8EG 8.82024-06-24
A security vulnerability has been identified in Bludit, allowing authenticated attackers to execute arbitrary code through the Image API. This vulnerability arises from improper handling of file uploads, enabling malicious actors to upload…
- CVE-2024-24897HIGHCVSS 8.1EG 8.12024-03-25
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in openEuler A-Tune-Collector on Linux allows Command Injection. This vulnerability is associated with program files https://gitee.Com/openeu…
- CVE-2024-24909HIGHCVSS 8.8EG 8.82026-06-16
Dell OpenManage Integration with Microsoft Windows Admin Center contains a Remote Code Execution vulnerability in the gateway plugin. A remote authenticated user could potentially exploit this vulnerability to escalate privileges. The mali…
- CVE-2024-25081MEDIUMCVSS 4.2EG 4.22024-02-26
Splinefont in FontForge through 20230101 allows command injection via crafted filenames.
- CVE-2024-25082MEDIUMCVSS 6.5EG 6.52024-02-26
Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files.
- CVE-2024-25228HIGHCVSS 8.8EG 8.82024-03-14
Vinchin Backup and Recovery 7.2 and Earlier is vulnerable to Authenticated Remote Code Execution (RCE) via the getVerifydiyResult function in ManoeuvreHandler.class.php.
- CVE-2024-25255CRITICALCVSS 9.8EG 9.82024-11-11
Sublime Text 4 was discovered to contain a command injection vulnerability via the New Build System module. NOTE: multiple third parties report that this is intended behavior.
- CVE-2024-25611HIGHCVSS 7.2EG 7.22024-03-05
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operat…
- CVE-2024-25612HIGHCVSS 7.2EG 7.22024-03-05
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operat…
- CVE-2024-25613HIGHCVSS 7.2EG 7.22024-03-05
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operat…
- CVE-2024-25639MEDIUMCVSS 5.9EG 5.92024-07-08
Khoj is an application that creates personal AI agents. The Khoj Obsidian, Desktop and Web clients inadequately sanitize the AI model's response and user inputs. This can trigger Cross Site Scripting (XSS) via Prompt Injection from untrust…
- CVE-2024-25850CRITICALCVSS 9.8EG 9.82024-02-22
Netis WF2780 v2.1.40144 was discovered to contain a command injection vulnerability via the wps_ap_ssid5g parameter
- CVE-2024-25946HIGHCVSS 7.2EG 7.22024-03-28
Dell vApp Manager, versions prior to 9.2.4.9 contain a Command Injection Vulnerability. An authorized attacker could potentially exploit this vulnerability leading to an execution of an inserted command. Dell recommends customers to upgrad…
- CVE-2024-25951HIGHCVSS 8.0EG 8.02024-03-09
A command injection vulnerability exists in local RACADM. A malicious authenticated user could gain control of the underlying operating system.
- CVE-2024-25955HIGHCVSS 7.2EG 7.22024-03-28
Dell vApp Manager, versions prior to 9.2.4.9 contain a Command Injection Vulnerability. An authorized attacker could potentially exploit this vulnerability leading to an execution of an inserted command. Dell recommends customers to upgrad…
- CVE-2024-25998HIGHCVSS 7.3EG 7.32024-03-12
An unauthenticated remote attacker can perform a command injection in the OCPP Service with limited privileges due to improper input validation.
- CVE-2024-26204HIGHCVSS 7.5EG 7.52024-03-12
Outlook for Android Information Disclosure Vulnerability
- CVE-2024-26294HIGHCVSS 7.2EG 7.22024-02-27
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as…
- CVE-2024-26295HIGHCVSS 7.2EG 7.22024-02-27
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as…
- CVE-2024-26296HIGHCVSS 7.2EG 7.22024-02-27
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as…
- CVE-2024-26297HIGHCVSS 7.2EG 7.22024-02-27
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as…
- CVE-2024-26298HIGHCVSS 7.2EG 7.22024-02-27
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as…
- CVE-2024-2642HIGHCVSS 7.3EG 7.32024-03-19
A vulnerability was found in Ruijie RG-NBS2009G-P up to 20240305. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /EXCU_SHELL. The manipulation of the argument Command1 leads to comm…
- CVE-2024-27763MEDIUMCVSS 5.3EG 5.32025-03-12
XPixelGroup BasicSR through 1.4.2 might locally allow code execution in contrived situations where "scontrol show hostname" is executed in the presence of a crafted SLURM_NODELIST environment variable.
- CVE-2024-27818HIGHCVSS 7.8EG 7.82024-05-14
The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5. An attacker may be able to cause unexpected app termination or arbitrary code executio…
- CVE-2024-27980HIGHCVSS 8.1EG 8.12025-01-09
Due to the improper handling of batch files in child_process.spawn / child_process.spawnSync, a malicious command line argument can inject arbitrary commands and achieve code execution even if the shell option is not enabled.
- CVE-2024-27981CRITICALCVSS 9.8EG 9.82024-04-04
A Command Injection vulnerability found in a Self-Hosted UniFi Network Servers (Linux) with UniFi Network Application (Version 8.0.28 and earlier) allows a malicious actor with UniFi Network Application Administrator credentials to escalat…
- CVE-2024-28041HIGHCVSS 8.8EG 8.82024-03-25
HGW BL1500HM Ver 002.001.013 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary command.
- CVE-2024-28135MEDIUMCVSS 5.0EG 5.02024-05-14
A low privileged remote attacker can use a command injection vulnerability in the API which performs remote code execution as the user-app user due to improper input validation. The confidentiality is partly affected.
- CVE-2024-28136HIGHCVSS 7.8EG 7.82024-05-14
A local attacker with low privileges can use a command injection vulnerability to gain root privileges due to improper input validation using the OCPP Remote service.
- CVE-2024-28328MEDIUMCVSS 5.4EG 5.42024-04-26
CSV Injection vulnerability in the Asus RT-N12+ router allows administrator users to inject arbitrary commands or formulas in the client name parameter which can be triggered and executed in a different user session upon exporting to CSV f…
- CVE-2024-28353HIGHCVSS 8.8EG 8.82024-03-15
There is a command injection vulnerability in the TRENDnet TEW-827DRU router with firmware version 2.10B01. An attacker can inject commands into the post request parameters usapps.config.smb_admin_name in the apply.cgi interface, thereby g…
- CVE-2024-28354CRITICALCVSS 10.0EG 10.02024-03-15
There is a command injection vulnerability in the TRENDnet TEW-827DRU router with firmware version 2.10B01. An attacker can inject commands into the post request parameters usapps.@smb[%d].username in the apply.cgi interface, thereby gaini…
- CVE-2024-28545CRITICALCVSS 9.8EG 9.82024-03-26
Tenda AC18 V15.03.05.05 contains a command injection vulnerablility in the deviceName parameter of formsetUsbUnload function.
- CVE-2024-28726HIGHCVSS 8.0EG 8.02024-11-12
An issue in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME allows a local attacker to execute arbitrary code via a crafted payload to the Diagnostics function.
- CVE-2024-28729CRITICALCVSS 9.8EG 9.82024-11-12
An issue in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME allows a local attacker to execute arbitrary code via a crafted request.
- CVE-2024-28739CRITICALCVSS 7.2EG 9.62024-08-06
An issue in Koha ILS 23.05 and before allows a remote attacker to execute arbitrary code via a crafted script to the format parameter.
- CVE-2024-29269HIGHCVSS 8.8EG 8.82024-04-10
An issue discovered in Telesquare TLR-2005Ksh 1.0.0 and 1.1.4 allows attackers to run arbitrary system commands via the Cmd parameter.
- CVE-2024-29292CRITICALCVSS 9.1EG 9.12024-11-20
Multiple OS Command Injection vulnerabilities affecting Kasda LinkSmart Router KW6512 <= v1.3 enable an authenticated remote attacker to execute arbitrary OS commands via various cgi parameters.
- CVE-2024-29366HIGHCVSS 8.8EG 8.82024-03-22
A command injection vulnerability exists in the cgibin binary in DIR-845L router firmware <= v1.01KRb03.
- CVE-2024-29385CRITICALCVSS 9.0EG 9.02024-03-22
DIR-845L router <= v1.01KRb03 has an Unauthenticated remote code execution vulnerability in the cgibin binary via soapcgi_main function.
- CVE-2024-29404HIGHCVSS 7.8EG 7.82024-12-03
An issue in Razer Synapse 3 v.3.9.131.20813 and Synapse 3 App v.20240213 allows a local attacker to execute arbitrary code via the export parameter of the Chroma Effects function in the Profiles component.
- CVE-2024-29435MEDIUMCVSS 4.1EG 4.12024-04-01
An issue discovered in Alldata v0.4.6 allows attacker to run arbitrary commands via the processId parameter.
- CVE-2024-2947HIGHCVSS 7.3EG 7.32024-03-28
A flaw was found in Cockpit. Deleting a sosreport with a crafted name via the Cockpit web interface can lead to a command injection vulnerability, resulting in privilege escalation. This issue affects Cockpit versions 270 and newer.
- CVE-2024-29737MEDIUMCVSS 4.7EG 4.72024-07-17
In streampark, the project module integrates Maven's compilation capabilities. The input parameter validation is not strict, allowing attackers to insert commands for remote command execution, The prerequisite for a successful attack is th…
- CVE-2024-2982MEDIUMCVSS 5.5EG 5.52024-03-27
A vulnerability has been found in Tenda FH1202 1.2.0.14(408) and classified as critical. Affected by this vulnerability is the function formWriteFacMac of the file /goform/WriteFacMac. The manipulation of the argument mac leads to command …
- CVE-2024-29864CRITICALCVSS 9.8EG 9.82024-03-21
Distrobox before 1.7.0.1 allows attackers to execute arbitrary code via command injection into exported executables.
- CVE-2024-29895CRITICALCVSS 10.0EG 10.02024-05-14
Cacti provides an operational monitoring and fault management framework. A command injection vulnerability on the 1.3.x DEV branch allows any unauthenticated user to execute arbitrary command on the server when `register_argc_argv` option …
- CVE-2024-2991MEDIUMCVSS 6.3EG 6.32024-03-27
A vulnerability has been found in Tenda FH1203 2.0.1.6 and classified as critical. This vulnerability affects the function formWriteFacMac of the file /goform/WriteFacMac. The manipulation of the argument mac leads to command injection. Th…
- CVE-2024-29946HIGHCVSS 8.1EG 8.12024-03-27
In Splunk Enterprise versions below 9.2.1, 9.1.4, and 9.0.9, the Dashboard Examples Hub lacks protections for risky SPL commands. This could let attackers bypass SPL safeguards for risky commands in the Hub. The vulnerability would require…
Map vulnerabilities like CWE-77 to your infrastructure
EchelonGraph correlates every CVE — across CWE-77 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →