CWE-77— Command Injection
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.— MITRE CWE catalog
4,102 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-77page 47 of 83
- CVE-2024-29949HIGHCVSS 7.2EG 7.22024-04-02
There is a command injection vulnerability in some Hikvision NVRs. This could allow an authenticated user with administrative rights to execute arbitrary commands.
- CVE-2024-3009MEDIUMCVSS 6.3EG 6.32024-03-28
A vulnerability has been found in Tenda FH1205 2.0.0.7(775) and classified as critical. Affected by this vulnerability is the function formWriteFacMac of the file /goform/WriteFacMac. The manipulation of the argument mac leads to command i…
- CVE-2024-30167MEDIUMCVSS 6.3EG 6.32026-05-08
/cgi-bin/time.cgi in Atlona AT-OME-MS42 Matrix Switcher 1.1.2 allow remote authenticated users to execute arbitrary commands as root via a POST request that carries a serverName parameter.
- CVE-2024-30213HIGHCVSS 8.8EG 8.82024-07-12
StoneFly Storage Concentrator (SC and SCVM) before 8.0.4.26 allows remote authenticated users to achieve Command Injection via a Ping URL, leading to remote code execution.
- CVE-2024-30220HIGHCVSS 8.8EG 8.82024-04-15
Command injection vulnerability in PLANEX COMMUNICATIONS wireless LAN routers allows a network-adjacent unauthenticated attacker to execute an arbitrary command by sending a specially crafted request to a certain port. Note that MZK-MF300N…
- CVE-2024-30368HIGHCVSS 8.8EG 8.82024-06-06
A10 Thunder ADC CsrRequestView Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of A10 Thunder ADC. Authentication is required to exploit …
- CVE-2024-30572HIGHCVSS 8.0EG 8.02024-04-03
Netgear R6850 1.1.0.88 was discovered to contain a command injection vulnerability via the ntp_server parameter.
- CVE-2024-30637HIGHCVSS 8.8EG 8.82024-03-29
Tenda F1202 v1.2.0.20(408) has a command injection vulnerablility in the formWriteFacMac function in the mac parameter.
- CVE-2024-30891HIGHCVSS 8.8EG 8.82024-04-05
A command injection vulnerability exists in /goform/exeCommand in Tenda AC18 v15.03.05.05, which allows attackers to construct cmdinput parameters for arbitrary command execution.
- CVE-2024-3116HIGHCVSS 7.4EG 8.42024-04-04
pgAdmin <= 8.4 is affected by a Remote Code Execution (RCE) vulnerability through the validate binary path API. This vulnerability allows attackers to execute arbitrary code on the server hosting PGAdmin, posing a severe risk to the datab…
- CVE-2024-31485HIGHCVSS 7.2EG 7.22024-05-14
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V5.30), SICORE Base system (All versions < V1.3.0). The web interface of affected devices is vulnerable to command injection due to missing serv…
- CVE-2024-3154HIGHCVSS 7.2EG 7.22024-04-26
A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation. Any user who can create a pod with an arbitrary annotation may perform an arbitrary action on the host system.
- CVE-2024-31811HIGHCVSS 8.0EG 8.02024-04-08
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the langType parameter in the setLanguageCfg function.
- CVE-2024-32022CRITICALCVSS 9.1EG 9.12024-04-16
Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to command injection in basic_caption_gui.py. This vulnerability is fixed in 23.1.5.
- CVE-2024-32025CRITICALCVSS 9.1EG 9.12024-04-16
Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to a command injection in `group_images_gui.py`. This vulnerability is fixed in 23.1.5.
- CVE-2024-32026CRITICALCVSS 9.1EG 9.12024-04-16
Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss is vulnerable to a command injection in `git_caption_gui.py`. This vulnerability is fixed in 23.1.5.
- CVE-2024-32027CRITICALCVSS 9.1EG 9.12024-04-16
Kohya_ss is a GUI for Kohya's Stable Diffusion trainers. Kohya_ss v22.6.1 is vulnerable to command injection in `finetune_gui.py` This vulnerability is fixed in 23.1.5.
- CVE-2024-32281HIGHCVSS 8.8EG 8.82024-04-17
Tenda AC7V1.0 v15.03.06.44 firmware contains a command injection vulnerablility in formexeCommand function via the cmdinput parameter.
- CVE-2024-32282MEDIUMCVSS 6.3EG 6.32024-04-17
Tenda FH1202 v1.2.0.14(408) firmware contains a command injection vulnerablility in the formexeCommand function via the cmdinput parameter.
- CVE-2024-32283HIGHCVSS 7.3EG 7.32024-04-17
Tenda FH1203 V2.0.1.6 firmware has a command injection vulnerablility in formexeCommand function via the cmdinput parameter.
- CVE-2024-32292HIGHCVSS 8.8EG 8.82024-04-17
Tenda W30E v1.0 V1.0.1.25(633) firmware contains a command injection vulnerablility in the formexeCommand function via the cmdinput parameter.
- CVE-2024-32314LOWCVSS 3.8EG 3.82024-04-17
Tenda AC500 V2.0.1.9(1307) firmware contains a command injection vulnerablility in the formexeCommand function via the cmdinput parameter.
- CVE-2024-32349MEDIUMCVSS 6.0EG 6.02024-05-14
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "mtu" parameters in the "cstecgi.cgi" binary.
- CVE-2024-32353CRITICALCVSS 9.8EG 9.82024-05-14
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'port' parameter in the setSSServer function at /cgi-bin/cstecgi.cgi.
- CVE-2024-32354MEDIUMCVSS 6.0EG 6.02024-05-14
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'timeout' parameter in the setSSServer function at /cgi-bin/cstecgi.cgi.
- CVE-2024-32355HIGHCVSS 8.0EG 8.02024-05-14
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain a command injection vulnerability via the 'password' parameter in the setSSServer function.
- CVE-2024-3271CRITICALCVSS 9.8EG 9.82024-04-16
A command injection vulnerability exists in the run-llama/llama_index repository, specifically within the safe_eval function. Attackers can bypass the intended security mechanism, which checks for the presence of underscores in code genera…
- CVE-2024-3273CRITICALCVSS 7.3EG 9.0⚠ KEV2024-04-04
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-320L, DNS-325, DNS-327L and DNS-340L up to 20240403. Affected is an unknown function of the file /cgi-bin/nas_sharing.cgi of the com…
- CVE-2024-32766CRITICALCVSS 10.0EG 10.02024-04-26
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the …
- CVE-2024-32884MEDIUMCVSS 6.4EG 6.42024-04-26
gitoxide is a pure Rust implementation of Git. `gix-transport` does not check the username part of a URL for text that the external `ssh` program would interpret as an option. A specially crafted clone URL can smuggle options to SSH. The p…
- CVE-2024-33112CRITICALCVSS 7.5EG 9.82024-05-06
D-Link DIR-845L router v1.01KRb03 and before is vulnerable to Command injection via the hnap_main()func.
- CVE-2024-33113MEDIUMCVSS 5.3EG 5.32024-05-06
D-LINK DIR-845L <=v1.01KRb03 is vulnerable to Information disclosurey via bsc_sms_inbox.php.
- CVE-2024-33342HIGHCVSS 7.5EG 7.52024-04-26
D-Link DIR-822+ V1.0.5 was found to contain a command injection in SetPlcNetworkpwd function of prog.cgi, which allows remote attackers to execute arbitrary commands via shell.
- CVE-2024-33344CRITICALCVSS 9.8EG 9.82024-04-26
D-Link DIR-822+ V1.0.5 was found to contain a command injection in ftext function of upload_firmware.cgi, which allows remote attackers to execute arbitrary commands via shell.
- CVE-2024-33439CRITICALCVSS 9.1EG 9.12024-11-20
An issue in Kasda LinkSmart Router KW5515 v1.7 and before allows an authenticated remote attacker to execute arbitrary OS commands via cgi parameters.
- CVE-2024-33469HIGHCVSS 7.9EG 7.92025-02-11
An issue in Team Amaze Amaze File Manager v.3.8.5 and fixed in v.3.10 allows a local attacker to execute arbitrary code via the onCreate method of DatabaseViewerActivity.java.
- CVE-2024-33508HIGHCVSS 7.3EG 7.32024-09-10
An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in Fortinet FortiClientEMS 7.2.0 through 7.2.4, 7.0.0 through 7.0.12 may allow an unauthenticated attacker to execute limited an…
- CVE-2024-33788HIGHCVSS 8.0EG 8.02024-05-06
Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the PinCode parameter at /API/info form endpoint.
- CVE-2024-33789CRITICALCVSS 9.8EG 9.82024-05-03
Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the ipurl parameter at /API/info form endpoint.
- CVE-2024-3400CRITICALCVSS 10.0EG 10.0⚠ KEV2024-04-12
A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated atta…
- CVE-2024-34166CRITICALCVSS 10.0EG 10.02025-01-14
An os command injection vulnerability exists in the touchlist_sync.cgi touchlistsync() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted set of HTTP requests can lead to arbitrary code execution. An attacker can send …
- CVE-2024-34204CRITICALCVSS 9.8EG 9.82024-05-14
TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the setUpgradeFW function via the FileName parameter.
- CVE-2024-34206MEDIUMCVSS 6.5EG 6.52024-05-14
TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the setWebWlanIdx function via the webWlanIdx parameter.
- CVE-2024-34218LOWCVSS 3.8EG 3.82024-05-14
TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the NTPSyncWithHost function via the hostTime parameter.
- CVE-2024-34338HIGHCVSS 7.2EG 7.22024-05-14
Tenda O3V2 with firmware versions V1.0.0.10 and V1.0.0.12 was discovered to contain a Blind Command Injection via dest parameter in /goform/getTraceroute. This vulnerability allows attackers to execute arbitrary commands with root privileg…
- CVE-2024-34347HIGHCVSS 8.3EG 8.32024-05-08
@hoppscotch/cli is a CLI to run Hoppscotch Test Scripts in CI environments. Prior to 0.8.0, the @hoppscotch/js-sandbox package provides a Javascript sandbox that uses the Node.js vm module. However, the vm module is not safe for sandboxing…
- CVE-2024-34352MEDIUMCVSS 6.5EG 6.52024-05-14
1Panel is an open source Linux server operation and maintenance management panel. Prior to v1.10.3-lts, there are many command injections in the project, and some of them are not well filtered, leading to arbitrary file writes, and ultima…
- CVE-2024-34713LOWCVSS 3.5EG 3.52024-05-14
sshproxy is used on a gateway to transparently proxy a user SSH connection on the gateway to an internal host via SSH. Prior to version 1.6.3, any user authorized to connect to a ssh server using `sshproxy` can inject options to the `ssh` …
- CVE-2024-34792CRITICALCVSS 9.1EG 9.12024-06-04
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in dexta Dextaz Ping allows Command Injection.This issue affects Dextaz Ping: from n/a through 0.65.
- CVE-2024-3483HIGHCVSS 7.8EG 7.82024-05-15
Remote Code Execution has been discovered in OpenText™ iManager 3.2.6.0200. The vulnerability can trigger command injection and insecure deserialization issues.
Map vulnerabilities like CWE-77 to your infrastructure
EchelonGraph correlates every CVE — across CWE-77 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →