CWE-77— Command Injection
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.— MITRE CWE catalog
4,102 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-77page 50 of 83
- CVE-2024-42947CRITICALCVSS 9.8EG 9.82024-08-15
An issue in the handler function in /goform/telnet of Tenda FH1201 v1.2.0.14 (408) allows attackers to execute arbitrary commands via a crafted HTTP request.
- CVE-2024-43027HIGHCVSS 8.0EG 8.02024-08-21
DrayTek Vigor 3900 before v1.5.1.5_Beta, DrayTek Vigor 2960 before v1.5.1.5_Beta and DrayTek Vigor 300B before v1.5.1.5_Beta were discovered to contain a command injection vulnerability via the action parameter at cgi-bin/mainfunction.cgi.
- CVE-2024-43028CRITICALCVSS 9.8EG 9.82026-04-01
A command injection vulnerability in the component /jmreport/show of jeecg boot v3.0.0 to v3.5.3 allows attackers to execute arbitrary code via a crafted HTTP request.
- CVE-2024-43497HIGHCVSS 8.4EG 8.42024-10-08
DeepSpeed Remote Code Execution Vulnerability
- CVE-2024-43591HIGHCVSS 8.7EG 8.72024-10-08
Azure Command Line Integration (CLI) Elevation of Privilege Vulnerability
- CVE-2024-43601HIGHCVSS 7.8EG 7.82024-10-08
Visual Studio Code for Linux Remote Code Execution Vulnerability
- CVE-2024-43613HIGHCVSS 7.2EG 7.22024-11-12
Azure Database for PostgreSQL Flexible Server Extension Elevation of Privilege Vulnerability
- CVE-2024-43693CRITICALCVSS 10.0EG 10.02024-09-25
A specially crafted POST request to the ProGauge MAGLINK LX CONSOLE UTILITY sub-menu can allow a remote attacker to inject arbitrary commands.
- CVE-2024-44334HIGHCVSS 8.8EG 8.82024-09-09
D-Link DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.04.18D1 are vulnerable to Remote Command Execution due to insufficient parameter filtering…
- CVE-2024-44335HIGHCVSS 8.8EG 8.82024-09-09
D-Link DI-7003G v19.12.24A1, DI-7003GV2 v24.04.18D1, DI-7100G+V2 v24.04.18D1, DI-7100GV2 v24.04.18D1, DI-7200GV2 v24.04.18E1, DI-7300G+V2 v24.04.18D1, and DI-7400G+V2 v24.04.18D1 are vulnerable to Remote Command Execution (RCE) via version…
- CVE-2024-44381CRITICALCVSS 9.8EG 9.82024-08-23
D-Link DI_8004W 16.07.26A1 contains a command execution vulnerability in jhttpd msp_info_htm function.
- CVE-2024-44382CRITICALCVSS 9.8EG 9.82024-08-23
D-Link DI_8004W 16.07.26A1 contains a command execution vulnerability in the jhttpd upgrade_filter_asp function.
- CVE-2024-44383HIGHCVSS 6.8EG 8.02024-09-04
WAYOS FBM-291W v19.09.11 is vulnerable to Command Execution via msp_info_htm.
- CVE-2024-44400CRITICALCVSS 9.8EG 9.82024-09-04
A vulnerability was discovered in DI_8400-16.07.26A1, which has been classified as critical. This issue affects the upgrade_filter_asp function in the upgrade_filter.asp file. Manipulation of the path parameter can lead to command injectio…
- CVE-2024-44401CRITICALCVSS 9.8EG 9.82024-09-06
D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via sub47A60C function in the upgrade_filter.asp file
- CVE-2024-44402CRITICALCVSS 9.8EG 9.82024-09-06
D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via msp_info.htm.
- CVE-2024-44410CRITICALCVSS 9.8EG 9.82024-09-09
D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the upgrade_filter_asp function.
- CVE-2024-44413HIGHCVSS 8.8EG 8.82024-10-11
A vulnerability was discovered in DI_8200-16.07.26A1, which has been classified as critical. This issue affects the upgrade_filter_asp function in the upgrade_filter.asp file. Manipulation of the path parameter can lead to command injectio…
- CVE-2024-44466CRITICALCVSS 9.8EG 9.82024-09-11
COMFAST CF-XR11 V2.7.2 has a command injection vulnerability in function sub_424CB4. Attackers can send POST request messages to /usr/bin/webmgnt and inject commands into parameter iface.
- CVE-2024-44570HIGHCVSS 8.8EG 8.82024-09-11
RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a code injection vulnerability via the getParams function in phpinf.php.
- CVE-2024-44572HIGHCVSS 8.8EG 8.82024-09-11
RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the sys_mgmt function.
- CVE-2024-44574HIGHCVSS 8.8EG 8.82024-09-11
RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the sys_conf function.
- CVE-2024-44577HIGHCVSS 8.8EG 8.82024-09-11
RELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a command injection vulnerability via the time_date function.
- CVE-2024-44610MEDIUMCVSS 5.6EG 5.62024-10-01
PCAN-Ethernet Gateway FD before 1.3.0 and PCAN-Ethernet Gateway before 2.11.0 are vulnerable to Command injection via shell metacharacters in a Software Update to processing.php.
- CVE-2024-44844HIGHCVSS 8.8EG 8.82024-09-06
DrayTek Vigor3900 v1.5.1.6 was discovered to contain an authenticated command injection vulnerability via the name parameter in the run_command function.
- CVE-2024-44845HIGHCVSS 8.8EG 8.82024-09-06
DrayTek Vigor3900 v1.5.1.6 was discovered to contain an authenticated command injection vulnerability via the value parameter in the filter_string function.
- CVE-2024-44916HIGHCVSS 7.2EG 7.22024-08-30
Vulnerability in admin_ip.php in Seacms v13.1, when action=set, allows attackers to control IP parameters that are written to the data/admin/ip.php file and could result in arbitrary command execution.
- CVE-2024-45066CRITICALCVSS 10.0EG 10.02024-09-25
A specially crafted POST request to the ProGauge MAGLINK LX CONSOLE IP sub-menu can allow a remote attacker to inject arbitrary commands.
- CVE-2024-45257HIGHCVSS 7.3EG 7.32026-05-08
A Command Injection issue in the payload build page in BYOB (Build Your Own Botnet) 2.0 allows attackers to execute arbitrary commands on the server via a crafted build parameter. This occurs in freeze in core/generators.py.
- CVE-2024-45348MEDIUMCVSS 6.4EG 6.42024-09-23
Xiaomi Router AX9000 has a post-authorization command injection vulnerability. This vulnerability is caused by the lack of validation of user input, and an attacker can exploit this vulnerability to execute arbitrary code.
- CVE-2024-45505HIGHCVSS 8.8EG 8.82024-11-18
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache HertzBeat (incubating). This vulnerability can only be exploited by authorized attackers. This issue affects Apache HertzBeat (inc…
- CVE-2024-45682HIGHCVSS 8.8EG 8.82024-09-17
There is a command injection vulnerability that may allow an attacker to inject malicious input on the device's operating system.
- CVE-2024-4578HIGHCVSS 8.4EG 8.42024-06-27
This Advisory describes an issue that impacts Arista Wireless Access Points. Any entity with the ability to authenticate via SSH to an affected AP as the “config” user is able to cause a privilege escalation via spawning a bash shell. …
- CVE-2024-45824CRITICALCVSS 9.8EG 9.82024-09-12
CVE-2024-45824 IMPACT A remote code vulnerability exists in the affected products. The vulnerability occurs when chained with Path Traversal, Command Injection, and XSS Vulnerabilities and allows for full unauthenticated remote code exe…
- CVE-2024-45989MEDIUMCVSS 4.0EG 4.02024-09-26
Monica AI Assistant desktop application v2.3.0 is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor. A prompt injection allows an attacker to modify chatbot answer with an unloaded image that exfiltrates the user's s…
- CVE-2024-46048CRITICALCVSS 9.8EG 9.82024-09-13
Tenda FH451 v1.0.0.9 has a command injection vulnerability in the formexeCommand function i
- CVE-2024-46060HIGHCVSS 7.8EG 7.82025-12-17
Anaconda3 macOS installers before 2024.06-1 contain a local privilege escalation vulnerability when installed outside the user's home directory. During installation, world-writable files are created and executed with root privileges. This …
- CVE-2024-46062HIGHCVSS 7.8EG 7.82025-12-17
Miniconda3 macOS installers before 23.11.0-1 contain a local privilege escalation vulnerability when installed outside the user's home directory. During installation, world-writable files are created and executed with root privileges. This…
- CVE-2024-46084HIGHCVSS 8.0EG 8.02024-10-01
Scriptcase 9.10.023 and before is vulnerable to Remote Code Execution (RCE) via the nm_unzip function.
- CVE-2024-46089MEDIUMCVSS 6.3EG 6.32025-04-18
74cms <=3.33 is vulnerable to remote code execution (RCE) in the background interface apiadmin.
- CVE-2024-46256CRITICALCVSS 9.8EG 9.82024-09-27
A Command injection vulnerability in requestLetsEncryptSsl in NginxProxyManager 2.11.3 allows an attacker to RCE via Add Let's Encrypt Certificate.
- CVE-2024-4638HIGHCVSS 7.1EG 7.12024-06-25
OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to a lack of neutralized inputs in the web key upload function. An attacker could modify the intended commands sent to target functions, whi…
- CVE-2024-4639HIGHCVSS 7.1EG 7.12024-06-25
OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to a lack of neutralized inputs in IPSec configuration. An attacker could modify the intended commands sent to target functions, which could…
- CVE-2024-46662HIGHCVSS 8.8EG 8.82025-03-14
A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiManager versions 7.4.1 through 7.4.3, FortiManager Cloud versions 7.4.1 through 7.4.3 allows attacker to escalation of privilege via spe…
- CVE-2024-4712HIGHCVSS 7.8EG 7.82024-05-14
An arbitrary file creation vulnerability exists in PaperCut NG/MF that only affects Windows servers with Web Print enabled. This specific flaw exists within the image-handler process, which can incorrectly create files that don’t exist …
- CVE-2024-47460CRITICALCVSS 9.0EG 9.02024-11-05
Command injection vulnerability in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Success…
- CVE-2024-47461HIGHCVSS 7.2EG 7.22024-11-05
An authenticated command injection vulnerability exists in the Instant AOS-8 and AOS-10 command line interface. A successful exploitation of this vulnerability results in the ability to execute arbitrary commands as a privileged user on th…
- CVE-2024-4748HIGHCVSS 8.8EG 8.82024-06-24
The CRUDDIY project is vulnerable to shell command injection via sending a crafted POST request to the application server. The exploitation risk is limited since CRUDDIY is meant to be launched locally. Nevertheless, a user with the proj…
- CVE-2024-47562HIGHCVSS 8.8EG 8.82024-10-08
A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly neutralize special elements in user input to the ```ssmctl-client``` command. This could allow an authentica…
- CVE-2024-48015MEDIUMCVSS 6.7EG 6.72025-03-17
Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A high privileged attacker with local acces…
Map vulnerabilities like CWE-77 to your infrastructure
EchelonGraph correlates every CVE — across CWE-77 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →