CWE-77— Command Injection
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.— MITRE CWE catalog
4,102 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-77page 51 of 83
- CVE-2024-48017MEDIUMCVSS 6.5EG 6.52025-03-17
Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A high privileged attacker with remote acce…
- CVE-2024-48139HIGHCVSS 7.5EG 7.52024-10-24
A prompt injection vulnerability in the chatbox of Blackbox AI v1.3.95 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.
- CVE-2024-48140HIGHCVSS 7.5EG 7.52024-10-24
A prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica Your AI Copilot powered by ChatGPT4 v6.3.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assis…
- CVE-2024-48141HIGHCVSS 7.5EG 7.52024-10-24
A prompt injection vulnerability in the chatbox of Zhipu AI CodeGeeX v2.17.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.
- CVE-2024-48142HIGHCVSS 7.5EG 7.52024-10-24
A prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica ChatGPT AI Assistant v2.4.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a craf…
- CVE-2024-48144CRITICALCVSS 9.1EG 9.12024-10-24
A prompt injection vulnerability in the chatbox of Fusion Chat Chat AI Assistant Ask Me Anything v1.2.4.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted m…
- CVE-2024-48145CRITICALCVSS 9.1EG 9.12024-10-24
A prompt injection vulnerability in the chatbox of Netangular Technologies ChatNet AI Version v1.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.
- CVE-2024-48153CRITICALCVSS 9.8EG 9.82024-10-14
DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the get_subconfig function.
- CVE-2024-48214HIGHCVSS 8.4EG 8.42024-10-30
KERUI HD 3MP 1080P Tuya Camera 1.0.4 has a command injection vulnerability in the module that connects to the local network via a QR code. This vulnerability allows an attacker to create a custom, unauthenticated QR code and abuse one of t…
- CVE-2024-48286HIGHCVSS 8.0EG 8.02024-11-21
Linksys E3000 1.0.06.002_US is vulnerable to command injection via the diag_ping_start function.
- CVE-2024-48288HIGHCVSS 8.0EG 8.02024-11-21
TP-Link TL-IPC42C V4.0_20211227_1.0.16 is vulnerable to command injection due to the lack of malicious code verification on both the frontend and backend.
- CVE-2024-48419HIGHCVSS 8.8EG 8.82025-01-27
Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 suffers from Command Injection issues in /bin/goahead. Specifically, these issues can be triggered through /goform/tracerouteDiagnosis, /goform/pingDiagnosis, and /goform/fromSysToolPin…
- CVE-2024-48440HIGHCVSS 8.8EG 8.82024-10-24
Shenzhen Tuoshi Network Communications Co.,Ltd 5G CPE Router NR500-EA RG500UEAABxCOMSLICv3.2.2543.12.18 was discovered to contain a command injection vulnerability via the component at_command.asp.
- CVE-2024-48441HIGHCVSS 8.8EG 8.82024-10-24
Wuhan Tianyu Information Industry Co., Ltd Tianyu CPE Router CommonCPExCPETS_v3.2.468.11.04_P4 was discovered to contain a command injection vulnerability via the component at_command.asp.
- CVE-2024-48659CRITICALCVSS 9.8EG 9.82024-10-21
An issue in DCME-320-L <=9.3.2.114 allows a remote attacker to execute arbitrary code via the log_u_umount.php component.
- CVE-2024-48705MEDIUMCVSS 6.5EG 6.52025-09-02
Wavlink AC1200 with firmware versions M32A3_V1410_230602 and M32A3_V1410_240222 are vulnerable to a post-authentication command injection while resetting the password. This vulnerability is specifically found within the "set_sys_adm" funct…
- CVE-2024-48746CRITICALCVSS 9.8EG 9.82024-11-05
An issue in Lens Visual integration with Power BI v.4.0.0.3 allows a remote attacker to execute arbitrary code via the Natural language processing component
- CVE-2024-48747MEDIUMCVSS 6.8EG 6.82024-11-21
An issue in alist-tvbox v1.7.1 allows a remote attacker to execute arbitrary code via the /atv-cli file.
- CVE-2024-48761CRITICALCVSS 8.8EG 9.82025-01-29
Reflected XSS vulnerability in Celk Sistemas Celk Saude v.3.1.252.1 allows a remote attacker to inject arbitrary JavaScript code via the "erro" parameter.
- CVE-2024-4883CRITICALCVSS 9.8EG 9.82024-06-25
In WhatsUp Gold versions released before 2023.1.3, a Remote Code Execution issue exists in Progress WhatsUp Gold. This vulnerability allows an unauthenticated attacker to achieve the RCE as a service account through NmApi.exe.
- CVE-2024-48830HIGHCVSS 7.8EG 7.82025-03-17
Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with local access…
- CVE-2024-4884CRITICALCVSS 9.8EG 9.82024-06-25
In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold. The Apm.UI.Areas.APM.Controllers.CommunityController allows execution of commands with iisapppool\nmco…
- CVE-2024-48841CRITICALCVSS 10.0EG 10.02025-01-27
Network access can be used to execute arbitrary code with elevated privileges. This issue affects FLXEON 9.3.4 and older.
- CVE-2024-48860CRITICALCVSS 9.8EG 9.82024-11-22
An OS command injection vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow remote attackers to execute commands. We have already fixed the vulnerability in the following version…
- CVE-2024-48861HIGHCVSS 7.8EG 7.82024-11-22
An OS command injection vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow local network attackers to execute commands. We have already fixed the vulnerability in the following …
- CVE-2024-48904CRITICALCVSS 9.8EG 9.82024-10-22
An command injection vulnerability in Trend Micro Cloud Edge could allow a remote attacker to execute arbitrary code on affected appliances. Please note: authentication is not required in order to exploit this vulnerability.
- CVE-2024-49026HIGHCVSS 7.8EG 7.82024-11-12
Microsoft Excel Remote Code Execution Vulnerability
- CVE-2024-49042HIGHCVSS 7.2EG 7.22024-11-12
Azure Database for PostgreSQL Flexible Server Extension Elevation of Privilege Vulnerability
- CVE-2024-49194HIGHCVSS 7.3EG 7.32024-12-17
Databricks JDBC Driver 2.x before 2.6.40 could potentially allow remote code execution (RCE) by triggering a JNDI injection via a JDBC URL parameter. The vulnerability is rooted in the improper handling of the krbJAASFile parameter. An att…
- CVE-2024-4944HIGHCVSS 7.8EG 7.82024-07-09
A local privilege escalation vlnerability in the WatchGuard Mobile VPN with SSL client on Windows enables a local user to execute arbitrary commands with elevated privileged.
- CVE-2024-49557HIGHCVSS 7.8EG 7.82024-11-12
Dell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with local access…
- CVE-2024-49560HIGHCVSS 7.8EG 7.82024-11-12
Dell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) a command injection vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command e…
- CVE-2024-4999CRITICALCVSS 9.4EG 9.42024-05-16
A vulnerability in the web-based management interface of multiple Ligowave devices could allow an authenticated remote attacker to execute arbitrary commands with elevated privileges.This issue affects UNITY: through 6.95-2; PRO: through …
- CVE-2024-5023CRITICALCVSS 9.3EG 9.32024-05-16
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Netflix ConsoleMe allows Command Injection.This issue affects ConsoleMe: before 1.4.0.
- CVE-2024-5035HIGHCVSS 8.8EG 8.82024-05-27
The affected device expose a network service called "rftest" that is vulnerable to unauthenticated command injection on ports TCP/8888, TCP/8889, and TCP/8890. By successfully exploiting this flaw, remote unauthenticated attacker can gain…
- CVE-2024-50388CRITICALCVSS 9.8EG 9.82024-12-06
An OS command injection vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If exploited, the vulnerability could allow remote attackers to execute commands. We have already fixed the vulnerability in the following version…
- CVE-2024-50572HIGHCVSS 7.2EG 7.22024-11-12
A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2) (All versions < V8.2), SCALANCE M804PB (6GK5804-0AP00-2AA2) (All versions < V8…
- CVE-2024-50591HIGHCVSS 7.8EG 7.82024-11-08
An attacker with local access the to medical office computer can escalate his Windows user privileges to "NT AUTHORITY\SYSTEM" by exploiting a command injection vulnerability in the Elefant Update Service. The command injection can be e…
- CVE-2024-50852HIGHCVSS 8.8EG 8.82024-11-13
Tenda G3 v3.0 v15.11.0.20 was discovered to contain a command injection vulnerability via the formSetUSBPartitionUmount function.
- CVE-2024-50853HIGHCVSS 8.8EG 8.82024-11-13
Tenda G3 v3.0 v15.11.0.20 was discovered to contain a command injection vulnerability via the formSetDebugCfg function.
- CVE-2024-51027MEDIUMCVSS 6.5EG 6.52024-11-13
Ruijie NBR800G gateway NBR_RGOS_11.1(6)B4P9 is vulnerable to command execution in /itbox_pi/networksafe.php via the province parameter.
- CVE-2024-51114HIGHCVSS 8.8EG 8.82024-12-03
An issue in Beijing Digital China Yunke Information Technology Co.Ltd v.7.2.6.120 allows a remote attacker to execute arbitrary code via the code/function/dpi/web_auth/customizable.php file
- CVE-2024-51115CRITICALCVSS 9.8EG 9.82024-11-05
DCME-320 v7.4.12.90 was discovered to contain a command injection vulnerability.
- CVE-2024-51151CRITICALCVSS 9.8EG 9.82024-11-21
D-Link DI-8200 16.07.26A1 is vulnerable to remote command execution in the msp_info_htm function via the flag parameter and cmd parameter.
- CVE-2024-51186HIGHCVSS 8.0EG 8.02024-11-11
D-Link DIR-820L 1.05b03 was discovered to contain a remote code execution (RCE) vulnerability via the ping_addr parameter in the ping_v4 and ping_v6 functions.
- CVE-2024-51254HIGHCVSS 8.8EG 8.82024-10-31
DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the sign_cacertificate function.
- CVE-2024-51255CRITICALCVSS 9.8EG 9.82024-10-31
DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the ruequest_certificate function.
- CVE-2024-51257HIGHCVSS 8.8EG 8.82024-10-30
DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doCertificate function.
- CVE-2024-51258HIGHCVSS 8.8EG 8.82024-10-30
DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doSSLTunnel function.
- CVE-2024-51259CRITICALCVSS 9.8EG 9.82024-10-31
DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the setup_cacertificate function.
Map vulnerabilities like CWE-77 to your infrastructure
EchelonGraph correlates every CVE — across CWE-77 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →