CWE-77— Command Injection
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.— MITRE CWE catalog
4,102 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-77page 52 of 83
- CVE-2024-51260CRITICALCVSS 9.8EG 9.82024-10-31
DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the acme_process function.
- CVE-2024-51296HIGHCVSS 8.8EG 8.82024-10-30
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the pingtrace function.
- CVE-2024-51299HIGHCVSS 8.8EG 8.82024-10-30
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the dumpSyslog function.
- CVE-2024-51300HIGHCVSS 8.8EG 8.82024-10-30
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the get_rrd function.
- CVE-2024-51301HIGHCVSS 8.8EG 8.82024-10-30
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the packet_monitor function.
- CVE-2024-51304HIGHCVSS 8.8EG 8.82024-10-30
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the ldap_search_dn function.
- CVE-2024-51317MEDIUMCVSS 6.5EG 6.52025-11-03
An issue in NetSurf v.3.11 allows a remote attacker to execute arbitrary code via the dom_node_normalize function
- CVE-2024-51378CRITICALCVSS 10.0EG 10.0⚠ KEV2024-10-29
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or /ftp/getresetstatus by bypassing secM…
- CVE-2024-51442HIGHCVSS 8.8EG 8.82025-01-08
Command Injection in Minidlna version v1.3.3 and before allows an attacker to execute arbitrary OS commands via a specially crafted minidlna.conf configuration file.
- CVE-2024-51503HIGHCVSS 8.0EG 8.02024-11-19
A security agent manual scan command injection vulnerability in the Trend Micro Deep Security 20 Agent could allow an attacker to escalate privileges and execute arbitrary code on an affected machine. In certain circumstances, attackers t…
- CVE-2024-51736UnratedEG 0.02024-11-06
Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. On Windows, when an executable file named `cmd.exe` is located in the current working directory it will be called by the `Process` class …
- CVE-2024-51771HIGHCVSS 7.2EG 7.22024-12-03
A vulnerability in the HPE Aruba Networking ClearPass Policy Manager web-based management interface could allow an authenticated remote threat actor to conduct a remote code execution attack. Successful exploitation could enable the attack…
- CVE-2024-51772MEDIUMCVSS 6.4EG 6.42024-12-03
An authenticated RCE vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation could allow an attacker to execut…
- CVE-2024-5194MEDIUMCVSS 4.7EG 4.72024-05-22
A vulnerability was found in Arris VAP2500 08.50. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /assoc_table.php. The manipulation of the argument id leads to command injection. Th…
- CVE-2024-51941HIGHCVSS 8.8EG 8.82025-01-21
A remote code injection vulnerability exists in the Ambari Metrics and AMS Alerts feature, allowing authenticated users to inject and execute arbitrary code. The vulnerability occurs when processing alert definitions, where malicious in…
- CVE-2024-5195MEDIUMCVSS 4.7EG 4.72024-05-22
A vulnerability was found in Arris VAP2500 08.50. It has been rated as critical. Affected by this issue is some unknown functionality of the file /diag_s.php. The manipulation of the argument customer_info leads to command injection. The a…
- CVE-2024-5196MEDIUMCVSS 4.7EG 4.72024-05-22
A vulnerability classified as critical has been found in Arris VAP2500 08.50. This affects an unknown part of the file /tools_command.php. The manipulation of the argument cmb_header/txt_command leads to command injection. It is possible t…
- CVE-2024-52011HIGHCVSS 8.3EG 8.32026-06-01
launch-editor allows users to open files with line numbers in editor from Node.js. Prior to version 2.9.0, due to the insufficient sanitization of the `file` argument in the `launchEditor`, an attacker can execute arbitrary commands on Win…
- CVE-2024-52022HIGHCVSS 8.0EG 8.02024-11-05
Netgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to contain a command injection vulnerability in the component wlg_adv.cgi via the apmode_gateway parameter. This vulnerability allows atta…
- CVE-2024-52308HIGHCVSS 8.0EG 8.02024-11-14
The GitHub CLI version 2.6.1 and earlier are vulnerable to remote code execution through a malicious codespace SSH server when using `gh codespace ssh` or `gh codespace logs` commands. This has been patched in the cli v2.62.0. Developers …
- CVE-2024-52325CRITICALCVSS 9.6EG 9.62025-01-23
ECOVACS robot lawnmowers and vacuums are vulnerable to command injection via SetNetPin() over an unauthenticated BLE connection.
- CVE-2024-52739HIGHCVSS 8.0EG 8.02024-11-20
D-LINK DI-8400 v16.07.26A1 was discovered to contain multiple remote command execution (RCE) vulnerabilities in the msp_info_htm function via the flag and cmd parameters.
- CVE-2024-53290HIGHCVSS 8.4EG 8.42024-12-11
Dell ThinOS version 2408 contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to …
- CVE-2024-53305HIGHCVSS 7.3EG 7.32025-04-16
An issue in the component /models/config.py of Whoogle search v0.9.0 allows attackers to execute arbitrary code via supplying a crafted search query.
- CVE-2024-53333MEDIUMCVSS 6.3EG 6.32024-11-21
TOTOLINK EX200 v4.0.3c.7646_B20201211 was found to contain a command insertion vulnerability in the setUssd function. This vulnerability allows an attacker to execute arbitrary commands via the "ussd" parameter.
- CVE-2024-53412HIGHCVSS 8.4EG 8.42026-04-15
Command injection in the connect function in NietThijmen ShoppingCart 0.0.2 allows an attacker to execute arbitrary shell commands and achieve remote code execution via injection of malicious payloads into the Port field
- CVE-2024-53526MEDIUMCVSS 6.4EG 6.42025-01-08
composio >=0.5.40 is vulnerable to Command Execution in composio_openai, composio_claude, and composio_julep via the handle_tool_calls function.
- CVE-2024-5355MEDIUMCVSS 6.3EG 6.32024-05-26
A vulnerability, which was classified as critical, has been found in anji-plus AJ-Report up to 1.4.1. This issue affects the function IGroovyHandler. The manipulation leads to command injection. The attack may be initiated remotely. The ex…
- CVE-2024-53615MEDIUMCVSS 6.5EG 6.52025-01-30
A command injection vulnerability in the video thumbnail rendering component of Karl Ward's files.gallery v0.3.0 through 0.11.0 allows remote attackers to execute arbitrary code via a crafted video file.
- CVE-2024-53672MEDIUMCVSS 4.7EG 4.72024-12-03
A vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploit could allow an attacker to execute arbitrary commands as …
- CVE-2024-53692MEDIUMCVSS 4.7EG 4.72025-03-07
A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute arbitrary commands. We have…
- CVE-2024-53700HIGHCVSS 7.2EG 7.22025-03-07
A command injection vulnerability has been reported to affect QHora. If exploited, the vulnerability could allow remote attackers who have gained administrator access to execute arbitrary commands. We have already fixed the vulnerability …
- CVE-2024-53899HIGHCVSS 7.8EG 7.82024-11-24
virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287.
- CVE-2024-53919HIGHCVSS 7.6EG 7.62024-12-10
An injection vulnerability in Barco ClickShare CX-30/20, C-5/10, and ClickShare Bar Pro and Core models, running firmware before 2.21.1, allows physically proximate attackers or local admins to the webUI to trigger OS-level command executi…
- CVE-2024-53945HIGHCVSS 8.8EG 8.82025-08-14
The KuWFi 4G AC900 LTE router 1.0.13 is vulnerable to command injection on the HTTP API endpoints /goform/formMultiApnSetting and /goform/atCmd. An authenticated attacker can execute arbitrary OS commands with root privileges via shell met…
- CVE-2024-54006HIGHCVSS 7.2EG 7.22025-01-07
Multiple command injection vulnerabilities exist in the web interface of the 501 Wireless Client Bridge which could lead to authenticated remote command execution. Successful exploitation of these vulnerabilities result in the ability of a…
- CVE-2024-54007HIGHCVSS 7.2EG 7.22025-01-07
Multiple command injection vulnerabilities exist in the web interface of the 501 Wireless Client Bridge which could lead to authenticated remote command execution. Successful exploitation of these vulnerabilities result in the ability of a…
- CVE-2024-5461HIGHCVSS 8.0EG 8.02025-02-15
Implementation of the Simple Network Management Protocol (SNMP) operating on the Brocade 6547 (FC5022) embedded switch blade, makes internal script calls to system.sh from within the SNMP binary. An authenticated attacker could perform …
- CVE-2024-54660HIGHCVSS 8.7EG 8.72025-01-16
A JNDI injection issue was discovered in Cloudera JDBC Connector for Hive before 2.6.26 and JDBC Connector for Impala before 2.6.35. Attackers can inject malicious parameters into the JDBC URL, triggering JNDI injection during the process …
- CVE-2024-54681LOWCVSS 3.5EG 3.52025-01-17
Multiple bash files were present in the application's private directory. Bash files can be used on their own, by an attacker that has already full access to the mobile platform to compromise the translations for the application.
- CVE-2024-54794CRITICALCVSS 9.1EG 9.12025-01-21
The script input feature of SpagoBI 3.5.1 allows arbitrary code execution.
- CVE-2024-54802CRITICALCVSS 9.8EG 9.82025-03-31
In Netgear WNR854T 1.5.2 (North America), the UPNP service (/usr/sbin/upnp) is vulnerable to stack-based buffer overflow in the M-SEARCH Host header.
- CVE-2024-55030CRITICALCVSS 9.8EG 9.82025-03-25
A command injection vulnerability in the Command Dispatcher Service of NASA Fprime v3.4.3 allows attackers to execute arbitrary commands.
- CVE-2024-55062CRITICALCVSS 9.8EG 9.82025-01-31
Code Injection vulnerability in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote unauthenticated attackers to execute arbitrary code to /api/license/sendlicense/.
- CVE-2024-55063HIGHCVSS 8.8EG 8.82025-05-19
Multiple Code Injection vulnerabilities in EasyVirt DC NetScope <= 8.7.0 allows remote authenticated attackers to execute arbitrary code via the (1) lang parameter to /international/keyboard/options; the (2) keyboard_layout or (3) keyboard…
- CVE-2024-55414CRITICALCVSS 9.8EG 9.82025-01-07
A vulnerability exits in driver SmSerl64.sys in Motorola SM56 Modem WDM Driver v6.12.23.0, which allows low-privileged users to mapping physical memory via specially crafted IOCTL requests . This can be exploited for privilege escalation, …
- CVE-2024-55461CRITICALCVSS 9.8EG 9.82024-12-18
SeaCMS <=13.0 is vulnerable to command execution in phome.php via the function Ebak_RepPathFiletext().
- CVE-2024-55466MEDIUMCVSS 6.5EG 6.52025-05-12
An arbitrary file upload vulnerability in the Image Gallery of ThingsBoard Community, ThingsBoard Cloud and ThingsBoard Professional v3.8.1 allows attackers to execute arbitrary code via uploading a crafted file.
- CVE-2024-55544HIGHCVSS 8.8EG 8.82024-12-10
Missing input validation in the ORing IAP-420 web-interface allows authenticated Command Injections on OS level.This issue affects IAP-420 version 2.01e and below.
- CVE-2024-55547CRITICALCVSS 9.8EG 9.82024-12-10
SNMP objects in NET-SNMP used in ORing IAP-420 allows Command Injection. This issue affects IAP-420: through 2.01e.
Map vulnerabilities like CWE-77 to your infrastructure
EchelonGraph correlates every CVE — across CWE-77 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →