CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
Description
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76
CVEs mapped to this weakness (3,835)
page 125 of 192| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-0789 | Hig | 0.46 | 8.1 | 0.02 | Feb 12, 2023 | Command Injection in GitHub repository thorsten/phpmyfaq prior to 3.1.11. | ||
| CVE-2023-22657 | Hig | 0.46 | 7.0 | 0.00 | Feb 1, 2023 | On F5OS-A beginning in version 1.2.0 to before 1.3.0 and F5OS-C beginning in version 1.3.0 to before 1.5.0, processing F5OS tenant file names may allow for command injection. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | ||
| CVE-2022-3086 | Hig | 0.46 | 7.1 | 0.00 | Dec 2, 2022 | Cradlepoint IBR600 NCOS versions 6.5.0.160bc2e and prior are vulnerable to shell escape, which enables local attackers with non-superuser credentials to gain full, unrestrictive shell access which may allow an attacker to execute arbitrary code. | ||
| CVE-2022-25900 | Hig | 0.46 | 8.1 | 0.04 | Jul 1, 2022 | All versions of package git-clone are vulnerable to Command Injection due to insecure usage of the --upload-pack feature of git. | ||
| CVE-2022-25865 | Hig | 0.46 | 8.1 | 0.07 | May 13, 2022 | The package workspace-tools before 0.18.4 are vulnerable to Command Injection via git argument injection. When calling the fetchRemoteBranch(remote: string, remoteBranch: string, cwd: string) function, both the remote and remoteBranch parameters are passed to the git fetch… | ||
| CVE-2022-25866 | Hig | 0.46 | 8.1 | 0.04 | Apr 25, 2022 | The package czproject/git-php before 4.0.3 are vulnerable to Command Injection via git argument injection. When calling the isRemoteUrlReadable($url, array $refs = NULL) function, both the url and refs parameters are passed to the git ls-remote subcommand in a way that… | ||
| CVE-2022-21235 | Hig | 0.46 | 8.1 | 0.02 | Apr 1, 2022 | The package github.com/masterminds/vcs before 1.13.3 are vulnerable to Command Injection via argument injection. When hg is executed, argument strings are passed to hg in a way that additional flags can be set. The additional flags can be used to perform a command injection. | ||
| CVE-2022-21187 | Hig | 0.46 | 8.1 | 0.04 | Mar 14, 2022 | The package libvcs before 0.11.1 are vulnerable to Command Injection via argument injection. When calling the update_repo function (when using hg), the url parameter is passed to the hg clone command. By injecting some hg options it was possible to get arbitrary command… | ||
| CVE-2021-45531 | Hig | 0.46 | 7.1 | 0.01 | Dec 26, 2021 | NETGEAR D6220 devices before 1.0.0.76 are affected by command injection by an authenticated user. | ||
| CVE-2020-36462 | Hig | 0.46 | 8.1 | 0.01 | Aug 8, 2021 | An issue was discovered in the syncpool crate before 0.1.6 for Rust. There is an unconditional implementation of Send for Bucket2. | ||
| CVE-2020-36457 | Hig | 0.46 | 8.1 | 0.01 | Aug 8, 2021 | An issue was discovered in the lever crate before 0.1.1 for Rust. AtomicBox implements the Send and Sync traits for all types T. | ||
| CVE-2020-36455 | Hig | 0.46 | 8.1 | 0.01 | Aug 8, 2021 | An issue was discovered in the slock crate through 2020-11-17 for Rust. Slock unconditionally implements Send and Sync. | ||
| CVE-2020-36447 | Hig | 0.46 | 8.1 | 0.01 | Aug 8, 2021 | An issue was discovered in the v9 crate through 2020-12-18 for Rust. There is an unconditional implementation of Sync for SyncRef. | ||
| CVE-2016-4989 | Hig | 0.46 | 7.0 | 0.00 | Apr 11, 2017 | setroubleshoot allows local users to bypass an intended container protection mechanism and execute arbitrary commands by (1) triggering an SELinux denial with a crafted file name, which is handled by the _set_tpath function in audit_data.py or via a crafted (2) local_id or (3)… | ||
| CVE-2016-4446 | Hig | 0.46 | 7.0 | 0.00 | Apr 11, 2017 | The allow_execstack plugin for setroubleshoot allows local users to execute arbitrary commands by triggering an execstack SELinux denial with a crafted filename, related to the commands.getoutput function. | ||
| CVE-2016-4445 | Hig | 0.46 | 7.0 | 0.00 | Apr 11, 2017 | The fix_lookup_id function in sealert in setroubleshoot before 3.2.23 allows local users to execute arbitrary commands as root by triggering an SELinux denial with a crafted file name, related to executing external commands with the commands.getstatusoutput function. | ||
| CVE-2016-4444 | Hig | 0.46 | 7.0 | 0.00 | Apr 11, 2017 | The allow_execmod plugin for setroubleshoot before 3.2.23 allows local users to execute arbitrary commands by triggering an execmod SELinux denial with a crafted binary filename, related to the commands.getstatusoutput function. | ||
| CVE-2026-55182 | hig | 0.45 | — | — | Aug 18, 2026 | ### Summary A vulnerability has been identified that allows an authenticated administrator to execute arbitrary code on the host server. By adding an alert transport entry, an attacker with administrative privileges can execute malicious commands. ### Details The vulnerability… | ||
| CVE-2025-71392 | Hig | 0.45 | 8.0 | 0.00 | Jul 18, 2026 | SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 fails to properly escape table and field names in the command-line export command. An authenticated System User with OWNER or EDITOR roles can create tables or fields with malicious names containing SurrealQL.… | ||
| CVE-2026-53932 | hig | 0.45 | — | — | Jul 9, 2026 | ## Summary A crafted backup archive can trigger OS command injection during database restore. The restore workflow extracts a ZIP archive, enumerates files under `db-dumps`, converts the dump path to an absolute path, and passes that path into database import commands that are… |
- risk 0.46cvss 8.1epss 0.02
Command Injection in GitHub repository thorsten/phpmyfaq prior to 3.1.11.
- risk 0.46cvss 7.0epss 0.00
On F5OS-A beginning in version 1.2.0 to before 1.3.0 and F5OS-C beginning in version 1.3.0 to before 1.5.0, processing F5OS tenant file names may allow for command injection. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
- risk 0.46cvss 7.1epss 0.00
Cradlepoint IBR600 NCOS versions 6.5.0.160bc2e and prior are vulnerable to shell escape, which enables local attackers with non-superuser credentials to gain full, unrestrictive shell access which may allow an attacker to execute arbitrary code.
- risk 0.46cvss 8.1epss 0.04
All versions of package git-clone are vulnerable to Command Injection due to insecure usage of the --upload-pack feature of git.
- risk 0.46cvss 8.1epss 0.07
The package workspace-tools before 0.18.4 are vulnerable to Command Injection via git argument injection. When calling the fetchRemoteBranch(remote: string, remoteBranch: string, cwd: string) function, both the remote and remoteBranch parameters are passed to the git fetch…
- risk 0.46cvss 8.1epss 0.04
The package czproject/git-php before 4.0.3 are vulnerable to Command Injection via git argument injection. When calling the isRemoteUrlReadable($url, array $refs = NULL) function, both the url and refs parameters are passed to the git ls-remote subcommand in a way that…
- risk 0.46cvss 8.1epss 0.02
The package github.com/masterminds/vcs before 1.13.3 are vulnerable to Command Injection via argument injection. When hg is executed, argument strings are passed to hg in a way that additional flags can be set. The additional flags can be used to perform a command injection.
- risk 0.46cvss 8.1epss 0.04
The package libvcs before 0.11.1 are vulnerable to Command Injection via argument injection. When calling the update_repo function (when using hg), the url parameter is passed to the hg clone command. By injecting some hg options it was possible to get arbitrary command…
- risk 0.46cvss 7.1epss 0.01
NETGEAR D6220 devices before 1.0.0.76 are affected by command injection by an authenticated user.
- risk 0.46cvss 8.1epss 0.01
An issue was discovered in the syncpool crate before 0.1.6 for Rust. There is an unconditional implementation of Send for Bucket2.
- risk 0.46cvss 8.1epss 0.01
An issue was discovered in the lever crate before 0.1.1 for Rust. AtomicBox implements the Send and Sync traits for all types T.
- risk 0.46cvss 8.1epss 0.01
An issue was discovered in the slock crate through 2020-11-17 for Rust. Slock unconditionally implements Send and Sync.
- risk 0.46cvss 8.1epss 0.01
An issue was discovered in the v9 crate through 2020-12-18 for Rust. There is an unconditional implementation of Sync for SyncRef.
- risk 0.46cvss 7.0epss 0.00
setroubleshoot allows local users to bypass an intended container protection mechanism and execute arbitrary commands by (1) triggering an SELinux denial with a crafted file name, which is handled by the _set_tpath function in audit_data.py or via a crafted (2) local_id or (3)…
- risk 0.46cvss 7.0epss 0.00
The allow_execstack plugin for setroubleshoot allows local users to execute arbitrary commands by triggering an execstack SELinux denial with a crafted filename, related to the commands.getoutput function.
- risk 0.46cvss 7.0epss 0.00
The fix_lookup_id function in sealert in setroubleshoot before 3.2.23 allows local users to execute arbitrary commands as root by triggering an SELinux denial with a crafted file name, related to executing external commands with the commands.getstatusoutput function.
- risk 0.46cvss 7.0epss 0.00
The allow_execmod plugin for setroubleshoot before 3.2.23 allows local users to execute arbitrary commands by triggering an execmod SELinux denial with a crafted binary filename, related to the commands.getstatusoutput function.
- risk 0.45cvss —epss —
### Summary A vulnerability has been identified that allows an authenticated administrator to execute arbitrary code on the host server. By adding an alert transport entry, an attacker with administrative privileges can execute malicious commands. ### Details The vulnerability…
- risk 0.45cvss 8.0epss 0.00
SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 fails to properly escape table and field names in the command-line export command. An authenticated System User with OWNER or EDITOR roles can create tables or fields with malicious names containing SurrealQL.…
- risk 0.45cvss —epss —
## Summary A crafted backup archive can trigger OS command injection during database restore. The restore workflow extracts a ZIP archive, enumerates files under `db-dumps`, converts the dump path to an absolute path, and passes that path into database import commands that are…