VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,835)

page 146 of 192
  • CVE-2021-1580MedAug 25, 2021
    risk 0.42cvss 6.5epss 0.02

    Multiple vulnerabilities in the web UI and API endpoints of Cisco Application Policy Infrastructure Controller (APIC) or Cisco Cloud APIC could allow a remote attacker to perform a command injection or file upload attack on an affected system. For more information about these…

  • CVE-2021-22867MedJul 14, 2021
    risk 0.42cvss 6.5epss 0.01

    A path traversal vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled configuration options used by GitHub Pages were not sufficiently restricted and made it possible to read files on the GitHub…

  • CVE-2021-1560MedMay 22, 2021
    risk 0.42cvss 6.5epss 0.03

    Multiple vulnerabilities in Cisco DNA Spaces Connector could allow an authenticated, remote attacker to perform a command injection attack on an affected device. These vulnerabilities are due to insufficient input sanitization when executing affected commands. A high-privileged…

  • CVE-2021-23360HigMar 21, 2021
    risk 0.42cvss 7.5epss 0.02

    This affects the package killport before 1.0.2. If (attacker-controlled) user input is given, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization. Running this PoC will cause the command…

  • CVE-2021-23337HigFeb 15, 2021
    risk 0.42cvss 7.2epss 0.21

    Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.

  • CVE-2020-35791MedDec 30, 2020
    risk 0.42cvss 6.4epss 0.01

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7800 before 1.0.2.68, R8900 before 1.0.5.2, and R9000 before 1.0.5.2.

  • CVE-2020-35790MedDec 30, 2020
    risk 0.42cvss 6.4epss 0.01

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.56, R7800 before 1.0.2.68, R8900 before 1.0.4.26, and R9000 before 1.0.4.26.

  • CVE-2020-26922MedOct 9, 2020
    risk 0.42cvss 6.4epss 0.00

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects WC7500 before 6.5.5.24, WC7600 before 6.5.5.24, WC7600v2 before 6.5.5.24, and WC9500 before 6.5.5.24.

  • CVE-2020-11084MedJul 14, 2020
    risk 0.42cvss 6.4epss 0.01

    In iPear, the manual execution of the eval() function can lead to command injection. Only PCs where commands are manually executed via "For Developers" are affected. This function allows executing any PHP code within iPear which may change, damage, or steal data (files) from the…

  • CVE-2020-3924MedFeb 27, 2020
    risk 0.42cvss 6.4epss 0.01

    DVR firmware in TAT-76 and TAT-77 series of products, provided by TONNET do not properly verify patch files. Attackers can inject a specific command into a patch file and gain access to the system.

  • CVE-2016-10849MedAug 1, 2019
    risk 0.42cvss 6.5epss 0.01

    cPanel before 11.54.0.4 allows certain file-chmod operations in scripts/secureit (SEC-82).

  • CVE-2016-10762HigJul 18, 2019
    risk 0.42cvss 7.5epss 0.02

    The CampTix Event Ticketing plugin before 1.5 for WordPress allows CSV injection when the export tool is used.

  • CVE-2019-6986HigJan 28, 2019
    risk 0.42cvss 7.5epss 0.03

    SPARQL Injection in VIVO Vitro v1.10.0 allows a remote attacker to execute arbitrary SPARQL via the uri parameter, leading to a regular expression denial of service (ReDoS), as demonstrated by crafted use of FILTER%20regex in a /individual?uri= request.

  • CVE-2016-7076MedMay 29, 2018
    risk 0.42cvss 6.4epss 0.00

    sudo before version 1.8.18p1 is vulnerable to a bypass in the sudo noexec restriction if application run via sudo executed wordexp() C library function with a user supplied argument. A local user permitted to run such application via sudo with noexec restriction could possibly…

  • CVE-2026-75011MedAug 17, 2026
    risk 0.41cvss 6.3epss 0.01

    A flaw has been found in kylecui NetForensicMCP 2.1.0. Impacted is the function execAsync of the file index.js. Executing a manipulation of the argument interface/protocol can lead to command injection. The attack may be launched remotely. The exploit has been published and may…

  • CVE-2026-19268MedAug 8, 2026
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was identified in abdullah1854 MCPGateway up to 549f494a9e363f40530149de324b8097de424230. This impacts the function getUsageByDateRange of the file src/services/claude-usage.ts of the component Claude Usage Range Endpoint. The manipulation of the argument since…

  • CVE-2026-19022MedAug 6, 2026
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was determined in OpenHands up to 0.62.0. The affected element is the function initialize_repo of the file OpenHands/resolver/send_pull_request.py. This manipulation causes command injection. Remote exploitation of the attack is possible. The vendor deleted the…

  • CVE-2026-18590MedAug 3, 2026
    risk 0.41cvss 6.3epss 0.01

    A vulnerability was determined in Wavlink WL-NU516U1 708c073-mt7628. Affected is the function set_sys_adm of the file adm.cgi of the component Admin Password Handler. This manipulation causes os command injection. The attack is possible to be carried out remotely. The exploit…

  • CVE-2026-12815MedJun 22, 2026
    risk 0.41cvss 6.3epss 0.02

    A vulnerability has been found in coollabsio coolify 4.0.0. Impacted is an unknown function of the component Image Name Handler. Such manipulation leads to os command injection. The attack may be performed from remote. The vendor was contacted early about this disclosure but did…

  • CVE-2026-12814MedJun 21, 2026
    risk 0.41cvss 6.3epss 0.02

    A flaw has been found in Comfast CF-WR631AX V3 up to 2.7.0.8. This issue affects the function system of the file /cgi-bin/mbox-config?section=ping_config of the component API Endpoint. This manipulation of the argument destination causes os command injection. The attack is…