VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,816)

page 180 of 191
  • CVE-2026-1735MedFeb 2, 2026
    risk 0.28cvss 4.3epss 0.01

    A weakness has been identified in Yealink MeetingBar A30 133.321.0.3. This issue affects some unknown processing of the component Diagnostic Handler. This manipulation causes command injection. It is feasible to perform the attack on the physical device. The exploit has been…

  • CVE-2025-25274MedMar 21, 2025
    risk 0.28cvss 4.3epss 0.00

    Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to restrict command execution in archived channels, which allows authenticated users to run commands in archived channels.

  • CVE-2023-20237MedAug 16, 2023
    risk 0.28cvss 4.3epss 0.00

    A vulnerability in Cisco Intersight Virtual Appliance could allow an unauthenticated, adjacent attacker to access internal HTTP services that are otherwise inaccessible. This vulnerability is due to insufficient restrictions on internally accessible http proxies. An attacker…

  • CVE-2021-22868MedSep 24, 2021
    risk 0.28cvss 4.3epss 0.01

    A path traversal vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub Pages site. User-controlled configuration options used by GitHub Pages were not sufficiently restricted and made it possible to read files on the GitHub…

  • CVE-2026-16631MedJul 23, 2026
    risk 0.27cvss 5.3epss 0.01

    A vulnerability was detected in publint up to 0.1.4. This impacts the function child_process.exec of the file src/node/pack.js of the component package-manager Command Handler. The manipulation results in os command injection. Attacking locally is a requirement. The exploit is…

  • CVE-2026-11487MedJun 8, 2026
    risk 0.27cvss 5.3epss 0.01

    A flaw has been found in Neovim up to 0.12.2. Affected by this issue is the function M.read of the file runtime/lua/vim/secure.lua of the component View Branch. Executing a manipulation of the argument path can lead to command injection. It is possible to launch the attack on…

  • CVE-2025-58132MedOct 15, 2025
    risk 0.27cvss 4.1epss 0.02

    Command injection in some Zoom Clients for Windows may allow an authenticated user to conduct a disclosure of information via network access.

  • CVE-2024-38903MedJun 24, 2024
    risk 0.27cvss 4.1epss 0.00

    H3C Magic R230 V100R002's udpserver opens port 9034, allowing attackers to execute arbitrary commands.

  • CVE-2024-29435MedApr 1, 2024
    risk 0.27cvss 4.1epss 0.00

    An issue discovered in Alldata v0.4.6 allows attacker to run arbitrary commands via the processId parameter.

  • CVE-2019-1612MedMar 11, 2019
    risk 0.27cvss 4.2epss 0.00

    A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device. The vulnerability is due to insufficient validation of arguments passed to certain CLI…

  • CVE-2026-53533medJul 7, 2026
    risk 0.26cvss epss

    ### Summary `aiosmtplib`'s `SMTP.mail()`, `SMTP.rcpt()`, `SMTP.vrfy()` and `SMTP.expn()` send the caller-supplied email address to the server without rejecting embedded CR/LF (`\r\n`) bytes. An address that contains a CR/LF is written verbatim onto the SMTP control connection,…

  • CVE-2024-45989MedSep 26, 2024
    risk 0.26cvss 4.0epss 0.00

    Monica AI Assistant desktop application v2.3.0 is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor. A prompt injection allows an attacker to modify chatbot answer with an unloaded image that exfiltrates the user's sensitive chat data of the current…

  • CVE-2024-34218LowMay 14, 2024
    risk 0.26cvss 3.8epss 0.18

    TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the NTPSyncWithHost function via the hostTime parameter.

  • CVE-2015-10096MedMar 20, 2023
    risk 0.26cvss 5.0epss 0.02

    A vulnerability, which was classified as critical, was found in Zarthus IRC Twitter Announcer Bot up to 1.1.0. This affects the function get_tweets of the file lib/twitterbot/plugins/twitter_announcer.rb. The manipulation of the argument tweet leads to command injection. It is…

  • CVE-2022-35954MedAug 15, 2022
    risk 0.26cvss 5.0epss 0.01

    The GitHub Actions ToolKit provides a set of packages to make creating actions easier. The `core.exportVariable` function uses a well known delimiter that attackers can use to break out of that specific variable and assign values to other arbitrary variables. Workflows that…

  • CVE-2021-32830LowAug 17, 2021
    risk 0.26cvss 3.9epss 0.02

    The @diez/generation npm package is a client for Diez. The locateFont method of @diez/generation has a command injection vulnerability. Clients of the @diez/generation library are unlikely to be aware of this, so they might unwittingly write code that contains a vulnerability.…

  • CVE-2026-59846LowJul 21, 2026
    risk 0.25cvss 3.9epss 0.00

    A flaw was found in libssh. A malicious username expanded through %r in ProxyCommand handling can inject shell metacharacters, exposing environment variables and causing unintended shell behavior.

  • CVE-2024-32314LowApr 17, 2024
    risk 0.25cvss 3.8epss 0.01

    Tenda AC500 V2.0.1.9(1307) firmware contains a command injection vulnerablility in the formexeCommand function via the cmdinput parameter.

  • CVE-2022-25619LowMar 30, 2022
    risk 0.25cvss 3.8epss 0.00

    Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in ping tool of Profelis IT Consultancy SambaBox allows AUTHENTICATED user to cause run arbitrary code. This issue affects: Profelis IT Consultancy SambaBox 4.0 version 4.0 and…

  • CVE-2019-11853LowAug 21, 2020
    risk 0.25cvss 3.9epss 0.01

    Several potential command injections vulnerabilities exist in the AT command interface of ALEOS before 4.11.0, and 4.9.4.