VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,970)

page 191 of 199
  • CVE-2022-25765HigSep 9, 2022
    risk 0.03cvss 7.3epss 0.43

    The package pdfkit from 0.0.0 are vulnerable to Command Injection where the URL is not properly sanitized.

  • CVE-2022-25766HigMar 21, 2022
    risk 0.03cvss 8.8epss 0.34

    The package ungit before 1.5.20 are vulnerable to Remote Code Execution (RCE) via argument injection. The issue occurs when calling the /api/fetch endpoint. User controlled values (remote and ref) are passed to the git fetch command. By injecting some git options it was possible…

  • CVE-2014-7208Dec 19, 2014
    risk 0.03cvss —epss 0.01

    GParted before 0.15.0 allows local users to execute arbitrary commands with root privileges via shell metacharacters in a crafted filesystem label.

  • CVE-2014-1216Apr 22, 2014
    risk 0.03cvss —epss 0.04

    FitNesse Wiki 20131110, 20140201, and earlier allows remote attackers to execute arbitrary commands by defining a COMMAND_PATTERN and TEST_RUNNER in the pageContent parameter when editing a page.

  • CVE-2025-27423HigMar 3, 2025
    risk 0.02cvss 7.1epss 0.22

    Vim is an open source, command line text editor. Vim is distributed with the tar.vim plugin, that allows easy editing and viewing of (compressed or uncompressed) tar files. Starting with 9.1.0858, the tar.vim plugin uses the ":read" ex command line to append below the cursor…

  • CVE-2018-1000802CriSep 18, 2018
    risk 0.02cvss 9.8epss 0.20

    Python Software Foundation Python (CPython) version 2.7 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in shutil module (make_archive function) that can result in Denial of service, Information gain via…

  • CVE-2023-34105HigJun 12, 2023
    risk 0.01cvss 7.5epss 0.09

    SRS is a real-time video server supporting RTMP, WebRTC, HLS, HTTP-FLV, SRT, MPEG-DASH, and GB28181. Prior to versions 5.0.157, 5.0-b1, and 6.0.48, SRS's `api-server` server is vulnerable to a drive-by command injection. An attacker may send a request to the `/api/v1/snapshots`…

  • CVE-2015-7839Oct 15, 2015
    risk 0.01cvss —epss 0.07

    SolarWinds Log and Event Manager (LEM) allows remote attackers to execute arbitrary commands on managed computers via a request to services/messagebroker/nonsecurestreamingamf involving the traceroute functionality.

  • CVE-2015-1986Jun 30, 2015
    risk 0.01cvss —epss 0.08

    The server in IBM Tivoli Storage Manager FastBack 6.1 before 6.1.12 allows remote attackers to execute arbitrary commands via unspecified vectors, a different vulnerability than CVE-2015-1938.

  • CVE-2015-0538May 7, 2015
    risk 0.01cvss —epss 0.07

    ftagent.exe in EMC AutoStart 5.4.x and 5.5.x before 5.5.0.508 HF4 allows remote attackers to execute arbitrary commands via crafted packets.

  • CVE-2015-0225Apr 3, 2015
    risk 0.01cvss —epss 0.07

    The default configuration in Apache Cassandra 1.2.0 through 1.2.19, 2.0.0 through 2.0.13, and 2.1.0 through 2.1.3 binds an unauthenticated JMX/RMI interface to all network interfaces, which allows remote attackers to execute arbitrary Java code via an RMI request.

  • CVE-2014-3556Dec 29, 2014
    risk 0.01cvss —epss 0.08

    The STARTTLS implementation in mail/ngx_mail_smtp_handler.c in the SMTP proxy in nginx 1.5.x and 1.6.x before 1.6.1 and 1.7.x before 1.7.4 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by…

  • CVE-2014-3524Aug 26, 2014
    risk 0.01cvss —epss 0.15

    Apache OpenOffice before 4.1.1 allows remote attackers to execute arbitrary commands and possibly have other unspecified impact via a crafted Calc spreadsheet.

  • CVE-2010-0136Feb 16, 2010
    risk 0.01cvss —epss 0.08

    OpenOffice.org (OOo) 2.0.4, 2.4.1, and 3.1.1 does not properly enforce Visual Basic for Applications (VBA) macro security settings, which allows remote attackers to run arbitrary macros via a crafted document.

  • CVE-2026-35847CriJul 30, 2026
    risk 0.00cvss 9.8epss 0.00

    An issue in dnsmgr v.2.15 and before allows a local attacker to execute arbitrary code via the ping function of the CheckUils.php file

  • CVE-2026-7849CriJul 30, 2026
    risk 0.00cvss 9.8epss 0.00

    Due to improper neutralization of special elements, an unauthenticated remote attacker is able to inject a command into the system configuration which is subsequently executed as root.

  • CVE-2026-16763MedJul 23, 2026
    risk 0.00cvss 5.3epss 0.01

    A vulnerability was identified in localstack serverless-localstack up to 1.4.0. The affected element is an unknown function of the file src/index.js of the component Configuration Handler. The manipulation of the argument custom.localstack.docker.compose_file leads to os command…

  • CVE-2026-16735MedJul 23, 2026
    risk 0.00cvss 5.3epss 0.01

    A security vulnerability has been detected in release-it conventional-changelog up to 11.0.1. This affects the function writeChangelog of the file index.js of the component Changelog File Handler. Such manipulation of the argument infile leads to os command injection. The attack…

  • CVE-2026-16630MedJul 22, 2026
    risk 0.00cvss 5.3epss 0.01

    A security vulnerability has been detected in syncfusion ej2-javascript-ui-controls up to 33.2.3. This affects the function child_process.exec of the file package.json. The manipulation leads to os command injection. An attack has to be approached locally. The exploit has been…

  • CVE-2026-16628MedJul 22, 2026
    risk 0.00cvss 5.3epss 0.01

    A vulnerability was detected in oclif up to 4.23.16. Affected by this vulnerability is the function child_process.exec of the component JIT Plugin Entry Handler. Performing a manipulation of the argument jitPlugins results in os command injection. The attack is only possible…