CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
Description
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76
CVEs mapped to this weakness (3,835)
page 84 of 192| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-38527 | Hig | 0.53 | 8.1 | 0.02 | Aug 11, 2021 | Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.14, EX6100v2 before 1.0.1.98, EX6150v2 before 1.0.1.98, EX6250 before 1.0.0.132, EX6400 before 1.0.2.158, EX6400v2 before 1.0.0.132, EX6410 before 1.0.0.132,… | ||
| CVE-2020-36463 | Hig | 0.53 | 8.1 | 0.01 | Aug 8, 2021 | An issue was discovered in the multiqueue crate through 2020-12-25 for Rust. There are unconditional implementations of Send for InnerSend<RW, T>, InnerRecv<RW, T>, FutInnerSend<RW, T>, and FutInnerRecv<RW, T>. | ||
| CVE-2020-36461 | Hig | 0.53 | 8.1 | 0.01 | Aug 8, 2021 | An issue was discovered in the noise_search crate through 2020-12-10 for Rust. There are unconditional implementations of Send and Sync for MvccRwLock. | ||
| CVE-2020-36459 | Hig | 0.53 | 8.1 | 0.01 | Aug 8, 2021 | An issue was discovered in the dces crate through 2020-12-09 for Rust. The World type is marked as Send but lacks bounds on its EntityStore and ComponentStore. | ||
| CVE-2020-36458 | Hig | 0.53 | 8.1 | 0.01 | Aug 8, 2021 | An issue was discovered in the lexer crate through 2020-11-10 for Rust. For ReaderResult<T, E>, there is an implementation of Sync with a trait bound of T: Send, E: Send. | ||
| CVE-2020-36456 | Hig | 0.53 | 8.1 | 0.01 | Aug 8, 2021 | An issue was discovered in the toolshed crate through 2020-11-15 for Rust. In CopyCell, the Send trait lacks bounds on the contained type. | ||
| CVE-2020-36450 | Hig | 0.53 | 8.1 | 0.01 | Aug 8, 2021 | An issue was discovered in the bunch crate through 2020-11-12 for Rust. There are unconditional implementations of Send and Sync for Bunch. | ||
| CVE-2020-36449 | Hig | 0.53 | 8.1 | 0.01 | Aug 8, 2021 | An issue was discovered in the kekbit crate before 0.3.4 for Rust. For ShmWriter, Send is implemented without requiring H: Send. | ||
| CVE-2020-36448 | Hig | 0.53 | 8.1 | 0.01 | Aug 8, 2021 | An issue was discovered in the cache crate through 2020-11-24 for Rust. There are unconditional implementations of Send and Sync for Cache. | ||
| CVE-2021-23412 | Hig | 0.53 | 8.1 | 0.04 | Jul 23, 2021 | All versions of package gitlogplus are vulnerable to Command Injection via the main functionality, as options attributes are appended to the command to be executed without sanitization. | ||
| CVE-2020-28429 | Hig | 0.53 | 7.3 | 0.63 | Feb 23, 2021 | All versions of package geojson2kml are vulnerable to Command Injection via the index.js file. PoC: var a =require("geojson2kml"); a("./","& touch JHU",function(){}) | ||
| CVE-2021-21479 | Cri | 0.53 | 9.1 | 0.10 | Feb 9, 2021 | In SCIMono before 0.0.19, it is possible for an attacker to inject and execute java expression compromising the availability and integrity of the system. | ||
| CVE-2016-10843 | Hig | 0.53 | 8.1 | 0.01 | Aug 1, 2019 | cPanel before 11.54.0.4 allows code execution in the context of shared users via JSON-API (SEC-76). | ||
| CVE-2019-5414 | Hig | 0.53 | 8.1 | 0.02 | Mar 21, 2019 | If an attacker can control the port, which in itself is a very sensitive value, they can inject arbitrary OS commands due to the usage of the exec function in a third-party module kill-port < 1.3.2. | ||
| CVE-2018-5403 | Hig | 0.53 | 8.1 | 0.02 | Jan 10, 2019 | Imperva SecureSphere gateway (GW) running v13, for both pre-First Time Login or post-First Time Login (FTL), if the attacker knows the basic authentication passwords, the GW may be vulnerable to RCE through specially crafted requests, from the web access management interface. | ||
| CVE-2013-7377 | Hig | 0.53 | 8.1 | 0.02 | Oct 23, 2017 | The codem-transcode module before 0.5.0 for Node.js, when ffprobe is enabled, allows remote attackers to execute arbitrary commands via a POST request to /probe. | ||
| CVE-2016-0396 | Hig | 0.53 | 8.1 | 0.01 | Feb 1, 2017 | IBM Tivoli Endpoint Manager could allow a user under special circumstances to inject commands that would be executed with unnecessary higher privileges than expected. | ||
| CVE-2026-18599 | Hig | 0.52 | 8.0 | 0.01 | Aug 3, 2026 | A flaw has been found in GL.iNet GL-MT3000 up to 4.4.5. The impacted element is the function logread.set_config of the file /usr/lib/oui-httpd/rpc/logread of the component Logread Lua RPC Plugin. This manipulation of the argument record_size causes command injection. The exploit… | ||
| CVE-2026-12045 | Cri | 0.52 | 9.0 | 0.00 | Jun 19, 2026 | Read-only transaction bypass in the pgAdmin 4 AI Assistant allows an attacker who can influence database content that the assistant reads to execute arbitrary SQL with the privileges of the pgAdmin user's database role. The AI Assistant's execute_sql_query tool runs… | ||
| CVE-2026-30615 | Hig | 0.52 | 8.0 | 0.00 | Apr 15, 2026 | A prompt injection vulnerability in Windsurf 1.9544.26 allows remote attackers to execute arbitrary commands on a victim system. When Windsurf processes attacker-controlled HTML content, malicious instructions can cause unauthorized modification of the local MCP configuration… |
- risk 0.53cvss 8.1epss 0.02
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.14, EX6100v2 before 1.0.1.98, EX6150v2 before 1.0.1.98, EX6250 before 1.0.0.132, EX6400 before 1.0.2.158, EX6400v2 before 1.0.0.132, EX6410 before 1.0.0.132,…
- risk 0.53cvss 8.1epss 0.01
An issue was discovered in the multiqueue crate through 2020-12-25 for Rust. There are unconditional implementations of Send for InnerSend<RW, T>, InnerRecv<RW, T>, FutInnerSend<RW, T>, and FutInnerRecv<RW, T>.
- risk 0.53cvss 8.1epss 0.01
An issue was discovered in the noise_search crate through 2020-12-10 for Rust. There are unconditional implementations of Send and Sync for MvccRwLock.
- risk 0.53cvss 8.1epss 0.01
An issue was discovered in the dces crate through 2020-12-09 for Rust. The World type is marked as Send but lacks bounds on its EntityStore and ComponentStore.
- risk 0.53cvss 8.1epss 0.01
An issue was discovered in the lexer crate through 2020-11-10 for Rust. For ReaderResult<T, E>, there is an implementation of Sync with a trait bound of T: Send, E: Send.
- risk 0.53cvss 8.1epss 0.01
An issue was discovered in the toolshed crate through 2020-11-15 for Rust. In CopyCell, the Send trait lacks bounds on the contained type.
- risk 0.53cvss 8.1epss 0.01
An issue was discovered in the bunch crate through 2020-11-12 for Rust. There are unconditional implementations of Send and Sync for Bunch.
- risk 0.53cvss 8.1epss 0.01
An issue was discovered in the kekbit crate before 0.3.4 for Rust. For ShmWriter, Send is implemented without requiring H: Send.
- risk 0.53cvss 8.1epss 0.01
An issue was discovered in the cache crate through 2020-11-24 for Rust. There are unconditional implementations of Send and Sync for Cache.
- risk 0.53cvss 8.1epss 0.04
All versions of package gitlogplus are vulnerable to Command Injection via the main functionality, as options attributes are appended to the command to be executed without sanitization.
- risk 0.53cvss 7.3epss 0.63
All versions of package geojson2kml are vulnerable to Command Injection via the index.js file. PoC: var a =require("geojson2kml"); a("./","& touch JHU",function(){})
- risk 0.53cvss 9.1epss 0.10
In SCIMono before 0.0.19, it is possible for an attacker to inject and execute java expression compromising the availability and integrity of the system.
- risk 0.53cvss 8.1epss 0.01
cPanel before 11.54.0.4 allows code execution in the context of shared users via JSON-API (SEC-76).
- risk 0.53cvss 8.1epss 0.02
If an attacker can control the port, which in itself is a very sensitive value, they can inject arbitrary OS commands due to the usage of the exec function in a third-party module kill-port < 1.3.2.
- risk 0.53cvss 8.1epss 0.02
Imperva SecureSphere gateway (GW) running v13, for both pre-First Time Login or post-First Time Login (FTL), if the attacker knows the basic authentication passwords, the GW may be vulnerable to RCE through specially crafted requests, from the web access management interface.
- risk 0.53cvss 8.1epss 0.02
The codem-transcode module before 0.5.0 for Node.js, when ffprobe is enabled, allows remote attackers to execute arbitrary commands via a POST request to /probe.
- risk 0.53cvss 8.1epss 0.01
IBM Tivoli Endpoint Manager could allow a user under special circumstances to inject commands that would be executed with unnecessary higher privileges than expected.
- risk 0.52cvss 8.0epss 0.01
A flaw has been found in GL.iNet GL-MT3000 up to 4.4.5. The impacted element is the function logread.set_config of the file /usr/lib/oui-httpd/rpc/logread of the component Logread Lua RPC Plugin. This manipulation of the argument record_size causes command injection. The exploit…
- risk 0.52cvss 9.0epss 0.00
Read-only transaction bypass in the pgAdmin 4 AI Assistant allows an attacker who can influence database content that the assistant reads to execute arbitrary SQL with the privileges of the pgAdmin user's database role. The AI Assistant's execute_sql_query tool runs…
- risk 0.52cvss 8.0epss 0.00
A prompt injection vulnerability in Windsurf 1.9544.26 allows remote attackers to execute arbitrary commands on a victim system. When Windsurf processes attacker-controlled HTML content, malicious instructions can cause unauthorized modification of the local MCP configuration…