VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,835)

page 84 of 192
  • CVE-2021-38527HigAug 11, 2021
    risk 0.53cvss 8.1epss 0.02

    Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.0.14, EX6100v2 before 1.0.1.98, EX6150v2 before 1.0.1.98, EX6250 before 1.0.0.132, EX6400 before 1.0.2.158, EX6400v2 before 1.0.0.132, EX6410 before 1.0.0.132,…

  • CVE-2020-36463HigAug 8, 2021
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in the multiqueue crate through 2020-12-25 for Rust. There are unconditional implementations of Send for InnerSend<RW, T>, InnerRecv<RW, T>, FutInnerSend<RW, T>, and FutInnerRecv<RW, T>.

  • CVE-2020-36461HigAug 8, 2021
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in the noise_search crate through 2020-12-10 for Rust. There are unconditional implementations of Send and Sync for MvccRwLock.

  • CVE-2020-36459HigAug 8, 2021
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in the dces crate through 2020-12-09 for Rust. The World type is marked as Send but lacks bounds on its EntityStore and ComponentStore.

  • CVE-2020-36458HigAug 8, 2021
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in the lexer crate through 2020-11-10 for Rust. For ReaderResult<T, E>, there is an implementation of Sync with a trait bound of T: Send, E: Send.

  • CVE-2020-36456HigAug 8, 2021
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in the toolshed crate through 2020-11-15 for Rust. In CopyCell, the Send trait lacks bounds on the contained type.

  • CVE-2020-36450HigAug 8, 2021
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in the bunch crate through 2020-11-12 for Rust. There are unconditional implementations of Send and Sync for Bunch.

  • CVE-2020-36449HigAug 8, 2021
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in the kekbit crate before 0.3.4 for Rust. For ShmWriter, Send is implemented without requiring H: Send.

  • CVE-2020-36448HigAug 8, 2021
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in the cache crate through 2020-11-24 for Rust. There are unconditional implementations of Send and Sync for Cache.

  • CVE-2021-23412HigJul 23, 2021
    risk 0.53cvss 8.1epss 0.04

    All versions of package gitlogplus are vulnerable to Command Injection via the main functionality, as options attributes are appended to the command to be executed without sanitization.

  • CVE-2020-28429HigFeb 23, 2021
    risk 0.53cvss 7.3epss 0.63

    All versions of package geojson2kml are vulnerable to Command Injection via the index.js file. PoC: var a =require("geojson2kml"); a("./","& touch JHU",function(){})

  • CVE-2021-21479CriFeb 9, 2021
    risk 0.53cvss 9.1epss 0.10

    In SCIMono before 0.0.19, it is possible for an attacker to inject and execute java expression compromising the availability and integrity of the system.

  • CVE-2016-10843HigAug 1, 2019
    risk 0.53cvss 8.1epss 0.01

    cPanel before 11.54.0.4 allows code execution in the context of shared users via JSON-API (SEC-76).

  • CVE-2019-5414HigMar 21, 2019
    risk 0.53cvss 8.1epss 0.02

    If an attacker can control the port, which in itself is a very sensitive value, they can inject arbitrary OS commands due to the usage of the exec function in a third-party module kill-port < 1.3.2.

  • CVE-2018-5403HigJan 10, 2019
    risk 0.53cvss 8.1epss 0.02

    Imperva SecureSphere gateway (GW) running v13, for both pre-First Time Login or post-First Time Login (FTL), if the attacker knows the basic authentication passwords, the GW may be vulnerable to RCE through specially crafted requests, from the web access management interface.

  • CVE-2013-7377HigOct 23, 2017
    risk 0.53cvss 8.1epss 0.02

    The codem-transcode module before 0.5.0 for Node.js, when ffprobe is enabled, allows remote attackers to execute arbitrary commands via a POST request to /probe.

  • CVE-2016-0396HigFeb 1, 2017
    risk 0.53cvss 8.1epss 0.01

    IBM Tivoli Endpoint Manager could allow a user under special circumstances to inject commands that would be executed with unnecessary higher privileges than expected.

  • CVE-2026-18599HigAug 3, 2026
    risk 0.52cvss 8.0epss 0.01

    A flaw has been found in GL.iNet GL-MT3000 up to 4.4.5. The impacted element is the function logread.set_config of the file /usr/lib/oui-httpd/rpc/logread of the component Logread Lua RPC Plugin. This manipulation of the argument record_size causes command injection. The exploit…

  • CVE-2026-12045CriJun 19, 2026
    risk 0.52cvss 9.0epss 0.00

    Read-only transaction bypass in the pgAdmin 4 AI Assistant allows an attacker who can influence database content that the assistant reads to execute arbitrary SQL with the privileges of the pgAdmin user's database role. The AI Assistant's execute_sql_query tool runs…

  • CVE-2026-30615HigApr 15, 2026
    risk 0.52cvss 8.0epss 0.00

    A prompt injection vulnerability in Windsurf 1.9544.26 allows remote attackers to execute arbitrary commands on a victim system. When Windsurf processes attacker-controlled HTML content, malicious instructions can cause unauthorized modification of the local MCP configuration…