VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,835)

page 90 of 192
  • CVE-2025-55125HigJan 8, 2026
    risk 0.51cvss 7.8epss 0.01

    This vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicious backup configuration file.

  • CVE-2024-46062HigDec 17, 2025
    risk 0.51cvss 7.8epss 0.00

    Miniconda3 macOS installers before 23.11.0-1 contain a local privilege escalation vulnerability when installed outside the user's home directory. During installation, world-writable files are created and executed with root privileges. This flaw allows a local low-privileged user…

  • CVE-2024-46060HigDec 17, 2025
    risk 0.51cvss 7.8epss 0.00

    Anaconda3 macOS installers before 2024.06-1 contain a local privilege escalation vulnerability when installed outside the user's home directory. During installation, world-writable files are created and executed with root privileges. This allows a local low-privileged user to…

  • CVE-2025-54100HigDec 9, 2025
    risk 0.51cvss 7.8epss 0.02

    Improper neutralization of special elements used in a command ('command injection') in Windows PowerShell allows an unauthorized attacker to execute code locally.

  • CVE-2025-53773HigAug 12, 2025
    risk 0.51cvss 7.8epss 0.03

    Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio allows an unauthorized attacker to execute code locally.

  • CVE-2025-54564HigAug 1, 2025
    risk 0.51cvss 7.8epss 0.00

    uploadsm in ChargePoint Home Flex 5.5.4.13 does not validate a user-controlled string for bz2 decompression, which allows command execution as the nobody user.

  • CVE-2025-7883HigJul 20, 2025
    risk 0.51cvss 7.8epss 0.02

    A vulnerability classified as critical has been found in Eluktronics Control Center 5.23.51.41. Affected is an unknown function of the file \AiStoneService\MyControlCenter\Command of the component Powershell Script Handler. The manipulation leads to command injection. Attacking…

  • CVE-2025-32702HigMay 13, 2025
    risk 0.51cvss 7.8epss 0.01

    Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an unauthorized attacker to execute code locally.

  • CVE-2025-22473HigMar 17, 2025
    risk 0.51cvss 7.8epss 0.01

    Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this…

  • CVE-2025-22472HigMar 17, 2025
    risk 0.51cvss 7.8epss 0.01

    Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this…

  • CVE-2024-48830HigMar 17, 2025
    risk 0.51cvss 7.8epss 0.01

    Dell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this…

  • CVE-2025-26331HigMar 7, 2025
    risk 0.51cvss 7.8epss 0.01

    Dell ThinOS 2411 and prior, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary code execution.

  • CVE-2024-12251HigFeb 12, 2025
    risk 0.51cvss 7.8epss 0.01

    In Progress Telerik UI for WinUI versions prior to 2025 Q1 (3.0.0), a command injection attack is possible through improper neutralization of hyperlink elements.

  • CVE-2024-33469HigFeb 11, 2025
    risk 0.51cvss 7.9epss 0.00

    An issue in Team Amaze Amaze File Manager v.3.8.5 and fixed in v.3.10 allows a local attacker to execute arbitrary code via the onCreate method of DatabaseViewerActivity.java.

  • CVE-2020-13712HigDec 20, 2024
    risk 0.51cvss 7.8epss 0.01

    A command injection is possible through the user interface, allowing arbitrary command execution as the root user. oMG2000 running MGOS 3.15.1 or earlier is affected.  MG90 running MGOS 4.2.1 or earlier is affected.

  • CVE-2024-29404HigDec 3, 2024
    risk 0.51cvss 7.8epss 0.00

    An issue in Razer Synapse 3 v.3.9.131.20813 and Synapse 3 App v.20240213 allows a local attacker to execute arbitrary code via the export parameter of the Chroma Effects function in the Profiles component.

  • CVE-2024-38831HigNov 26, 2024
    risk 0.51cvss 7.8epss 0.00

    VMware Aria Operations contains a local privilege escalation vulnerability.  A malicious actor with local administrative privileges can insert malicious commands into the properties file to escalate privileges to  a root user on the appliance running VMware Aria Operations.

  • CVE-2024-48861HigNov 22, 2024
    risk 0.51cvss 7.8epss 0.01

    An OS command injection vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow local network attackers to execute commands. We have already fixed the vulnerability in the following versions: QuRouter 2.4.4.106 and later

  • CVE-2024-49026HigNov 12, 2024
    risk 0.51cvss 7.8epss 0.01

    Microsoft Excel Remote Code Execution Vulnerability

  • CVE-2024-49560HigNov 12, 2024
    risk 0.51cvss 7.8epss 0.01

    Dell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) a command injection vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution.