VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,835)

page 99 of 192
  • CVE-2025-4653HigJun 10, 2025
    risk 0.49cvss epss 0.03

    Improper Neutralization of Special Elements in the backup name field may allow OS command injection. This issue affects Pandora ITSM 5.0.105.

  • CVE-2025-3002HigMar 31, 2025
    risk 0.49cvss 7.3epss 0.19

    A vulnerability, which was classified as critical, has been found in Digital China DCME-520 up to 20250320. This issue affects some unknown processing of the file /usr/local/WWW/function/audit/newstatistics/mon_merge_stat_hist.php. The manipulation of the argument type_name…

  • CVE-2025-23119HigMar 1, 2025
    risk 0.49cvss 7.5epss 0.01

    An Improper Neutralization of Escape Sequences vulnerability could allow an Authentication Bypass with a Remote Code Execution (RCE) by a malicious actor with access to UniFi Protect Cameras adjacent network.

  • CVE-2025-24861HigFeb 13, 2025
    risk 0.49cvss 7.5epss 0.01

    An attacker may inject commands via specially-crafted post requests.

  • CVE-2024-53919HigDec 10, 2024
    risk 0.49cvss 7.6epss 0.00

    An injection vulnerability in Barco ClickShare CX-30/20, C-5/10, and ClickShare Bar Pro and Core models, running firmware before 2.21.1, allows physically proximate attackers or local admins to the webUI to trigger OS-level command execution as root.

  • CVE-2024-9579HigNov 5, 2024
    risk 0.49cvss 7.5epss 0.00

    A potential vulnerability was discovered in certain Poly video conferencing devices. The firmware flaw does not properly sanitize user input. The exploitation of this vulnerability is dependent on a layered attack and cannot be exploited by itself.

  • CVE-2024-48142HigOct 24, 2024
    risk 0.49cvss 7.5epss 0.00

    A prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica ChatGPT AI Assistant v2.4.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.

  • CVE-2024-48141HigOct 24, 2024
    risk 0.49cvss 7.5epss 0.00

    A prompt injection vulnerability in the chatbox of Zhipu AI CodeGeeX v2.17.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.

  • CVE-2024-48140HigOct 24, 2024
    risk 0.49cvss 7.5epss 0.00

    A prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica Your AI Copilot powered by ChatGPT4 v6.3.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.

  • CVE-2024-48139HigOct 24, 2024
    risk 0.49cvss 7.5epss 0.00

    A prompt injection vulnerability in the chatbox of Blackbox AI v1.3.95 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.

  • CVE-2024-42427HigSep 10, 2024
    risk 0.49cvss 7.6epss 0.01

    Dell ThinOS versions 2402 and 2405, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Elevation of privileges.

  • CVE-2024-38486HigSep 6, 2024
    risk 0.49cvss 7.5epss 0.01

    Dell SmartFabric OS10 Software, version(s) 10.5.5.4 through 10.5.5.10 and 10.5.6.x , contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this…

  • CVE-2024-33112HigMay 6, 2024
    risk 0.49cvss 7.5epss 0.06

    D-Link DIR-845L router v1.01KRb03 and before is vulnerable to Command injection via the hnap_main()func.

  • CVE-2024-33342HigApr 26, 2024
    risk 0.49cvss 7.5epss 0.02

    D-Link DIR-822+ V1.0.5 was found to contain a command injection in SetPlcNetworkpwd function of prog.cgi, which allows remote attackers to execute arbitrary commands via shell.

  • CVE-2022-35503HigApr 22, 2024
    risk 0.49cvss 7.5epss 0.01

    Improper verification of a user input in Open Source MANO v7-v12 allows an authenticated attacker to execute arbitrary code within the LCM module container via a Virtual Network Function (VNF) descriptor. An attacker may be able execute code to change the normal execution of the…

  • CVE-2024-3116HigApr 4, 2024
    risk 0.49cvss 7.4epss 0.65

    pgAdmin <= 8.4 is affected by a Remote Code Execution (RCE) vulnerability through the validate binary path API. This vulnerability allows attackers to execute arbitrary code on the server hosting PGAdmin, posing a severe risk to the database management system's integrity and…

  • CVE-2024-26204HigMar 12, 2024
    risk 0.49cvss 7.5epss 0.02

    Outlook for Android Information Disclosure Vulnerability

  • CVE-2024-20667HigFeb 13, 2024
    risk 0.49cvss 7.5epss 0.01

    Azure DevOps Server Remote Code Execution Vulnerability

  • CVE-2023-26320HigOct 11, 2023
    risk 0.49cvss 7.5epss 0.01

    Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Xiaomi Xiaomi Router allows Command Injection.

  • CVE-2023-41303HigSep 25, 2023
    risk 0.49cvss 7.5epss 0.01

    Command injection vulnerability in the distributed file system module. Successful exploitation of this vulnerability may cause variables in the sock structure to be modified.