CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
Description
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76
CVEs mapped to this weakness (3,835)
page 99 of 192| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-4653 | Hig | 0.49 | — | 0.03 | Jun 10, 2025 | Improper Neutralization of Special Elements in the backup name field may allow OS command injection. This issue affects Pandora ITSM 5.0.105. | ||
| CVE-2025-3002 | Hig | 0.49 | 7.3 | 0.19 | Mar 31, 2025 | A vulnerability, which was classified as critical, has been found in Digital China DCME-520 up to 20250320. This issue affects some unknown processing of the file /usr/local/WWW/function/audit/newstatistics/mon_merge_stat_hist.php. The manipulation of the argument type_name… | ||
| CVE-2025-23119 | Hig | 0.49 | 7.5 | 0.01 | Mar 1, 2025 | An Improper Neutralization of Escape Sequences vulnerability could allow an Authentication Bypass with a Remote Code Execution (RCE) by a malicious actor with access to UniFi Protect Cameras adjacent network. | ||
| CVE-2025-24861 | Hig | 0.49 | 7.5 | 0.01 | Feb 13, 2025 | An attacker may inject commands via specially-crafted post requests. | ||
| CVE-2024-53919 | Hig | 0.49 | 7.6 | 0.00 | Dec 10, 2024 | An injection vulnerability in Barco ClickShare CX-30/20, C-5/10, and ClickShare Bar Pro and Core models, running firmware before 2.21.1, allows physically proximate attackers or local admins to the webUI to trigger OS-level command execution as root. | ||
| CVE-2024-9579 | Hig | 0.49 | 7.5 | 0.00 | Nov 5, 2024 | A potential vulnerability was discovered in certain Poly video conferencing devices. The firmware flaw does not properly sanitize user input. The exploitation of this vulnerability is dependent on a layered attack and cannot be exploited by itself. | ||
| CVE-2024-48142 | Hig | 0.49 | 7.5 | 0.00 | Oct 24, 2024 | A prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica ChatGPT AI Assistant v2.4.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message. | ||
| CVE-2024-48141 | Hig | 0.49 | 7.5 | 0.00 | Oct 24, 2024 | A prompt injection vulnerability in the chatbox of Zhipu AI CodeGeeX v2.17.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message. | ||
| CVE-2024-48140 | Hig | 0.49 | 7.5 | 0.00 | Oct 24, 2024 | A prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica Your AI Copilot powered by ChatGPT4 v6.3.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message. | ||
| CVE-2024-48139 | Hig | 0.49 | 7.5 | 0.00 | Oct 24, 2024 | A prompt injection vulnerability in the chatbox of Blackbox AI v1.3.95 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message. | ||
| CVE-2024-42427 | Hig | 0.49 | 7.6 | 0.01 | Sep 10, 2024 | Dell ThinOS versions 2402 and 2405, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Elevation of privileges. | ||
| CVE-2024-38486 | Hig | 0.49 | 7.5 | 0.01 | Sep 6, 2024 | Dell SmartFabric OS10 Software, version(s) 10.5.5.4 through 10.5.5.10 and 10.5.6.x , contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this… | ||
| CVE-2024-33112 | Hig | 0.49 | 7.5 | 0.06 | May 6, 2024 | D-Link DIR-845L router v1.01KRb03 and before is vulnerable to Command injection via the hnap_main()func. | ||
| CVE-2024-33342 | Hig | 0.49 | 7.5 | 0.02 | Apr 26, 2024 | D-Link DIR-822+ V1.0.5 was found to contain a command injection in SetPlcNetworkpwd function of prog.cgi, which allows remote attackers to execute arbitrary commands via shell. | ||
| CVE-2022-35503 | Hig | 0.49 | 7.5 | 0.01 | Apr 22, 2024 | Improper verification of a user input in Open Source MANO v7-v12 allows an authenticated attacker to execute arbitrary code within the LCM module container via a Virtual Network Function (VNF) descriptor. An attacker may be able execute code to change the normal execution of the… | ||
| CVE-2024-3116 | Hig | 0.49 | 7.4 | 0.65 | Apr 4, 2024 | pgAdmin <= 8.4 is affected by a Remote Code Execution (RCE) vulnerability through the validate binary path API. This vulnerability allows attackers to execute arbitrary code on the server hosting PGAdmin, posing a severe risk to the database management system's integrity and… | ||
| CVE-2024-26204 | Hig | 0.49 | 7.5 | 0.02 | Mar 12, 2024 | Outlook for Android Information Disclosure Vulnerability | ||
| CVE-2024-20667 | Hig | 0.49 | 7.5 | 0.01 | Feb 13, 2024 | Azure DevOps Server Remote Code Execution Vulnerability | ||
| CVE-2023-26320 | Hig | 0.49 | 7.5 | 0.01 | Oct 11, 2023 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Xiaomi Xiaomi Router allows Command Injection. | ||
| CVE-2023-41303 | Hig | 0.49 | 7.5 | 0.01 | Sep 25, 2023 | Command injection vulnerability in the distributed file system module. Successful exploitation of this vulnerability may cause variables in the sock structure to be modified. |
- risk 0.49cvss —epss 0.03
Improper Neutralization of Special Elements in the backup name field may allow OS command injection. This issue affects Pandora ITSM 5.0.105.
- risk 0.49cvss 7.3epss 0.19
A vulnerability, which was classified as critical, has been found in Digital China DCME-520 up to 20250320. This issue affects some unknown processing of the file /usr/local/WWW/function/audit/newstatistics/mon_merge_stat_hist.php. The manipulation of the argument type_name…
- risk 0.49cvss 7.5epss 0.01
An Improper Neutralization of Escape Sequences vulnerability could allow an Authentication Bypass with a Remote Code Execution (RCE) by a malicious actor with access to UniFi Protect Cameras adjacent network.
- risk 0.49cvss 7.5epss 0.01
An attacker may inject commands via specially-crafted post requests.
- risk 0.49cvss 7.6epss 0.00
An injection vulnerability in Barco ClickShare CX-30/20, C-5/10, and ClickShare Bar Pro and Core models, running firmware before 2.21.1, allows physically proximate attackers or local admins to the webUI to trigger OS-level command execution as root.
- risk 0.49cvss 7.5epss 0.00
A potential vulnerability was discovered in certain Poly video conferencing devices. The firmware flaw does not properly sanitize user input. The exploitation of this vulnerability is dependent on a layered attack and cannot be exploited by itself.
- risk 0.49cvss 7.5epss 0.00
A prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica ChatGPT AI Assistant v2.4.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.
- risk 0.49cvss 7.5epss 0.00
A prompt injection vulnerability in the chatbox of Zhipu AI CodeGeeX v2.17.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.
- risk 0.49cvss 7.5epss 0.00
A prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica Your AI Copilot powered by ChatGPT4 v6.3.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.
- risk 0.49cvss 7.5epss 0.00
A prompt injection vulnerability in the chatbox of Blackbox AI v1.3.95 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.
- risk 0.49cvss 7.6epss 0.01
Dell ThinOS versions 2402 and 2405, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Elevation of privileges.
- risk 0.49cvss 7.5epss 0.01
Dell SmartFabric OS10 Software, version(s) 10.5.5.4 through 10.5.5.10 and 10.5.6.x , contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this…
- risk 0.49cvss 7.5epss 0.06
D-Link DIR-845L router v1.01KRb03 and before is vulnerable to Command injection via the hnap_main()func.
- risk 0.49cvss 7.5epss 0.02
D-Link DIR-822+ V1.0.5 was found to contain a command injection in SetPlcNetworkpwd function of prog.cgi, which allows remote attackers to execute arbitrary commands via shell.
- risk 0.49cvss 7.5epss 0.01
Improper verification of a user input in Open Source MANO v7-v12 allows an authenticated attacker to execute arbitrary code within the LCM module container via a Virtual Network Function (VNF) descriptor. An attacker may be able execute code to change the normal execution of the…
- risk 0.49cvss 7.4epss 0.65
pgAdmin <= 8.4 is affected by a Remote Code Execution (RCE) vulnerability through the validate binary path API. This vulnerability allows attackers to execute arbitrary code on the server hosting PGAdmin, posing a severe risk to the database management system's integrity and…
- risk 0.49cvss 7.5epss 0.02
Outlook for Android Information Disclosure Vulnerability
- risk 0.49cvss 7.5epss 0.01
Azure DevOps Server Remote Code Execution Vulnerability
- risk 0.49cvss 7.5epss 0.01
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Xiaomi Xiaomi Router allows Command Injection.
- risk 0.49cvss 7.5epss 0.01
Command injection vulnerability in the distributed file system module. Successful exploitation of this vulnerability may cause variables in the sock structure to be modified.