CWE-77 · 3 230 записей
Improper Neutralization of Special Elements used in a Command ('Command Injection')
CVE этого класса
3 228 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2023-1671Готовый эксплойт | A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution sophos · web appliance · CWE-77 | Критическая9,8 | KEV | 100,0 % | 4 апр. 2023 г. |
99Срочно | CVE-2012-1823Готовый эксплойт | sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle quephp · php · CWE-77 | Критическая9,8 | KEV | 100,0 % | 11 мая 2012 г. |
99Срочно | CVE-2024-3273Готовый эксплойт | D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injectiondlink · dns-320l firmware · CWE-77 | Критическая9,8 | KEV | 100,0 % | 3 апр. 2024 г. |
99Срочно | CVE-2025-10035Готовый эксплойт | Deserialization Vulnerability in GoAnywhere MFT's License Servletfortra · goanywhere managed file transfer · CWE-77 | Критическая9,8 | KEV | 99,8 % | 18 сент. 2025 г. |
98Срочно | CVE-2016-1555Готовый эксплойт | (1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear WN604 before 3.3.3 netgear · wnap320 firmware · CWE-77 | Критическая9,8 | KEV | 98,3 % | 21 апр. 2017 г. |
98Срочно | CVE-2023-20887Готовый эксплойт | Aria Operations for Networks contains a command injection vulnerability.vmware · aria operations for networks · CWE-77 | Критическая9,8 | KEV | 98,3 % | 7 июн. 2023 г. |
98Срочно | CVE-2007-3010Готовый эксплойт | masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to exeal-enterprise · omnipcx enterprise communication server · CWE-77 | Критическая9,8 | KEV | 97,4 % | 18 сент. 2007 г. |
97Срочно | CVE-2024-55956Готовый эксплойт | In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitcleo · harmony · CWE-77 | Критическая9,8 | KEV | 94,0 % | 13 дек. 2024 г. |
96Срочно | CVE-2024-21887Готовый эксплойт | A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an autivanti · connect secure · CWE-77 | Критическая9,1 | KEV | 100,0 % | 12 янв. 2024 г. |
95Срочно | CVE-2023-1389Готовый эксплойт | TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form otp-link · archer ax21 firmware · CWE-77 | Высокая8,8 | KEV | 100,0 % | 15 мар. 2023 г. |
95Срочно | CVE-2024-12356Готовый эксплойт | Command Injection Vulnerability in Remote Support(RS) & Privileged Remote Access (PRA)beyondtrust · privileged remote access · CWE-77 | Критическая9,8 | KEV | 87,3 % | 17 дек. 2024 г. |
94Срочно | CVE-2015-2051Готовый эксплойт | The D-Link DIR-645 Wired/Wireless Router Rev.dlink · dir-645 firmware · CWE-77 | Высокая8,8 | KEV | 97,1 % | 23 февр. 2015 г. |
92Срочно | CVE-2025-4008Готовый эксплойт | Arbitrary Command Injection in Smartbedded MeteoBridgesmartbedded · meteobridge vm · CWE-77 | Высокая8,7 | KEV | 93,7 % | 21 мая 2025 г. |
92Срочно | CVE-2026-8037Готовый эксплойт | OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAFprogress · connection manager for objectscale · CWE-77 | Критическая9,8 | KEV | 77,4 % | 4 июн. 2026 г. |
91Срочно | CVE-2005-2773Готовый эксплойт | HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) hp · openview network node manager · CWE-77 | Критическая9,8 | KEV | 74,6 % | 2 сент. 2005 г. |
88Срочно | CVE-2016-20017Готовый эксплойт | D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wildlink · dsl-2750b firmware · CWE-77 | Критическая9,8 | KEV | 64,2 % | 19 окт. 2022 г. |
86Срочно | CVE-2024-12987Готовый эксплойт | DrayTek Vigor2960/Vigor300B Web Management Interface apmcfgupload os command injectiondraytek · vigor300b firmware · CWE-77 | Средняя6,9 | KEV | 98,1 % | 27 дек. 2024 г. |
84Срочно | CVE-2025-29635Готовый эксплойт | A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remotedlink · dir-823x firmware · CWE-77 | Высокая7,2 | KEV | 87,9 % | 25 мар. 2025 г. |
81Срочно | CVE-2020-25079Готовый эксплойт | An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices.dlink · dcs-4703e firmware · CWE-77 | Высокая8,8 | KEV | 54,0 % | 2 сент. 2020 г. |
81Срочно | CVE-2019-0541Готовый эксплойт | A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Exmicrosoft · internet explorer · CWE-77 | Высокая8,8 | KEV | 53,2 % | 8 янв. 2019 г. |
81Срочно | CVE-2010-5330Готовый эксплойт | On certain Ubiquiti devices, Command Injection exists via a GET request to stainfo.cgi (aka Show AP info) because the ifname variable is notui · airos · CWE-77 | Критическая9,8 | KEV | 39,4 % | 11 июн. 2019 г. |
79На этой неделе | CVE-2020-2509Готовый эксплойт | Command Injection Vulnerability in QTS and QuTS heroqnap · qts · CWE-77 | Критическая9,8 | KEV | 34,0 % | 17 апр. 2021 г. |
77На этой неделе | CVE-2023-33538Готовый эксплойт | TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerability via the componenttp-link · tl-wr940n firmware · CWE-77 | Высокая8,8 | KEV | 41,6 % | 7 июн. 2023 г. |
76На этой неделе | CVE-2024-9380Готовый эксплойт | An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker witivanti · endpoint manager cloud services appliance · CWE-77 | Высокая7,2 | KEV | 59,7 % | 8 окт. 2024 г. |
76На этой неделе | CVE-2017-6327Готовый эксплойт | The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution, which describes a situation whereby an indsymantec · message gateway · CWE-77 | Высокая8,8 | KEV | 35,9 % | 11 авг. 2017 г. |
- CVE-2023-167199Срочно
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %sophos · web appliance4 апр. 2023 г.
- CVE-2012-182399Срочно
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle que
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %php · php11 мая 2012 г.
- CVE-2024-327399Срочно
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %dlink · dns-320l firmware3 апр. 2024 г.
- CVE-2025-1003599Срочно
Deserialization Vulnerability in GoAnywhere MFT's License Servlet
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %fortra · goanywhere managed file transfer18 сент. 2025 г.
- CVE-2016-155598Срочно
(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear WN604 before 3.3.3
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 98 %netgear · wnap320 firmware21 апр. 2017 г.
- CVE-2023-2088798Срочно
Aria Operations for Networks contains a command injection vulnerability.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 98 %vmware · aria operations for networks7 июн. 2023 г.
- CVE-2007-301098Срочно
masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to exe
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %al-enterprise · omnipcx enterprise communication server18 сент. 2007 г.
- CVE-2024-5595697Срочно
In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbit
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 94 %cleo · harmony13 дек. 2024 г.
- CVE-2024-2188796Срочно
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an aut
КритическаяCVSS 9,1KEVГотовый эксплойтEPSS 100 %ivanti · connect secure12 янв. 2024 г.
- CVE-2023-138995Срочно
TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form o
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 100 %tp-link · archer ax21 firmware15 мар. 2023 г.
- CVE-2024-1235695Срочно
Command Injection Vulnerability in Remote Support(RS) & Privileged Remote Access (PRA)
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 87 %beyondtrust · privileged remote access17 дек. 2024 г.
- CVE-2015-205194Срочно
The D-Link DIR-645 Wired/Wireless Router Rev.
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 97 %dlink · dir-645 firmware23 февр. 2015 г.
- CVE-2025-400892Срочно
Arbitrary Command Injection in Smartbedded MeteoBridge
ВысокаяCVSS 8,7KEVГотовый эксплойтEPSS 94 %smartbedded · meteobridge vm21 мая 2025 г.
- CVE-2026-803792Срочно
OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 77 %progress · connection manager for objectscale4 июн. 2026 г.
- CVE-2005-277391Срочно
HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1)
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 75 %hp · openview network node manager2 сент. 2005 г.
- CVE-2016-2001788Срочно
D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wil
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 64 %dlink · dsl-2750b firmware19 окт. 2022 г.
- CVE-2024-1298786Срочно
DrayTek Vigor2960/Vigor300B Web Management Interface apmcfgupload os command injection
СредняяCVSS 6,9KEVГотовый эксплойтEPSS 98 %draytek · vigor300b firmware27 дек. 2024 г.
- CVE-2025-2963584Срочно
A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote
ВысокаяCVSS 7,2KEVГотовый эксплойтEPSS 88 %dlink · dir-823x firmware25 мар. 2025 г.
- CVE-2020-2507981Срочно
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices.
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 54 %dlink · dcs-4703e firmware2 сент. 2020 г.
- CVE-2019-054181Срочно
A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Ex
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 53 %microsoft · internet explorer8 янв. 2019 г.
- CVE-2010-533081Срочно
On certain Ubiquiti devices, Command Injection exists via a GET request to stainfo.cgi (aka Show AP info) because the ifname variable is not
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 39 %ui · airos11 июн. 2019 г.
- CVE-2020-250979На этой неделе
Command Injection Vulnerability in QTS and QuTS hero
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 34 %qnap · qts17 апр. 2021 г.
- CVE-2023-3353877На этой неделе
TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerability via the component
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 42 %tp-link · tl-wr940n firmware7 июн. 2023 г.
- CVE-2024-938076На этой неделе
An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker wit
ВысокаяCVSS 7,2KEVГотовый эксплойтEPSS 60 %ivanti · endpoint manager cloud services appliance8 окт. 2024 г.
- CVE-2017-632776На этой неделе
The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution, which describes a situation whereby an ind
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 36 %symantec · message gateway11 авг. 2017 г.