Vulnerabilities (CVE)

Filtered by CWE-77
Total 937 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-1040 1 Agpt 1 Autogpt 2025-04-01 N/A 8.8 HIGH
AutoGPT versions 0.3.4 and earlier are vulnerable to a Server-Side Template Injection (SSTI) that could lead to Remote Code Execution (RCE). The vulnerability arises from the improper handling of user-supplied format strings in the `AgentOutputBlock` implementation, where malicious input is passed to the Jinja2 templating engine without adequate security measures. Attackers can exploit this flaw to execute arbitrary commands on the host system. The issue is fixed in version 0.4.0.
CVE-2022-25908 1 Create-choo-electron Project 1 Create-choo-electron 2025-04-01 N/A 7.4 HIGH
All versions of the package create-choo-electron are vulnerable to Command Injection via the devInstall function due to improper user-input sanitization.
CVE-2022-25350 1 Helecloud 1 Puppet-facter 2025-04-01 N/A 7.4 HIGH
All versions of the package puppet-facter are vulnerable to Command Injection via the getFact function due to improper input sanitization.
CVE-2024-28353 1 Trendnet 2 Tew-827dru, Tew-827dru Firmware 2025-04-01 N/A 8.8 HIGH
There is a command injection vulnerability in the TRENDnet TEW-827DRU router with firmware version 2.10B01. An attacker can inject commands into the post request parameters usapps.config.smb_admin_name in the apply.cgi interface, thereby gaining root shell privileges.
CVE-2022-25962 1 Vagrant.js Project 1 Vagrant.js 2025-04-01 N/A 7.4 HIGH
All versions of the package vagrant.js are vulnerable to Command Injection via the boxAdd function due to improper input sanitization.
CVE-2022-21810 1 Smartctl Project 1 Smartctl 2025-04-01 N/A 7.4 HIGH
All versions of the package smartctl are vulnerable to Command Injection via the info method due to improper input sanitization.
CVE-2024-42636 1 Dedecms 1 Dedecms 2025-03-31 N/A 7.2 HIGH
DedeCMS V5.7.115 has a command execution vulnerability via file_manage_view.php?fmdo=newfile&activepath.
CVE-2024-12251 1 Telerik 1 Ui For Winui 2025-03-28 N/A 7.8 HIGH
In ProgressĀ® TelerikĀ® UI for WinUI versions prior to 2025 Q1 (3.0.0), a command injection attack is possible through improper neutralization of hyperlink elements.
CVE-2024-44916 1 Seacms 1 Seacms 2025-03-28 N/A 7.2 HIGH
Vulnerability in admin_ip.php in Seacms v13.1, when action=set, allows attackers to control IP parameters that are written to the data/admin/ip.php file and could result in arbitrary command execution.
CVE-2024-28041 2025-03-28 N/A 8.8 HIGH
HGW BL1500HM Ver 002.001.013 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary command.
CVE-2022-21129 1 Paypal 1 Nemo-appium 2025-03-27 N/A 7.4 HIGH
Versions of the package nemo-appium before 0.0.9 are vulnerable to Command Injection due to improper input sanitization in the 'module.exports.setup' function. **Note:** In order to exploit this vulnerability appium-running 0.1.3 has to be installed as one of nemo-appium dependencies.
CVE-2024-26296 1 Arubanetworks 1 Clearpass Policy Manager 2025-03-27 N/A 7.2 HIGH
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise.
CVE-2024-26295 1 Arubanetworks 1 Clearpass Policy Manager 2025-03-27 N/A 7.2 HIGH
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise.
CVE-2024-26297 1 Arubanetworks 1 Clearpass Policy Manager 2025-03-27 N/A 7.2 HIGH
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise.
CVE-2024-26298 1 Arubanetworks 1 Clearpass Policy Manager 2025-03-27 N/A 7.2 HIGH
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise.
CVE-2024-26294 1 Arubanetworks 1 Clearpass Policy Manager 2025-03-27 N/A 7.2 HIGH
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system leading to complete system compromise.
CVE-2022-25916 1 Mt7688-wiscan Project 1 Mt7688-wiscan 2025-03-27 N/A 7.4 HIGH
Versions of the package mt7688-wiscan before 0.8.3 are vulnerable to Command Injection due to improper input sanitization in the 'wiscan.scan' function.
CVE-2024-27818 1 Apple 3 Ipados, Iphone Os, Macos 2025-03-26 N/A 7.8 HIGH
The issue was addressed with improved memory handling. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5. An attacker may be able to cause unexpected app termination or arbitrary code execution.
CVE-2024-23247 1 Apple 1 Macos 2025-03-26 N/A 7.8 HIGH
The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.4, macOS Monterey 12.7.4, macOS Ventura 13.6.5. Processing a file may lead to unexpected app termination or arbitrary code execution.
CVE-2022-25855 1 Create-choo-app3 Project 1 Create-choo-app3 2025-03-25 N/A 7.4 HIGH
All versions of the package create-choo-app3 are vulnerable to Command Injection via the devInstall function due to improper user-input sanitization.