CWE-78

Total CVEs
4K
Vulnerabilities
Avg CVSS v3
8.6
High
Avg CVSS v2
8.2
High
Latest CVE
2025
Most Recent

Severity Distribution

Critical 1.4K
35.1%
High 2.2K
55.7%
Medium 358
9%
Low 8
0.2%

External References

All CVEs (4K)

Page 1 of 165
CVSS:10.0(Critical)

In MITRE Caldera through 4.2.0 and 5.0.0 before 35bc06e, a Remote Code Execution (RCE) vulnerability was found in the dynamic agent (implant) compilation functionality of the server. This allows remot...

CWE-782025
CVSS:10.0(Critical)

A vulnerability has been identified in OZW672 (All versions < V8.0), OZW772 (All versions < V8.0). The web service in affected devices does not sanitize the input parameters required for the `exportDi...

CWE-782025
CVSS:10.0(Critical)

An OS Command Injection vulnerability exists within myPRO Manager. A parameter within a command can be exploited by an unauthenticated remote attacker to inject arbitrary operating system commands.

CWE-782024
CVSS:10.0(Critical)

CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecutioner() sink. There is /filemanager/upload (aka File Manager upload) unauthentic...

CWE-782024
CVSS:10.0(Critical)

A parameter within a command does not properly validate input within myPRO Manager which could be exploited by an unauthenticated remote attacker to inject arbitrary operating system commands.

CWE-782024
CVSS:10.0(Critical)

Rust is a programming language. The Rust Security Response WG was notified that the Rust standard library prior to version 1.77.2 did not properly escape arguments when invoking batch files (with the ...

CWE-782024
CVSS:10.0(Critical)

An attacker can overwrite any file on the server hosting MLflow without any authentication.

CWE-782023
CVSS:10.0(Critical)

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in ZkTeco-based OEM devices allows OS Command Injection. Since all the found command implementa...

CWE-782023
CVSS:10.0(Critical)

vm2 is an open source vm/sandbox for Node.js. In vm2 for versions up to and including 3.9.19, Node.js custom inspect function allows attackers to escape the sandbox and run arbitrary code. This may re...

CWE-782023
CVSS:10.0(Critical)

OS Command Injection in GitHub repository sbs20/scanservjs prior to v2.27.0.

CWE-782023
CVSS:10.0(Critical)

Four OS command injection vulnerabilities exists in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted HTTP ...

CWE-782022
CVSS:10.0(Critical)

Four OS command injection vulnerabilities exists in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted HTTP ...

CWE-782022
CVSS:10.0(Critical)

Four OS command injection vulnerabilities exists in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted HTTP ...

CWE-782022
CVSS:10.0(Critical)

Four OS command injection vulnerabilities exists in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted HTTP ...

CWE-782022
CVSS:10.0(Critical)

Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A XCMD can lead to arbitrary command execution. ...

CWE-782022
CVSS:10.0(Critical)

Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A XCMD can lead to arbitrary command execution. ...

CWE-782022
CVSS:10.0(Critical)

Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A XCMD can lead to arbitrary command execution. ...

CWE-782022
CVSS:10.0(Critical)

Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A XCMD can lead to arbitrary command execution. ...

CWE-782022
CVSS:10.0(Critical)

An OS command injection vulnerability exists in the XCMD setAlexa functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z. A specially-crafted XCMD can lead to arbitrary command executi...

CWE-782022
CVSS:10.0(Critical)

An OS command injection vulnerability exists in the XCMD doDebug functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted XCMD can lead to arbitrary command...

CWE-782022
CVSS:10.0(Critical)

An OS command injection vulnerability exists in the web interface /action/iperf functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted HTTP request can le...

CWE-782022
CVSS:10.0(Critical)

An OS command injection vulnerability exists in the XCMD setUPnP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted XCMD can lead to arbitrary command...

CWE-782022
CVSS:10.0(Critical)

An OS command injection vulnerability exists in the web interface util_set_serial_mac functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted HTTP request ...

CWE-782022
CVSS:10.0(Critical)

OS Command Injection in GitHub repository gogs/gogs prior to 0.12.9.

CWE-782022