CWE-77: Command Injection
The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.
Yearly Trend
Top Affected Vendors
All Command Injection CVEs (1,142)
This vulnerability allows authenticated attackers to execute arbitrary system commands by manipulating uploaded file names. It affects Zenitel communi...
Feb 4, 2026This vulnerability allows authenticated attackers to execute arbitrary commands on affected devices by manipulating the hostname parameter. It affects...
Jan 9, 2026This is a critical remote code execution vulnerability in Zenitel devices that allows unauthenticated attackers to execute arbitrary commands by injec...
Jan 9, 2026A command injection vulnerability in terminal-controller-mcp 0.1.7 allows attackers to execute arbitrary system commands by providing malicious input ...
Jan 7, 2026A critical deserialization vulnerability in Fortra's GoAnywhere MFT License Servlet allows attackers with forged license signatures to execute arbitra...
Sep 18, 2025This critical vulnerability in FLXEON software allows remote attackers to execute arbitrary code with elevated privileges through network access. It a...
Jan 27, 2025This critical vulnerability allows unauthenticated attackers to execute arbitrary operating system commands on Wavlink AC3000 routers by sending speci...
Jan 14, 2025This critical vulnerability allows unauthenticated remote attackers to execute arbitrary commands with root privileges on Cisco URWB Access Points by ...
Nov 6, 2024This vulnerability allows remote attackers to execute arbitrary commands on ProGauge MAGLINK LX CONSOLE UTILITY systems by sending specially crafted P...
Sep 25, 2024CVE-2024-29895 is a critical command injection vulnerability in Cacti's 1.3.x DEV branch that allows unauthenticated attackers to execute arbitrary co...
May 14, 2024This is a critical command injection vulnerability in TRENDnet TEW-827DRU routers that allows remote attackers to execute arbitrary commands with root...
Mar 15, 2024CVE-2022-31161 is a critical remote code execution vulnerability in Roxy-WI web interface versions prior to 6.1.1.0. It allows unauthenticated attacke...
Jul 15, 2022This vulnerability allows attackers to upload malicious files through an API in MDT AutoSave software, which can manipulate process creation commands ...
Apr 1, 2022This vulnerability allows unauthenticated remote attackers to execute arbitrary commands on affected NETGEAR WiFi systems. It affects multiple NETGEAR...
Dec 26, 2021Mesa Labs AmegaView version 3.0 contains a command injection vulnerability (CWE-77) that allows remote attackers to execute arbitrary code on affected...
Dec 21, 2021CVE-2026-22688 is a command injection vulnerability in WeKnora that allows authenticated users to inject malicious commands into MCP stdio settings, c...
Jan 10, 2026This critical vulnerability in TLS4B ATG systems allows authenticated remote attackers to execute arbitrary system commands on the underlying Linux op...
Oct 23, 2025Flowise versions 3.0.1 through 3.0.7 and all later versions with 'ALLOW_BUILTIN_DEP' enabled contain an authenticated remote code execution vulnerabil...
Oct 14, 2025This CVE describes a command injection vulnerability in the WordPress Widget Options plugin that allows attackers to execute arbitrary operating syste...
Feb 14, 2025An authenticated low-privileged attacker can execute arbitrary CLI commands with network-admin privileges on Cisco NDFC-managed devices via command in...
Oct 2, 2024CVE-2023-25911 is a critical OS command injection vulnerability in Danfoss AK-EM100 web applications that allows authenticated attackers to execute ar...
Jun 11, 2023CVE-2023-27407 is a command injection vulnerability in SCALANCE LPE9403 industrial network devices that allows authenticated remote attackers to execu...
May 9, 2023This is a command injection vulnerability in Synology Download Station that allows authenticated remote attackers to execute arbitrary commands on the...
Jun 18, 2021This CVE describes a remote command injection vulnerability in D-Link DIR-868L routers via the SSDP service. Attackers can execute arbitrary operating...
Mar 3, 2026This CVE describes a remote command injection vulnerability in SECCN Dingcheng G10 software version 3.1.0.181203. Attackers can execute arbitrary oper...
Feb 19, 2026Orval versions 7.19.0 and below and 8.0.0-rc.0 through 8.0.2 contain a code injection vulnerability where untrusted OpenAPI specifications can inject ...
Jan 23, 2026Orval versions 7.19.0 through 8.0.2 contain a code injection vulnerability in the x-enumDescriptions field processing. Untrusted OpenAPI specification...
Jan 20, 2026This CVE describes a remote command injection vulnerability in Apache bRPC's heap profiler service. Attackers can execute arbitrary commands by inject...
Jan 16, 2026A command injection vulnerability in D-Link DIR895LA1 routers allows attackers to execute arbitrary commands with root privileges by sending malicious...
Jan 9, 2026EDIMAX BR-6208AC V2 router firmware version 1.02 contains a command injection vulnerability in the pppUserName field that allows attackers to execute ...
Jan 9, 2026This CVE describes a remote command injection vulnerability in TRENDnet TEW-713RE routers. Attackers can execute arbitrary operating system commands b...
Jan 7, 2026CVE-2025-69201 is a command injection vulnerability in Tugtainer's agent API that allows attackers to inject arbitrary arguments into docker container...
Dec 29, 2025CVE-2025-67728 is a command injection vulnerability in Fireshare that allows authenticated users (or unauthenticated users if Public Uploads is enable...
Dec 12, 2025CVE-2025-66032 is a command injection vulnerability in Claude Code that allows bypassing read-only validation to execute arbitrary code. Attackers can...
Dec 3, 2025This vulnerability allows remote attackers to execute arbitrary commands on D-Link R15 (AX1500) routers by manipulating the model name parameter durin...
Dec 2, 2025CVE-2025-66219 is a command injection vulnerability in willitmerge, a command-line tool for checking pull request mergeability. Attackers can execute ...
Nov 29, 2025This is a critical command injection vulnerability in AndSoft's e-TMS v25.03 that allows unauthenticated attackers to execute arbitrary operating syst...
Oct 2, 2025This is a critical command injection vulnerability in AndSoft's e-TMS transportation management system. Attackers can execute arbitrary operating syst...
Oct 2, 2025This is a critical command injection vulnerability in AndSoft's e-TMS v25.03 that allows attackers to execute arbitrary operating system commands on t...
Oct 2, 2025This is a critical command injection vulnerability in AndSoft's e-TMS transportation management system. Attackers can execute arbitrary operating syst...
Oct 2, 2025This is a critical command injection vulnerability in AndSoft's e-TMS v25.03 that allows unauthenticated attackers to execute arbitrary operating syst...
Oct 2, 2025This is a critical command injection vulnerability in AndSoft's e-TMS transportation management software that allows unauthenticated attackers to exec...
Oct 2, 2025This is a critical command injection vulnerability in AndSoft's e-TMS transportation management software that allows unauthenticated attackers to exec...
Oct 2, 2025This CVE describes a command injection vulnerability in TOTOLINK X18 routers that allows attackers to execute arbitrary commands on the device. The vu...
Oct 1, 2025This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK X18 routers by injecting malicious code into the mac parameter of...
Oct 1, 2025CVE-2025-59834 is a command injection vulnerability in ADB MCP Server versions 0.1.0 and earlier that allows attackers to execute arbitrary commands o...
Sep 25, 2025This is a critical command injection vulnerability in TOTOLINK X6000R routers that allows unauthenticated attackers to execute arbitrary commands on a...
Sep 15, 2025CVE-2025-59046 is a command injection vulnerability in the interactive-git-checkout npm package that allows attackers to execute arbitrary commands on...
Sep 9, 2025This CVE describes a critical command injection vulnerability in FTP-Flask-python that allows unauthenticated remote attackers to execute arbitrary op...
Sep 9, 2025CVE-2025-57285 is a critical command injection vulnerability in codeceptjs 3.7.3 that allows attackers to execute arbitrary commands on the host syste...
Sep 8, 2025About Command Injection (CWE-77)
The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.
Our database tracks 1,142 CVEs classified as CWE-77, with 441 rated critical and 479 rated high severity. The average CVSS score for Command Injection vulnerabilities is 8.3.
External reference: View CWE-77 on MITRE CWE →
Monitor Command Injection Vulnerabilities
Get alerted when new Command Injection CVEs affect your infrastructure.
Start Monitoring Free