CWE-77: Command Injection

The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.

1,157
Total CVEs
445
Critical
490
High
8.3
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
82
2025
378
2024
247
2023
225
2022
77

Top Affected Vendors

1 Totolink 107
2 Dlink 80
3 Netgear 73
4 Tenda 35
5 Arubanetworks 32
6 Linksys 28
7 Microsoft 24
8 Qnap 19
9 Siemens 18
10 Wavlink 17

All Command Injection CVEs (1,157)

CVE-2025-64424
8.8

A command injection vulnerability in Coolify allows low-privileged users (members) to execute arbitrary system commands as root on the Coolify instanc...

Jan 5, 2026
CVE-2025-66738
8.8

A command injection vulnerability in Yealink T21P_E2 phones allows remote attackers with normal privileges to execute arbitrary code via crafted reque...

Dec 26, 2025
CVE-2025-57201
8.8

This CVE describes an authenticated command injection vulnerability in AVTECH SECURITY Corporation's DGM1104 FullImg-1015-1004-1006-1003 SMB server fu...

Dec 3, 2025
CVE-2025-57198
8.8

This vulnerability allows authenticated attackers to execute arbitrary commands on AVTECH SECURITY DGM1104 devices via the Machine.cgi endpoint. Organ...

Dec 3, 2025
CVE-2025-57199
8.8

This vulnerability allows authenticated attackers to execute arbitrary commands on AVTECH SECURITY Corporation DGM1104 devices through the NetFailDete...

Dec 3, 2025
CVE-2025-66399
8.8

This vulnerability allows authenticated Cacti users to inject malicious SNMP community strings containing control characters like newlines. When these...

Dec 2, 2025
CVE-2025-63406
8.8

This vulnerability allows remote attackers to execute arbitrary code on GroupOffice installations via improper input validation in the dbToApi() funct...

Nov 13, 2025
CVE-2025-46427
8.8

Dell SmartFabric OS10 Software versions before 10.6.1.0 contain a command injection vulnerability that allows low-privileged remote attackers to execu...

Nov 12, 2025
CVE-2025-46428
8.8

Dell SmartFabric OS10 Software contains a command injection vulnerability that allows low-privileged remote attackers to execute arbitrary code on aff...

Nov 12, 2025
CVE-2025-9223
8.8

This vulnerability allows authenticated attackers to execute arbitrary commands on ManageEngine Applications Manager servers. Attackers with valid cre...

Nov 11, 2025
CVE-2025-55848
8.8

This vulnerability allows remote command execution on D-Link DIR-823 routers through improper input filtering in the set_cassword settings interface. ...

Sep 26, 2025
CVE-2025-59831
8.8

CVE-2025-59831 is a command injection vulnerability in git-commiters Node.js module that allows attackers to execute arbitrary commands on the host sy...

Sep 25, 2025
CVE-2025-20334
8.8

A command injection vulnerability in Cisco IOS XE's HTTP API allows authenticated attackers or social engineering victims to execute arbitrary command...

Sep 24, 2025
CVE-2025-57685
8.8

This vulnerability allows unauthenticated attackers to execute arbitrary commands with highest privileges on affected LB-Link routers. Attackers can e...

Sep 22, 2025
CVE-2025-43953
8.8

This vulnerability allows authenticated admin and manager users of 2wcom IP-4c devices to execute arbitrary code with root privileges through the web ...

Sep 22, 2025
CVE-2025-57293
8.8

A command injection vulnerability in COMFAST CF-XR11 routers allows attackers to execute arbitrary commands via a POST request to the multi_pppoe API....

Sep 18, 2025
CVE-2025-55319
8.8

This vulnerability allows remote command injection in Agentic AI and Visual Studio Code, enabling unauthorized attackers to execute arbitrary code ove...

Sep 12, 2025
CVE-2025-55227
8.8

This command injection vulnerability in SQL Server allows authenticated attackers to execute arbitrary commands on the database server, potentially ga...

Sep 9, 2025
CVE-2025-9161
8.8

This vulnerability in FactoryTalk Optix MQTT broker allows remote attackers to load malicious Mosquito plugins due to insufficient URI sanitization, l...

Sep 9, 2025
CVE-2025-30264
8.8

This CVE describes a command injection vulnerability in QNAP operating systems that allows authenticated attackers to execute arbitrary commands on af...

Aug 29, 2025
CVE-2024-53945
8.8

This vulnerability allows authenticated attackers to execute arbitrary operating system commands with root privileges on KuWFi 4G AC900 LTE routers. A...

Aug 14, 2025
CVE-2025-54782
EPSS 24.4% 8.8

A critical Remote Code Execution vulnerability in @nestjs/devtools-integration package allows malicious websites to execute arbitrary code on a develo...

Aug 2, 2025
CVE-2025-6104
8.8

This critical vulnerability allows remote attackers to execute arbitrary operating system commands on Wifi-soft UniBox Controller systems by manipulat...

Jun 16, 2025
CVE-2025-6102
8.8

This critical vulnerability in Wifi-soft UniBox Controller allows remote attackers to execute arbitrary operating system commands via command injectio...

Jun 16, 2025
CVE-2025-22481
8.8

A command injection vulnerability in QNAP operating systems allows authenticated remote attackers to execute arbitrary commands on affected devices. T...

Jun 6, 2025
CVE-2025-48492
8.8

This vulnerability allows authenticated users with Edit component access in GetSimple CMS to inject arbitrary PHP code into component files, leading t...

May 30, 2025
CVE-2024-55063
8.8

Multiple code injection vulnerabilities in EasyVirt DC NetScope allow remote authenticated attackers to execute arbitrary code via various parameters....

May 19, 2025
CVE-2025-29509
8.8

CVE-2025-29509 is a remote code execution vulnerability in Jan AI desktop application versions 0.5.14 and earlier. Attackers can exploit this by trick...

May 9, 2025
CVE-2025-29635
8.8

A command injection vulnerability in D-Link DIR-823X routers allows authenticated attackers to execute arbitrary commands on affected devices by sendi...

Mar 25, 2025
CVE-2024-12971
EPSS 73.6% 8.8

This CVE allows attackers to execute arbitrary operating system commands on Pandora FMS servers by injecting malicious input into vulnerable parameter...

Mar 17, 2025
CVE-2024-46662
8.8

This command injection vulnerability in Fortinet FortiManager allows attackers to execute arbitrary commands with elevated privileges by sending speci...

Mar 14, 2025
CVE-2024-13871
8.8

An unauthenticated command injection vulnerability in Bitdefender Box 1 allows network-adjacent attackers to execute arbitrary commands on the device,...

Mar 12, 2025
CVE-2025-0593
8.8

This vulnerability allows remote attackers with low privileges to execute arbitrary shell commands on affected SICK devices by exploiting improper neu...

Feb 14, 2025
CVE-2024-23971
8.8

CVE-2024-23971 is a command injection vulnerability in ChargePoint Home Flex charging stations that allows network-adjacent attackers to execute arbit...

Jan 31, 2025
CVE-2025-24150
8.8

This vulnerability allows command injection when copying URLs from Web Inspector in affected Apple products. Attackers could execute arbitrary command...

Jan 27, 2025
CVE-2024-48419
EPSS 11.3% 8.8

This CVE describes multiple command injection vulnerabilities in Edimax AC1200 routers that allow authenticated attackers to execute arbitrary shell c...

Jan 27, 2025
CVE-2025-23196
8.8

This CVE describes a code injection vulnerability in Apache Ambari's Alert Definition feature where authenticated users can inject arbitrary shell com...

Jan 21, 2025
CVE-2024-51442
EPSS 36.3% 8.8

CVE-2024-51442 is a command injection vulnerability in MiniDLNA v1.3.3 and earlier that allows attackers to execute arbitrary operating system command...

Jan 8, 2025
CVE-2024-13129
8.8

CVE-2024-13129 is a critical OS command injection vulnerability in Roxy-WI's action_service function that allows remote attackers to execute arbitrary...

Jan 3, 2025
CVE-2024-39703
8.8

This vulnerability allows authenticated users in ThreatQuotient ThreatQ to execute arbitrary commands on the system by sending specially crafted reque...

Dec 18, 2024
CVE-2024-55544
8.8

This vulnerability allows authenticated attackers to execute arbitrary operating system commands on ORing IAP-420 devices through the web interface. A...

Dec 10, 2024
CVE-2024-51114
8.8

This vulnerability allows remote attackers to execute arbitrary code on affected Digital China Yunke systems via a specific PHP file. It affects Beiji...

Dec 3, 2024
CVE-2021-38116
8.8

CVE-2021-38116 is an elevation of privilege vulnerability in OpenText iManager that allows authenticated users to execute arbitrary commands with high...

Nov 22, 2024
CVE-2024-50852
8.8

This CVE describes a command injection vulnerability in Tenda G3 routers that allows attackers to execute arbitrary commands on the device. The vulner...

Nov 13, 2024
CVE-2024-51258
8.8

This vulnerability allows remote attackers to execute arbitrary commands on DrayTek Vigor3900 routers by injecting malicious commands into the mainfun...

Oct 30, 2024
CVE-2024-51257
8.8

This vulnerability allows attackers to inject malicious commands into the mainfunction.cgi component of DrayTek Vigor3900 routers by exploiting the do...

Oct 30, 2024
CVE-2024-51300
8.8

This vulnerability allows remote attackers to execute arbitrary commands on Draytek Vigor3900 routers by injecting malicious commands into the mainfun...

Oct 30, 2024
CVE-2024-51304
8.8

This vulnerability allows remote attackers to execute arbitrary commands on Draytek Vigor3900 routers by injecting malicious commands into the mainfun...

Oct 30, 2024
CVE-2024-48441
8.8

This vulnerability allows unauthenticated attackers to execute arbitrary operating system commands on Tianyu CPE routers via the at_command.asp compon...

Oct 24, 2024
CVE-2024-44570
8.8

RELY-PCIe versions v22.2.1 to v23.1.0 contain a code injection vulnerability in the getParams function within phpinf.php. This allows attackers to exe...

Sep 11, 2024

About Command Injection (CWE-77)

The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.

Our database tracks 1,157 CVEs classified as CWE-77, with 445 rated critical and 490 rated high severity. The average CVSS score for Command Injection vulnerabilities is 8.3.

External reference: View CWE-77 on MITRE CWE →

Monitor Command Injection Vulnerabilities

Get alerted when new Command Injection CVEs affect your infrastructure.

Start Monitoring Free