CWE-77: Command Injection
The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.
Yearly Trend
Top Affected Vendors
All Command Injection CVEs (1,157)
CVE-2023-2520 is a critical command injection vulnerability in Caton Prime's Ping Handler component that allows remote attackers to execute arbitrary ...
May 4, 2023This vulnerability allows authenticated users to impersonate arbitrary users in Apache Spark UI when ACLs are enabled, leading to arbitrary shell comm...
May 2, 2023CVE-2023-30623 is a command injection vulnerability in the embano1/wip GitHub Action that allows attackers to execute arbitrary code on GitHub runners...
Apr 24, 2023CVE-2022-4009 is a command injection vulnerability in Octopus Deploy that allows authenticated users to execute arbitrary code during offline package ...
Mar 16, 2023CVE-2023-27581 is a command injection vulnerability in github-slug-action that allows attackers to execute arbitrary code on GitHub runners by manipul...
Mar 13, 2023This vulnerability allows remote command injection in Akuvox E11 devices through the phone-book contacts functionality. Attackers can upload files con...
Mar 13, 2023This vulnerability allows remote attackers to execute arbitrary commands with root privileges on affected Korenix Jetwave industrial routers. Attacker...
Feb 23, 2023A prototype pollution vulnerability in Rocket.Chat server versions below 5.2.0 allows attackers to achieve remote code execution (RCE) under admin pri...
Feb 23, 2023This vulnerability allows remote attackers to execute arbitrary code on Arris TG2482A routers via the ping utility feature. Attackers can gain full co...
Feb 17, 2023This vulnerability allows a low-privileged remote attacker to execute arbitrary commands on Dell Unisphere for PowerMax vApp, VASA Provider vApp, and ...
Feb 11, 2023CVE-2022-29558 is a command injection vulnerability in Realtek's rtl819x-SDK web interface that allows attackers to execute arbitrary commands on affe...
Jul 28, 2022CVE-2022-32262 is a command injection vulnerability in SINEMA Remote Connect Server that allows attackers to execute arbitrary code through a vulnerab...
Jun 14, 2022This critical vulnerability in SevOne Network Management System allows remote attackers to execute arbitrary commands via the traceroute.php file, lea...
Jun 7, 2022CVE-2022-26042 is an OS command injection vulnerability in InHand Networks InRouter302's daretools binary that allows remote attackers to execute arbi...
May 12, 2022CVE-2022-26085 is an OS command injection vulnerability in InHand Networks InRouter302's httpd wlscan_ASP functionality that allows authenticated atta...
May 12, 2022A remote code execution vulnerability in Ruijie Networks RG-EW Series Routers allows attackers to execute arbitrary commands via the switchFastDhcp fu...
May 4, 2022This vulnerability allows remote attackers to execute arbitrary code on Ruijie Networks RG-EW Series Routers by exploiting improper input validation i...
May 4, 2022CVE-2021-44520 is an authenticated command injection vulnerability in Citrix XenMobile Server that allows authenticated attackers to execute arbitrary...
Apr 13, 2022An authenticated remote code execution vulnerability in Aruba AOS-CX Network Analytics Engine allows attackers with valid credentials to execute arbit...
Mar 2, 2022This vulnerability allows remote attackers to execute arbitrary commands on CommScope SURFboard SBG6950AC2 devices via command injection. It affects u...
Feb 15, 2022CVE-2021-3621 is a command injection vulnerability in SSSD's sssctl command that allows attackers to execute arbitrary shell commands with root privil...
Dec 23, 2021This command injection vulnerability in Ivanti Avalanche allows attackers with access to the Inforail Service to execute arbitrary commands on the sys...
Dec 7, 2021CVE-2021-43339 is a command injection vulnerability in Ericsson Network Location software that allows authenticated attackers to execute arbitrary com...
Nov 3, 2021This vulnerability allows arbitrary code execution on Windows systems where qutebrowser is installed and registered as a URL handler. Attackers can cr...
Oct 21, 2021This vulnerability allows authenticated remote attackers to execute arbitrary commands with root privileges on Cisco Intersight Virtual Appliance by e...
Oct 6, 2021CVE-2021-38169 is a command injection vulnerability in Roxy-WI web interface that allows attackers to execute arbitrary commands on the server. This a...
Aug 7, 2021This vulnerability in xdg-open allows remote attackers to execute arbitrary commands by tricking users into opening a malicious file. It affects Debia...
Jun 2, 2021This CVE describes an arbitrary PHP code execution vulnerability in Drupal Core that allows attackers to create specially named directories on the fil...
May 5, 2021This CVE describes a remote code execution vulnerability in GitHub Enterprise Server where attackers with permission to create GitHub Pages sites coul...
Mar 23, 2021CVE-2020-10519 is a remote code execution vulnerability in GitHub Enterprise Server that allows authenticated users with GitHub Pages creation permiss...
Mar 3, 2021This vulnerability allows attackers on the same network to execute arbitrary code on D-Link DVA-2800 and DSL-2888A routers without authentication. The...
Feb 12, 2021This vulnerability allows attackers on the same network to execute arbitrary code on D-Link DAP-1860 WiFi extenders without authentication. The flaw e...
Feb 12, 2021A command injection vulnerability in F5 BIG-IP Appliance mode allows authenticated administrators to execute arbitrary system commands, potentially cr...
May 7, 2025An authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint when running in Appliance mode with a highly-p...
Feb 5, 2025This JNDI injection vulnerability in Cloudera JDBC connectors allows attackers to inject malicious parameters into JDBC URLs, potentially leading to r...
Jan 16, 2025This vulnerability allows attackers to elevate privileges in Azure CLI environments, potentially gaining unauthorized access to cloud resources. It af...
Oct 8, 2024An authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint on F5 multi-bladed systems running in applianc...
Feb 14, 2024This vulnerability allows authenticated administrators on F5 BIG-IP systems running in Appliance mode to bypass security restrictions through command ...
May 5, 2022This vulnerability allows authenticated attackers to execute arbitrary commands on affected NETGEAR routers. It affects R7000, R6900P, and R7000P mode...
Dec 26, 2021This CVE describes a command injection vulnerability in Linksys E5600 routers that allows attackers to execute arbitrary commands on the device. The v...
Mar 21, 2025This command injection vulnerability in Copilot allows unauthorized attackers to execute arbitrary code on affected systems by injecting malicious com...
Dec 9, 2025This vulnerability in BAE SOCET GXP allows attackers to inject arbitrary executables through the GXP Job Service. If the service is configured for loc...
Oct 23, 2025This vulnerability allows authenticated users to execute arbitrary operating system commands on OpenEdge AdminServer via Java RMI interface manipulati...
Sep 4, 2025A command injection vulnerability in HybridDesk Station allows attackers with local network access to execute arbitrary commands on affected systems. ...
Aug 29, 2025This command injection vulnerability in Azure CLI allows local attackers to execute arbitrary commands with elevated privileges. It affects users runn...
Mar 11, 2025This vulnerability allows remote attackers to execute arbitrary commands on Netgear EX6120 WiFi extenders by injecting malicious commands into the wan...
Oct 14, 2024This vulnerability allows authenticated attackers to execute arbitrary commands on Netgear R7000 routers by injecting malicious input into the device_...
Oct 14, 2024This vulnerability allows authenticated attackers to execute arbitrary commands on Netgear EX3700 AC750 WiFi Range Extender Essentials Edition devices...
Oct 11, 2024CVE-2023-37154 is a command injection vulnerability in Nagios check_by_ssh plugin that allows attackers to execute arbitrary commands on the monitorin...
Oct 9, 2024CVE-2024-43497 is a remote code execution vulnerability in DeepSpeed, Microsoft's deep learning optimization library. It allows attackers to execute a...
Oct 8, 2024About Command Injection (CWE-77)
The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.
Our database tracks 1,157 CVEs classified as CWE-77, with 445 rated critical and 490 rated high severity. The average CVSS score for Command Injection vulnerabilities is 8.3.
External reference: View CWE-77 on MITRE CWE →
Monitor Command Injection Vulnerabilities
Get alerted when new Command Injection CVEs affect your infrastructure.
Start Monitoring Free