CWE-77: Command Injection
The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.
Yearly Trend
Top Affected Vendors
All Command Injection CVEs (1,159)
CVE-2023-37154 is a command injection vulnerability in Nagios check_by_ssh plugin that allows attackers to execute arbitrary commands on the monitorin...
Oct 9, 2024CVE-2024-43497 is a remote code execution vulnerability in DeepSpeed, Microsoft's deep learning optimization library. It allows attackers to execute a...
Oct 8, 2024This vulnerability allows authenticated SSH users with the 'config' account on affected Arista Wireless Access Points to escalate privileges to root b...
Jun 27, 2024CVE-2024-6257 is a vulnerability in HashiCorp's go-getter library where an attacker can manipulate Git configuration files to execute arbitrary code d...
Jun 25, 2024This vulnerability in Astropy allows remote code execution through improper input validation in the TransformGraph().to_dot_graph function. An attacke...
Mar 18, 2024CVE-2023-25643 is a command injection vulnerability in certain ZTE mobile internet products that allows authenticated attackers to execute arbitrary c...
Dec 14, 2023This vulnerability allows remote administrators to execute arbitrary code with root privileges on ESM systems by exploiting improper input sanitizatio...
Nov 30, 2023This vulnerability allows authenticated attackers to execute arbitrary commands on affected NETGEAR WiFi systems. It affects RBK752, RBR750, RBS750, R...
Dec 26, 2021This vulnerability allows authenticated users to execute arbitrary commands on affected NETGEAR WiFi systems through command injection. It affects spe...
Dec 26, 2021This vulnerability allows authenticated users to execute arbitrary commands on affected NETGEAR WiFi systems. It affects RBK752, RBR750, RBS750, RBK85...
Dec 26, 2021This vulnerability allows authenticated attackers to execute arbitrary commands on affected NETGEAR WiFi systems. It affects RBK752, RBR750, RBS750, R...
Dec 26, 2021This vulnerability allows authenticated users to execute arbitrary commands on affected NETGEAR WiFi systems through command injection. It affects mul...
Dec 26, 2021This vulnerability allows authenticated users to execute arbitrary commands on affected NETGEAR WiFi systems. It affects specific NETGEAR CBR40, CBR75...
Dec 26, 2021This vulnerability allows authenticated users to execute arbitrary commands on affected NETGEAR WiFi systems. It affects specific NETGEAR CBR40, CBR75...
Dec 26, 2021This vulnerability allows authenticated users on certain NETGEAR WiFi systems to execute arbitrary commands through command injection. It affects spec...
Dec 26, 2021This vulnerability allows authenticated users to execute arbitrary commands on affected NETGEAR WiFi systems. It affects RBK752, RBR750, RBS750, RBK85...
Dec 26, 2021This vulnerability allows authenticated users to execute arbitrary commands on affected NETGEAR WiFi systems through command injection. It affects RBK...
Dec 26, 2021This vulnerability allows authenticated attackers to execute arbitrary commands on affected NETGEAR WiFi systems. It affects RBK752, RBR750, RBS750, R...
Dec 26, 2021This vulnerability allows an authenticated user to execute arbitrary commands on affected NETGEAR WiFi systems via command injection. It impacts speci...
Dec 26, 2021This vulnerability allows authenticated users on certain NETGEAR WiFi systems to execute arbitrary commands through command injection. It affects RBK7...
Dec 26, 2021This vulnerability allows authenticated users to execute arbitrary commands on affected NETGEAR WiFi systems. It affects RBK752, RBR750, RBS750, RBK85...
Dec 26, 2021This vulnerability allows authenticated users to execute arbitrary commands on affected NETGEAR WiFi systems through command injection. It affects spe...
Dec 26, 2021This vulnerability allows authenticated users to execute arbitrary commands on affected NETGEAR WiFi systems. It affects RBK752, RBR750, RBS750, RBK85...
Dec 26, 2021This vulnerability allows authenticated users to execute arbitrary commands on affected NETGEAR WiFi systems. It affects RBK752, RBR750, RBS750, RBK85...
Dec 26, 2021This vulnerability allows authenticated users on certain NETGEAR routers and WiFi systems to execute arbitrary commands through command injection. Att...
Dec 26, 2021This vulnerability allows authenticated users to execute arbitrary commands on affected NETGEAR routers and WiFi systems through command injection. At...
Dec 26, 2021This vulnerability allows authenticated users to execute arbitrary commands on affected NETGEAR routers and WiFi systems through command injection. It...
Dec 26, 2021This vulnerability allows authenticated users to execute arbitrary commands on affected NETGEAR routers, extenders, and WiFi systems. Attackers with v...
Dec 26, 2021This vulnerability allows authenticated attackers to execute arbitrary commands on affected NETGEAR routers. It affects R7900P, R7960P, and R8000P mod...
Dec 26, 2021This vulnerability allows authenticated users to execute arbitrary commands on affected NETGEAR WiFi systems. It affects RBK752, RBR750, RBS750, RBK85...
Dec 26, 2021This vulnerability allows authenticated attackers to execute arbitrary commands on affected NETGEAR WiFi systems. It affects RBK752, RBR750, RBS750, R...
Dec 26, 2021This vulnerability allows authenticated users to execute arbitrary commands on affected NETGEAR WiFi systems through command injection. It affects spe...
Dec 26, 2021This vulnerability allows authenticated users to execute arbitrary commands on affected NETGEAR devices through command injection. It affects multiple...
Dec 26, 2021This vulnerability allows authenticated users on certain NETGEAR routers and WiFi systems to execute arbitrary commands through command injection. It ...
Dec 26, 2021This vulnerability allows authenticated attackers to execute arbitrary commands on affected NETGEAR routers and WiFi systems. It affects multiple NETG...
Dec 26, 2021This vulnerability allows authenticated attackers to execute arbitrary commands on affected NETGEAR routers and WiFi systems. It affects multiple NETG...
Dec 26, 2021This vulnerability allows authenticated users to execute arbitrary commands on affected NETGEAR routers and WiFi systems through command injection. At...
Dec 26, 2021This vulnerability allows authenticated attackers to execute arbitrary commands on affected NETGEAR routers and WiFi systems. It affects specific NETG...
Aug 11, 2021This vulnerability in SIMATIC CN 4100 allows authenticated attackers to execute arbitrary code with limited privileges due to improper input validatio...
Dec 9, 2025This vulnerability allows command injection in JetBrains Toolbox App's SSH plugin, enabling attackers to execute arbitrary commands on affected system...
Apr 17, 2025CVE-2024-41637 is a privilege escalation vulnerability in RaspAP web GUI where the www-data user has write access to the restapi.service file and can ...
Jul 29, 2024This vulnerability allows pre-request scripts in Hoppscotch CLI to escape the JavaScript sandbox and execute arbitrary code on the host system. It aff...
May 8, 2024This vulnerability allows unauthenticated attackers to execute arbitrary commands on affected NETGEAR routers via command injection. It affects R7800,...
Dec 26, 2021CVE-2025-60595 allows arbitrary code execution in SPH Engineering UgCS 5.13.0 through improper neutralization of special elements used in a command. T...
Oct 29, 2025jshERP up to commit fbda24da contains an unauthenticated remote code execution vulnerability in the jsh_erp function. Attackers can execute arbitrary ...
Oct 24, 2025CVE-2025-53787 is an information disclosure vulnerability in Microsoft 365 Copilot BizChat that allows unauthorized access to sensitive business chat ...
Aug 7, 2025This CVE describes a command injection vulnerability in Linksys E8450 routers where an attacker can execute arbitrary commands via the userEmail param...
Jan 21, 2025A command injection vulnerability in the gradio-app/gradio repository's GitHub Actions workflow allows attackers to execute arbitrary commands by mani...
Mar 27, 2024CVE-2021-41116 is a command injection vulnerability in Composer, the PHP dependency manager, affecting Windows users who install untrusted packages. A...
Oct 5, 2021CVE-2026-22719 is a command injection vulnerability in VMware Aria Operations that allows unauthenticated attackers to execute arbitrary commands duri...
Feb 25, 2026About Command Injection (CWE-77)
The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.
Our database tracks 1,159 CVEs classified as CWE-77, with 447 rated critical and 490 rated high severity. The average CVSS score for Command Injection vulnerabilities is 8.3.
External reference: View CWE-77 on MITRE CWE →
Monitor Command Injection Vulnerabilities
Get alerted when new Command Injection CVEs affect your infrastructure.
Start Monitoring Free