CWE-77: Command Injection

The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.

1,159
Total CVEs
447
Critical
490
High
8.3
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
82
2025
378
2024
247
2023
225
2022
77

Top Affected Vendors

1 Totolink 107
2 Dlink 80
3 Netgear 73
4 Tenda 35
5 Arubanetworks 32
6 Linksys 28
7 Microsoft 24
8 Qnap 19
9 Siemens 18
10 Wavlink 17

All Command Injection CVEs (1,159)

CVE-2023-37154
8.4

CVE-2023-37154 is a command injection vulnerability in Nagios check_by_ssh plugin that allows attackers to execute arbitrary commands on the monitorin...

Oct 9, 2024
CVE-2024-43497
8.4

CVE-2024-43497 is a remote code execution vulnerability in DeepSpeed, Microsoft's deep learning optimization library. It allows attackers to execute a...

Oct 8, 2024
CVE-2024-4578
8.4

This vulnerability allows authenticated SSH users with the 'config' account on affected Arista Wireless Access Points to escalate privileges to root b...

Jun 27, 2024
CVE-2024-6257
8.4

CVE-2024-6257 is a vulnerability in HashiCorp's go-getter library where an attacker can manipulate Git configuration files to execute arbitrary code d...

Jun 25, 2024
CVE-2023-41334
8.4

This vulnerability in Astropy allows remote code execution through improper input validation in the TransformGraph().to_dot_graph function. An attacke...

Mar 18, 2024
CVE-2023-25643
8.4

CVE-2023-25643 is a command injection vulnerability in certain ZTE mobile internet products that allows authenticated attackers to execute arbitrary c...

Dec 14, 2023
CVE-2023-6071
8.4

This vulnerability allows remote administrators to execute arbitrary code with root privileges on ESM systems by exploiting improper input sanitizatio...

Nov 30, 2023
CVE-2021-45585
8.4

This vulnerability allows authenticated attackers to execute arbitrary commands on affected NETGEAR WiFi systems. It affects RBK752, RBR750, RBS750, R...

Dec 26, 2021
CVE-2021-45587
8.4

This vulnerability allows authenticated users to execute arbitrary commands on affected NETGEAR WiFi systems through command injection. It affects spe...

Dec 26, 2021
CVE-2021-45589
8.4

This vulnerability allows authenticated users to execute arbitrary commands on affected NETGEAR WiFi systems. It affects RBK752, RBR750, RBS750, RBK85...

Dec 26, 2021
CVE-2021-45591
8.4

This vulnerability allows authenticated attackers to execute arbitrary commands on affected NETGEAR WiFi systems. It affects RBK752, RBR750, RBS750, R...

Dec 26, 2021
CVE-2021-45593
8.4

This vulnerability allows authenticated users to execute arbitrary commands on affected NETGEAR WiFi systems through command injection. It affects mul...

Dec 26, 2021
CVE-2021-45597
8.4

This vulnerability allows authenticated users to execute arbitrary commands on affected NETGEAR WiFi systems. It affects specific NETGEAR CBR40, CBR75...

Dec 26, 2021
CVE-2021-45599
8.4

This vulnerability allows authenticated users to execute arbitrary commands on affected NETGEAR WiFi systems. It affects specific NETGEAR CBR40, CBR75...

Dec 26, 2021
CVE-2021-45601
8.4

This vulnerability allows authenticated users on certain NETGEAR WiFi systems to execute arbitrary commands through command injection. It affects spec...

Dec 26, 2021
CVE-2021-45565
8.4

This vulnerability allows authenticated users to execute arbitrary commands on affected NETGEAR WiFi systems. It affects RBK752, RBR750, RBS750, RBK85...

Dec 26, 2021
CVE-2021-45567
8.4

This vulnerability allows authenticated users to execute arbitrary commands on affected NETGEAR WiFi systems through command injection. It affects RBK...

Dec 26, 2021
CVE-2021-45569
8.4

This vulnerability allows authenticated attackers to execute arbitrary commands on affected NETGEAR WiFi systems. It affects RBK752, RBR750, RBS750, R...

Dec 26, 2021
CVE-2021-45571
8.4

This vulnerability allows an authenticated user to execute arbitrary commands on affected NETGEAR WiFi systems via command injection. It impacts speci...

Dec 26, 2021
CVE-2021-45575
8.4

This vulnerability allows authenticated users on certain NETGEAR WiFi systems to execute arbitrary commands through command injection. It affects RBK7...

Dec 26, 2021
CVE-2021-45577
8.4

This vulnerability allows authenticated users to execute arbitrary commands on affected NETGEAR WiFi systems. It affects RBK752, RBR750, RBS750, RBK85...

Dec 26, 2021
CVE-2021-45579
8.4

This vulnerability allows authenticated users to execute arbitrary commands on affected NETGEAR WiFi systems through command injection. It affects spe...

Dec 26, 2021
CVE-2021-45581
8.4

This vulnerability allows authenticated users to execute arbitrary commands on affected NETGEAR WiFi systems. It affects RBK752, RBR750, RBS750, RBK85...

Dec 26, 2021
CVE-2021-45583
8.4

This vulnerability allows authenticated users to execute arbitrary commands on affected NETGEAR WiFi systems. It affects RBK752, RBR750, RBS750, RBK85...

Dec 26, 2021
CVE-2021-45543
8.4

This vulnerability allows authenticated users on certain NETGEAR routers and WiFi systems to execute arbitrary commands through command injection. Att...

Dec 26, 2021
CVE-2021-45545
8.4

This vulnerability allows authenticated users to execute arbitrary commands on affected NETGEAR routers and WiFi systems through command injection. At...

Dec 26, 2021
CVE-2021-45547
8.4

This vulnerability allows authenticated users to execute arbitrary commands on affected NETGEAR routers and WiFi systems through command injection. It...

Dec 26, 2021
CVE-2021-45549
8.4

This vulnerability allows authenticated users to execute arbitrary commands on affected NETGEAR routers, extenders, and WiFi systems. Attackers with v...

Dec 26, 2021
CVE-2021-45555
8.4

This vulnerability allows authenticated attackers to execute arbitrary commands on affected NETGEAR routers. It affects R7900P, R7960P, and R8000P mod...

Dec 26, 2021
CVE-2021-45559
8.4

This vulnerability allows authenticated users to execute arbitrary commands on affected NETGEAR WiFi systems. It affects RBK752, RBR750, RBS750, RBK85...

Dec 26, 2021
CVE-2021-45561
8.4

This vulnerability allows authenticated attackers to execute arbitrary commands on affected NETGEAR WiFi systems. It affects RBK752, RBR750, RBS750, R...

Dec 26, 2021
CVE-2021-45563
8.4

This vulnerability allows authenticated users to execute arbitrary commands on affected NETGEAR WiFi systems through command injection. It affects spe...

Dec 26, 2021
CVE-2021-45533
8.4

This vulnerability allows authenticated users to execute arbitrary commands on affected NETGEAR devices through command injection. It affects multiple...

Dec 26, 2021
CVE-2021-45535
8.4

This vulnerability allows authenticated users on certain NETGEAR routers and WiFi systems to execute arbitrary commands through command injection. It ...

Dec 26, 2021
CVE-2021-45537
8.4

This vulnerability allows authenticated attackers to execute arbitrary commands on affected NETGEAR routers and WiFi systems. It affects multiple NETG...

Dec 26, 2021
CVE-2021-45539
8.4

This vulnerability allows authenticated attackers to execute arbitrary commands on affected NETGEAR routers and WiFi systems. It affects multiple NETG...

Dec 26, 2021
CVE-2021-45541
8.4

This vulnerability allows authenticated users to execute arbitrary commands on affected NETGEAR routers and WiFi systems through command injection. At...

Dec 26, 2021
CVE-2021-38518
8.4

This vulnerability allows authenticated attackers to execute arbitrary commands on affected NETGEAR routers and WiFi systems. It affects specific NETG...

Aug 11, 2021
CVE-2025-40937
8.3

This vulnerability in SIMATIC CN 4100 allows authenticated attackers to execute arbitrary code with limited privileges due to improper input validatio...

Dec 9, 2025
CVE-2025-43012
8.3

This vulnerability allows command injection in JetBrains Toolbox App's SSH plugin, enabling attackers to execute arbitrary commands on affected system...

Apr 17, 2025
CVE-2024-41637
8.3

CVE-2024-41637 is a privilege escalation vulnerability in RaspAP web GUI where the www-data user has write access to the restapi.service file and can ...

Jul 29, 2024
CVE-2024-34347
8.3

This vulnerability allows pre-request scripts in Hoppscotch CLI to escape the JavaScript sandbox and execute arbitrary code on the host system. It aff...

May 8, 2024
CVE-2021-45623
8.3

This vulnerability allows unauthenticated attackers to execute arbitrary commands on affected NETGEAR routers via command injection. It affects R7800,...

Dec 26, 2021
CVE-2025-60595
8.2

CVE-2025-60595 allows arbitrary code execution in SPH Engineering UgCS 5.13.0 through improper neutralization of special elements used in a command. T...

Oct 29, 2025
CVE-2025-60801
8.2

jshERP up to commit fbda24da contains an unauthenticated remote code execution vulnerability in the jsh_erp function. Attackers can execute arbitrary ...

Oct 24, 2025
CVE-2025-53787
8.2

CVE-2025-53787 is an information disclosure vulnerability in Microsoft 365 Copilot BizChat that allows unauthorized access to sensitive business chat ...

Aug 7, 2025
CVE-2024-57539
8.2

This CVE describes a command injection vulnerability in Linksys E8450 routers where an attacker can execute arbitrary commands via the userEmail param...

Jan 21, 2025
CVE-2024-1540
8.2

A command injection vulnerability in the gradio-app/gradio repository's GitHub Actions workflow allows attackers to execute arbitrary commands by mani...

Mar 27, 2024
CVE-2021-41116
8.2

CVE-2021-41116 is a command injection vulnerability in Composer, the PHP dependency manager, affecting Windows users who install untrusted packages. A...

Oct 5, 2021
CVE-2026-22719
8.1

CVE-2026-22719 is a command injection vulnerability in VMware Aria Operations that allows unauthenticated attackers to execute arbitrary commands duri...

Feb 25, 2026

About Command Injection (CWE-77)

The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.

Our database tracks 1,159 CVEs classified as CWE-77, with 447 rated critical and 490 rated high severity. The average CVSS score for Command Injection vulnerabilities is 8.3.

External reference: View CWE-77 on MITRE CWE →

Monitor Command Injection Vulnerabilities

Get alerted when new Command Injection CVEs affect your infrastructure.

Start Monitoring Free