CWE-77: Command Injection
The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.
Yearly Trend
Top Affected Vendors
All Command Injection CVEs (1,160)
This vulnerability allows remote attackers to execute arbitrary operating system commands on EnOcean SmartServer IoT devices by sending specially craf...
Feb 20, 2026This vulnerability allows attackers to bypass Deno's security restrictions on Windows by using case variations in file extensions (.BAT, .Bat instead ...
Jan 15, 2026A command injection vulnerability in GL-iNet GL-AXT1800 router firmware allows authenticated attackers to execute arbitrary commands with root privile...
Jan 8, 2026This CVE describes a command injection vulnerability in Deno on Windows systems. When Deno executes batch files (.bat, .cmd) on Windows, the underlyin...
Oct 8, 2025CVE-2025-54424 is a certificate validation bypass vulnerability in 1Panel web interface that allows attackers to intercept HTTPS communications betwee...
Aug 1, 2025This CVE describes a command injection vulnerability (CWE-77) in OmniAccess Stellar access points that allows authenticated attackers to execute arbit...
Jul 16, 2025This critical vulnerability in Comodo Internet Security Premium allows remote attackers to execute arbitrary operating system commands through command...
Jul 6, 2025CVE-2025-53098 is a vulnerability in Roo Code AI coding agent that allows arbitrary command execution through malicious MCP configuration files. Attac...
Jun 27, 2025This critical vulnerability in MicroWorld eScan Antivirus allows remote attackers to execute arbitrary operating system commands through command injec...
Jan 29, 2025This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK A810R routers by sending specially crafted HTTP requests to the d...
Jan 21, 2025This vulnerability in Node.js allows command injection through malicious batch file arguments in child_process.spawn/spawnSync functions, even when sh...
Jan 9, 2025This vulnerability in Bludit allows attackers with API token access to upload arbitrary files, including PHP files, leading to remote code execution o...
Jun 24, 2024The LearnPress WordPress plugin contains a command injection vulnerability that allows unauthenticated attackers to execute arbitrary PHP functions wi...
Jan 11, 2024This CVE describes a command injection vulnerability in the Gradio library that allows attackers to execute arbitrary commands on the host system. It ...
Dec 14, 2023This CVE describes an OS command injection vulnerability in Milesight VPN's liburvpn.so library that allows remote attackers to execute arbitrary comm...
Jul 6, 2023A post-authentication command injection vulnerability in Zyxel USG FLEX and VPN series firewalls allows authenticated attackers to execute arbitrary c...
Apr 24, 2023This CVE describes a command injection vulnerability in TOTOLINK EX300_v2 routers that allows attackers to execute arbitrary commands on the device. T...
Mar 30, 2022CVE-2021-42638 is a critical vulnerability in PrinterLogic Web Stack that allows unauthenticated attackers to execute arbitrary code remotely due to i...
Feb 1, 2022CVE-2021-35220 is a command injection vulnerability in SolarWinds Orion Platform's EmailWebPage API that allows attackers to execute arbitrary command...
Aug 31, 2021This vulnerability allows man-in-the-middle attackers to inject plaintext commands into encrypted POP3 sessions in SmarterMail. Attackers can pipeline...
Aug 17, 2021This vulnerability allows unauthenticated attackers to execute arbitrary commands on affected NETGEAR devices via command injection. It affects multip...
Aug 11, 2021This vulnerability in the syncpool Rust crate allows data races and memory corruption due to an unconditional Send implementation for Bucket2. It affe...
Aug 8, 2021This vulnerability in the kekbit Rust crate allows data races and memory corruption when ShmWriter objects are sent between threads without proper syn...
Aug 8, 2021This vulnerability in the rcu_cell Rust crate allows data races and memory corruption by incorrectly implementing Send and Sync traits for RcuCell<T> ...
Aug 8, 2021This vulnerability in the Rust toolshed crate allows Send trait misuse in CopyCell<T>, potentially enabling data races and memory corruption in concur...
Aug 8, 2021This vulnerability allows attackers with administrative privileges in Gardener projects to inject malicious credential values that break out of string...
Dec 12, 2025The Edimax BR-6473AX router firmware version 1.0.28 contains a remote code execution vulnerability in the openwrt_getConfig function. Attackers can ex...
Sep 16, 2025CVE-2025-52995 is an improper command allowlist vulnerability in File Browser that allows authenticated users to execute unauthorized shell commands. ...
Jun 30, 2025CVE-2025-52903 is a command injection vulnerability in File Browser version 2.32.0 that allows authenticated users with 'Execute commands' permission ...
Jun 26, 2025This CVE describes a command injection vulnerability in the Linksys E8450 router's wizard_status component, allowing attackers to execute arbitrary co...
Jan 21, 2025This CVE describes a command injection vulnerability in Linksys E7350 routers where an attacker can execute arbitrary commands via the ifname paramete...
Jan 10, 2025This CVE describes a command injection vulnerability in Linksys E7350 routers where an attacker can execute arbitrary commands via the iface parameter...
Jan 10, 2025This CVE describes a command injection vulnerability in TOTOLINK A6000R routers that allows attackers to execute arbitrary commands on the device. Att...
Jan 10, 2025CVE-2024-48286 is a command injection vulnerability in Linksys E3000 routers that allows attackers to execute arbitrary commands on the device. This a...
Nov 21, 2024This vulnerability allows remote code execution on a developer's workstation when using GitHub CLI to connect to malicious codespaces. Attackers can i...
Nov 14, 2024This vulnerability allows a local attacker to execute arbitrary code on affected D-Link 5G CPE devices via the Diagnostics function. Attackers with lo...
Nov 12, 2024This CVE describes a command injection vulnerability in specific Netgear router models via the wlg_adv.cgi component's apmode_gateway parameter. Attac...
Nov 5, 2024Scriptcase versions 9.10.023 and earlier contain a vulnerability in the nm_unzip function that allows remote attackers to execute arbitrary code on af...
Oct 1, 2024This CVE describes a command injection vulnerability in DrayTek router firmware that allows attackers to execute arbitrary commands on affected device...
Aug 21, 2024This vulnerability allows authenticated users in Splunk Enterprise and Cloud Platform to create external lookups that call legacy internal functions, ...
Jul 1, 2024This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK X5000R routers by injecting malicious commands into the 'password...
May 14, 2024This vulnerability allows authenticated attackers to execute arbitrary code on Linksys Router E1700 devices via the setDateTime function. Attackers wi...
Feb 27, 2024This vulnerability allows remote code execution on Azure Storage Mover instances through improper neutralization of special elements used in a command...
Jan 9, 2024This CVE describes a command injection vulnerability in ELECOM and LOGITEC wireless LAN routers that allows authenticated attackers on the same networ...
Jul 13, 2023CVE-2023-28854 is a command injection vulnerability in the nophp PHP framework that allows attackers to execute arbitrary shell commands on the web se...
Apr 3, 2023This vulnerability allows remote attackers to execute arbitrary code on Microsoft Dynamics Unified Service Desk servers by sending specially crafted r...
Feb 14, 2023This vulnerability allows remote attackers to execute arbitrary commands on Netgear RAX43 routers by injecting malicious commands into the name parame...
Dec 30, 2021This vulnerability allows a local attacker to execute arbitrary code through the onCreate method in DatabaseViewerActivity.java in Amaze File Manager....
Feb 11, 2025CVE-2025-33246 is a command injection vulnerability in NVIDIA's NeMo Framework ASR Evaluator utility that allows attackers to execute arbitrary comman...
Feb 18, 2026CVE-2026-24905 is a command injection vulnerability in Inspektor Gadget's image building functionality. An attacker who can control the YAML gadget ma...
Jan 29, 2026About Command Injection (CWE-77)
The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.
Our database tracks 1,160 CVEs classified as CWE-77, with 447 rated critical and 491 rated high severity. The average CVSS score for Command Injection vulnerabilities is 8.3.
External reference: View CWE-77 on MITRE CWE →
Monitor Command Injection Vulnerabilities
Get alerted when new Command Injection CVEs affect your infrastructure.
Start Monitoring Free