CWE-77: Command Injection

The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.

1,160
Total CVEs
447
Critical
491
High
8.3
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
83
2025
378
2024
247
2023
225
2022
77

Top Affected Vendors

1 Totolink 107
2 Dlink 80
3 Netgear 73
4 Tenda 35
5 Arubanetworks 32
6 Linksys 28
7 Microsoft 24
8 Qnap 19
9 Siemens 18
10 Wavlink 17

All Command Injection CVEs (1,160)

CVE-2026-20761
8.1

This vulnerability allows remote attackers to execute arbitrary operating system commands on EnOcean SmartServer IoT devices by sending specially craf...

Feb 20, 2026
CVE-2026-22864
8.1

This vulnerability allows attackers to bypass Deno's security restrictions on Windows by using case variations in file extensions (.BAT, .Bat instead ...

Jan 15, 2026
CVE-2025-67089
8.1

A command injection vulnerability in GL-iNet GL-AXT1800 router firmware allows authenticated attackers to execute arbitrary commands with root privile...

Jan 8, 2026
CVE-2025-61787
8.1

This CVE describes a command injection vulnerability in Deno on Windows systems. When Deno executes batch files (.bat, .cmd) on Windows, the underlyin...

Oct 8, 2025
CVE-2025-54424
8.1

CVE-2025-54424 is a certificate validation bypass vulnerability in 1Panel web interface that allows attackers to intercept HTTPS communications betwee...

Aug 1, 2025
CVE-2025-52690
8.1

This CVE describes a command injection vulnerability (CWE-77) in OmniAccess Stellar access points that allows authenticated attackers to execute arbit...

Jul 16, 2025
CVE-2025-7097
8.1

This critical vulnerability in Comodo Internet Security Premium allows remote attackers to execute arbitrary operating system commands through command...

Jul 6, 2025
CVE-2025-53098
8.1

CVE-2025-53098 is a vulnerability in Roo Code AI coding agent that allows arbitrary command execution through malicious MCP configuration files. Attac...

Jun 27, 2025
CVE-2025-0798
8.1

This critical vulnerability in MicroWorld eScan Antivirus allows remote attackers to execute arbitrary operating system commands through command injec...

Jan 29, 2025
CVE-2024-57036
8.1

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK A810R routers by sending specially crafted HTTP requests to the d...

Jan 21, 2025
CVE-2024-27980
8.1

This vulnerability in Node.js allows command injection through malicious batch file arguments in child_process.spawn/spawnSync functions, even when sh...

Jan 9, 2025
CVE-2024-24550
8.1

This vulnerability in Bludit allows attackers with API token access to upload arbitrary files, including PHP files, leading to remote code execution o...

Jun 24, 2024
CVE-2023-6634
8.1

The LearnPress WordPress plugin contains a command injection vulnerability that allows unauthenticated attackers to execute arbitrary PHP functions wi...

Jan 11, 2024
CVE-2023-6572
8.1

This CVE describes a command injection vulnerability in the Gradio library that allows attackers to execute arbitrary commands on the host system. It ...

Dec 14, 2023
CVE-2023-22371
8.1

This CVE describes an OS command injection vulnerability in Milesight VPN's liburvpn.so library that allows remote attackers to execute arbitrary comm...

Jul 6, 2023
CVE-2023-22913
8.1

A post-authentication command injection vulnerability in Zyxel USG FLEX and VPN series firewalls allows authenticated attackers to execute arbitrary c...

Apr 24, 2023
CVE-2021-43664
8.1

This CVE describes a command injection vulnerability in TOTOLINK EX300_v2 routers that allows attackers to execute arbitrary commands on the device. T...

Mar 30, 2022
CVE-2021-42638
8.1

CVE-2021-42638 is a critical vulnerability in PrinterLogic Web Stack that allows unauthenticated attackers to execute arbitrary code remotely due to i...

Feb 1, 2022
CVE-2021-35220
8.1

CVE-2021-35220 is a command injection vulnerability in SolarWinds Orion Platform's EmailWebPage API that allows attackers to execute arbitrary command...

Aug 31, 2021
CVE-2020-29548
8.1

This vulnerability allows man-in-the-middle attackers to inject plaintext commands into encrypted POP3 sessions in SmarterMail. Attackers can pipeline...

Aug 17, 2021
CVE-2021-38527
8.1

This vulnerability allows unauthenticated attackers to execute arbitrary commands on affected NETGEAR devices via command injection. It affects multip...

Aug 11, 2021
CVE-2020-36462
8.1

This vulnerability in the syncpool Rust crate allows data races and memory corruption due to an unconditional Send implementation for Bucket2. It affe...

Aug 8, 2021
CVE-2020-36449
8.1

This vulnerability in the kekbit Rust crate allows data races and memory corruption when ShmWriter objects are sent between threads without proper syn...

Aug 8, 2021
CVE-2020-36451
8.1

This vulnerability in the rcu_cell Rust crate allows data races and memory corruption by incorrectly implementing Send and Sync traits for RcuCell<T> ...

Aug 8, 2021
CVE-2020-36456
8.1

This vulnerability in the Rust toolshed crate allows Send trait misuse in CopyCell<T>, potentially enabling data races and memory corruption in concur...

Aug 8, 2021
CVE-2025-67508
8.0

This vulnerability allows attackers with administrative privileges in Gardener projects to inject malicious credential values that break out of string...

Dec 12, 2025
CVE-2025-56706
8.0

The Edimax BR-6473AX router firmware version 1.0.28 contains a remote code execution vulnerability in the openwrt_getConfig function. Attackers can ex...

Sep 16, 2025
CVE-2025-52995
8.0

CVE-2025-52995 is an improper command allowlist vulnerability in File Browser that allows authenticated users to execute unauthorized shell commands. ...

Jun 30, 2025
CVE-2025-52903
8.0

CVE-2025-52903 is a command injection vulnerability in File Browser version 2.32.0 that allows authenticated users with 'Execute commands' permission ...

Jun 26, 2025
CVE-2024-57536
8.0

This CVE describes a command injection vulnerability in the Linksys E8450 router's wizard_status component, allowing attackers to execute arbitrary co...

Jan 21, 2025
CVE-2024-57227
8.0

This CVE describes a command injection vulnerability in Linksys E7350 routers where an attacker can execute arbitrary commands via the ifname paramete...

Jan 10, 2025
CVE-2024-57228
8.0

This CVE describes a command injection vulnerability in Linksys E7350 routers where an attacker can execute arbitrary commands via the iface parameter...

Jan 10, 2025
CVE-2024-57211
8.0

This CVE describes a command injection vulnerability in TOTOLINK A6000R routers that allows attackers to execute arbitrary commands on the device. Att...

Jan 10, 2025
CVE-2024-48286
8.0

CVE-2024-48286 is a command injection vulnerability in Linksys E3000 routers that allows attackers to execute arbitrary commands on the device. This a...

Nov 21, 2024
CVE-2024-52308
8.0

This vulnerability allows remote code execution on a developer's workstation when using GitHub CLI to connect to malicious codespaces. Attackers can i...

Nov 14, 2024
CVE-2024-28726
8.0

This vulnerability allows a local attacker to execute arbitrary code on affected D-Link 5G CPE devices via the Diagnostics function. Attackers with lo...

Nov 12, 2024
CVE-2024-52022
8.0

This CVE describes a command injection vulnerability in specific Netgear router models via the wlg_adv.cgi component's apmode_gateway parameter. Attac...

Nov 5, 2024
CVE-2024-46084
8.0

Scriptcase versions 9.10.023 and earlier contain a vulnerability in the nm_unzip function that allows remote attackers to execute arbitrary code on af...

Oct 1, 2024
CVE-2024-43027
8.0

This CVE describes a command injection vulnerability in DrayTek router firmware that allows attackers to execute arbitrary commands on affected device...

Aug 21, 2024
CVE-2024-36983
8.0

This vulnerability allows authenticated users in Splunk Enterprise and Cloud Platform to create external lookups that call legacy internal functions, ...

Jul 1, 2024
CVE-2024-32355
8.0

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK X5000R routers by injecting malicious commands into the 'password...

May 14, 2024
CVE-2024-22544
8.0

This vulnerability allows authenticated attackers to execute arbitrary code on Linksys Router E1700 devices via the setDateTime function. Attackers wi...

Feb 27, 2024
CVE-2024-20676
8.0

This vulnerability allows remote code execution on Azure Storage Mover instances through improper neutralization of special elements used in a command...

Jan 9, 2024
CVE-2023-37566
8.0

This CVE describes a command injection vulnerability in ELECOM and LOGITEC wireless LAN routers that allows authenticated attackers on the same networ...

Jul 13, 2023
CVE-2023-28854
8.0

CVE-2023-28854 is a command injection vulnerability in the nophp PHP framework that allows attackers to execute arbitrary shell commands on the web se...

Apr 3, 2023
CVE-2023-21778
8.0

This vulnerability allows remote attackers to execute arbitrary code on Microsoft Dynamics Unified Service Desk servers by sending specially crafted r...

Feb 14, 2023
CVE-2021-20167
8.0

This vulnerability allows remote attackers to execute arbitrary commands on Netgear RAX43 routers by injecting malicious commands into the name parame...

Dec 30, 2021
CVE-2024-33469
7.9

This vulnerability allows a local attacker to execute arbitrary code through the onCreate method in DatabaseViewerActivity.java in Amaze File Manager....

Feb 11, 2025
CVE-2025-33246
7.8

CVE-2025-33246 is a command injection vulnerability in NVIDIA's NeMo Framework ASR Evaluator utility that allows attackers to execute arbitrary comman...

Feb 18, 2026
CVE-2026-24905
7.8

CVE-2026-24905 is a command injection vulnerability in Inspektor Gadget's image building functionality. An attacker who can control the YAML gadget ma...

Jan 29, 2026

About Command Injection (CWE-77)

The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.

Our database tracks 1,160 CVEs classified as CWE-77, with 447 rated critical and 491 rated high severity. The average CVSS score for Command Injection vulnerabilities is 8.3.

External reference: View CWE-77 on MITRE CWE →

Monitor Command Injection Vulnerabilities

Get alerted when new Command Injection CVEs affect your infrastructure.

Start Monitoring Free