CWE-77: Command Injection

The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.

1,166
Total CVEs
452
Critical
492
High
8.3
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
83
2025
378
2024
247
2023
225
2022
77

Top Affected Vendors

1 Totolink 107
2 Dlink 80
3 Netgear 73
4 Tenda 35
5 Arubanetworks 32
6 Linksys 28
7 Microsoft 24
8 Qnap 19
9 Siemens 18
10 Wavlink 17

All Command Injection CVEs (1,166)

CVE-2023-21778
8.0

This vulnerability allows remote attackers to execute arbitrary code on Microsoft Dynamics Unified Service Desk servers by sending specially crafted r...

Feb 14, 2023
CVE-2021-20167
8.0

This vulnerability allows remote attackers to execute arbitrary commands on Netgear RAX43 routers by injecting malicious commands into the name parame...

Dec 30, 2021
CVE-2024-33469
7.9

This vulnerability allows a local attacker to execute arbitrary code through the onCreate method in DatabaseViewerActivity.java in Amaze File Manager....

Feb 11, 2025
CVE-2025-33246
7.8

CVE-2025-33246 is a command injection vulnerability in NVIDIA's NeMo Framework ASR Evaluator utility that allows attackers to execute arbitrary comman...

Feb 18, 2026
CVE-2026-24905
7.8

CVE-2026-24905 is a command injection vulnerability in Inspektor Gadget's image building functionality. An attacker who can control the YAML gadget ma...

Jan 29, 2026
CVE-2026-0975
7.8

Delta Electronics DIAView has a command injection vulnerability (CWE-77) that allows remote attackers to execute arbitrary commands on affected system...

Jan 16, 2026
CVE-2025-55125
7.8

This vulnerability allows authenticated Backup or Tape Operators to execute arbitrary code with root privileges by creating a malicious backup configu...

Jan 8, 2026
CVE-2024-46060
7.8

This CVE describes a local privilege escalation vulnerability in Anaconda3 macOS installers. When installed outside the user's home directory, world-w...

Dec 17, 2025
CVE-2024-46062
7.8

This vulnerability allows local privilege escalation on macOS systems running vulnerable Miniconda3 installers. When installed outside the user's home...

Dec 17, 2025
CVE-2025-54100
7.8

This command injection vulnerability in Windows PowerShell allows attackers to execute arbitrary code on affected systems. It affects Windows systems ...

Dec 9, 2025
CVE-2025-58178
7.8

A command injection vulnerability in SonarQube Scan GitHub Action versions 4 to 5.3.0 allows attackers to execute arbitrary commands by injecting mali...

Sep 2, 2025
CVE-2025-54377
7.8

CVE-2025-54377 is a command injection vulnerability in Roo Code AI coding agent that allows bypassing allow-list restrictions via line break character...

Jul 23, 2025
CVE-2025-22473
7.8

This vulnerability allows a low-privileged attacker with local access to Dell SmartFabric OS10 switches to execute arbitrary code via command injectio...

Mar 17, 2025
CVE-2025-22472
7.8

This CVE describes a command injection vulnerability in Dell SmartFabric OS10 Software that allows low-privileged local attackers to execute arbitrary...

Mar 17, 2025
CVE-2024-48830
7.8

This CVE describes a command injection vulnerability in Dell SmartFabric OS10 Software that allows low-privileged local attackers to execute arbitrary...

Mar 17, 2025
CVE-2025-26331
7.8

This CVE describes a command injection vulnerability in Dell ThinOS versions 2411 and earlier. A low-privileged attacker with local access can execute...

Mar 7, 2025
CVE-2024-12251
7.8

This CVE describes a command injection vulnerability in Progress Telerik UI for WinUI where improper neutralization of hyperlink elements allows attac...

Feb 12, 2025
CVE-2024-29404
7.8

This vulnerability in Razer Synapse 3 allows a local attacker to execute arbitrary code via the export parameter in the Chroma Effects function. Attac...

Dec 3, 2024
CVE-2024-53899
7.8

CVE-2024-53899 is a command injection vulnerability in virtualenv's activation scripts where magic template strings are improperly quoted during repla...

Nov 24, 2024
CVE-2024-49557
7.8

This CVE describes a command injection vulnerability in Dell SmartFabric OS10 Software that allows a low-privileged attacker with local access to exec...

Nov 12, 2024
CVE-2024-49560
7.8

Dell SmartFabric OS10 Software contains a command injection vulnerability that allows low-privileged attackers with local access to execute arbitrary ...

Nov 12, 2024
CVE-2024-50591
7.8

This CVE describes a local privilege escalation vulnerability in Elefant Update Service where an attacker with local access can execute arbitrary comm...

Nov 8, 2024
CVE-2024-43601
7.8

This vulnerability allows remote code execution in Visual Studio Code on Linux systems. Attackers can execute arbitrary code by exploiting improper ne...

Oct 8, 2024
CVE-2024-7679
7.8

This vulnerability allows attackers to execute arbitrary commands on systems running vulnerable Progress Telerik UI for WinForms applications. Attacke...

Sep 25, 2024
CVE-2024-7575
7.8

This vulnerability allows attackers to execute arbitrary commands on systems running vulnerable versions of Progress Telerik UI for WPF. Attackers can...

Sep 25, 2024
CVE-2024-42025
7.8

This CVE describes a command injection vulnerability in self-hosted UniFi Network Application servers running Linux. An attacker with existing 'unifi'...

Sep 13, 2024
CVE-2023-40396
7.8

This vulnerability allows an app to execute arbitrary code with kernel privileges, potentially gaining full control over affected Apple devices. It af...

Jul 29, 2024
CVE-2024-39567
7.8

This vulnerability allows authenticated local attackers to execute arbitrary code with system privileges on SINEMA Remote Connect Client systems. The ...

Jul 9, 2024
CVE-2024-4944
7.8

This CVE describes a local privilege escalation vulnerability in WatchGuard Mobile VPN with SSL client on Windows. It allows a local authenticated use...

Jul 9, 2024
CVE-2024-1417
7.8

This CVE describes a command injection vulnerability in WatchGuard AuthPoint Password Manager for macOS. An attacker with local access can execute arb...

May 16, 2024
CVE-2024-28136
7.8

A local attacker with low privileges can exploit a command injection vulnerability in the OCPP Remote service to execute arbitrary commands and gain r...

May 14, 2024
CVE-2024-27818
7.8

This CVE describes a memory handling vulnerability in Apple operating systems that could allow an attacker to cause app crashes or execute arbitrary c...

May 14, 2024
CVE-2023-33806
7.8

Hikvision Interactive Tablet DS-D5B86RB/B version V2.3.0 build220119 has insecure default configurations that allow attackers to execute arbitrary com...

Apr 15, 2024
CVE-2023-52624
7.8

A race condition vulnerability in the Linux kernel's AMD display driver where the DMCUB (Display Microcontroller Unit) can be in idle state when GPINT...

Mar 26, 2024
CVE-2024-0817
7.8

This vulnerability allows remote command injection in the IrGraph.draw function of PaddlePaddle 2.6.0. Attackers can execute arbitrary commands on the...

Mar 7, 2024
CVE-2024-23749
7.8

CVE-2024-23749 is a command injection vulnerability in KiTTY that allows attackers to execute arbitrary code by manipulating filename inputs. This aff...

Feb 9, 2024
CVE-2023-50274
7.8

This vulnerability in HPE OneView allows authenticated local attackers to execute arbitrary commands with elevated privileges through improper input v...

Jan 23, 2024
CVE-2023-24135
7.8

This CVE describes a command injection vulnerability in Jensen of Scandinavia Eagle 1200AC routers running firmware version V15.03.06.33_en. Attackers...

Jan 22, 2024
CVE-2023-42136
7.8

This vulnerability allows shell injection in PAX Android-based POS devices, enabling attackers with shell access to execute arbitrary commands with sy...

Jan 15, 2024
CVE-2023-4401
7.8

Dell SmartFabric Storage Software v1.4 and earlier contains an OS command injection vulnerability in the CLI's 'more' command. Authenticated attackers...

Oct 5, 2023
CVE-2023-40796
7.8

This CVE describes a command injection vulnerability in Phicomm K2 routers that allows attackers to execute arbitrary commands via the luci.sys.call f...

Aug 25, 2023
CVE-2023-35390
7.8

CVE-2023-35390 is a remote code execution vulnerability in .NET and Visual Studio that allows attackers to execute arbitrary code on affected systems....

Aug 8, 2023
CVE-2023-33298
7.8

This vulnerability in Perimeter81's macOS agent allows local attackers to escalate privileges to root by injecting shell metacharacters into the using...

Jun 30, 2023
CVE-2023-24032
7.8

This vulnerability allows an attacker with initial user access to a Zimbra Collaboration Suite server to execute arbitrary commands as root by manipul...

Jun 15, 2023
CVE-2023-26294
7.8

CVE-2023-26294 is a command injection vulnerability in HP Device Manager that allows attackers to execute arbitrary commands on affected systems. This...

Jun 12, 2023
CVE-2022-25834
7.8

This vulnerability allows arbitrary command execution through crafted filenames in Percona XtraBackup. Attackers can execute shell commands on the sys...

Jun 7, 2023
CVE-2023-32700
7.8

This vulnerability in LuaTeX allows arbitrary shell command execution when processing untrusted TeX files. Attackers can exploit this to run malicious...

May 20, 2023
CVE-2023-24229
7.8

This vulnerability allows authenticated attackers with network access to the DrayTek Vigor2960 web management interface to execute arbitrary operating...

Mar 15, 2023
CVE-2023-1277
7.8

This critical vulnerability in kylin-system-updater allows local attackers to execute arbitrary commands through command injection in the InstallSnap ...

Mar 8, 2023
CVE-2023-0127
7.8

This CVE describes a command injection vulnerability in the firmware_update command of a device's restricted telnet interface. Authenticated attackers...

Feb 11, 2023

About Command Injection (CWE-77)

The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.

Our database tracks 1,166 CVEs classified as CWE-77, with 452 rated critical and 492 rated high severity. The average CVSS score for Command Injection vulnerabilities is 8.3.

External reference: View CWE-77 on MITRE CWE →

Monitor Command Injection Vulnerabilities

Get alerted when new Command Injection CVEs affect your infrastructure.

Start Monitoring Free