CWE-77: Command Injection

The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.

1,171
Total CVEs
454
Critical
495
High
8.3
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
83
2025
378
2024
247
2023
225
2022
77

Top Affected Vendors

1 Totolink 107
2 Dlink 80
3 Netgear 77
4 Tenda 35
5 Arubanetworks 32
6 Linksys 28
7 Microsoft 24
8 Qnap 19
9 Siemens 18
10 Wavlink 17

All Command Injection CVEs (1,171)

CVE-2022-25834
7.8

This vulnerability allows arbitrary command execution through crafted filenames in Percona XtraBackup. Attackers can execute shell commands on the sys...

Jun 7, 2023
CVE-2023-32700
7.8

This vulnerability in LuaTeX allows arbitrary shell command execution when processing untrusted TeX files. Attackers can exploit this to run malicious...

May 20, 2023
CVE-2023-24229
7.8

This vulnerability allows authenticated attackers with network access to the DrayTek Vigor2960 web management interface to execute arbitrary operating...

Mar 15, 2023
CVE-2023-1277
7.8

This critical vulnerability in kylin-system-updater allows local attackers to execute arbitrary commands through command injection in the InstallSnap ...

Mar 8, 2023
CVE-2023-0127
7.8

This CVE describes a command injection vulnerability in the firmware_update command of a device's restricted telnet interface. Authenticated attackers...

Feb 11, 2023
CVE-2021-40043
7.8

This CVE describes a laser command injection vulnerability in Huawei AIS-BW80H-00 devices that allows attackers to execute voice commands on the devic...

Feb 25, 2022
CVE-2021-31357
7.8

This CVE describes a command injection vulnerability in tcpdump command processing on Juniper Networks Junos OS Evolved. It allows authenticated users...

Oct 19, 2021
CVE-2021-0252
7.8

This vulnerability allows local attackers on Juniper NFX Series devices to execute arbitrary code with elevated privileges via the Junos Device Manage...

Apr 22, 2021
CVE-2021-29154
7.8

This vulnerability in Linux kernel BPF JIT compilers allows attackers to execute arbitrary code within kernel context due to incorrect branch displace...

Apr 8, 2021
CVE-2020-28243
7.8

CVE-2020-28243 is a command injection vulnerability in SaltStack Salt's restartcheck feature that allows local privilege escalation. Any user who can ...

Feb 27, 2021
CVE-2020-4688
7.8

This CVE describes a command injection vulnerability in IBM Security Guardium that allows a local attacker to execute arbitrary commands on the system...

Jan 20, 2021
CVE-2018-19418
7.8

CVE-2018-19418 is a command injection vulnerability in Foxit PDF ActiveX that allows remote attackers to execute arbitrary code on affected systems. T...

Jan 7, 2021
CVE-2022-40619
7.7

This vulnerability allows unauthenticated attackers on the local network to execute arbitrary commands on affected NETGEAR routers and Orbi WiFi syste...

Jan 28, 2026
CVE-2025-68432
7.7

Zed code editor versions before 0.218.2-pre have an arbitrary code execution vulnerability where malicious Language Server Protocol configurations in ...

Dec 17, 2025
CVE-2025-68433
7.7

Zed code editor versions before 0.218.2-pre have an arbitrary code execution vulnerability where malicious MCP configurations in project settings file...

Dec 17, 2025
CVE-2024-57695
7.7

A local privilege escalation vulnerability in Agnitum Outpost Security Suite allows attackers to execute arbitrary code via the lock function. This af...

Nov 11, 2025
CVE-2024-22197
7.7

This vulnerability in nginx-ui allows authenticated users to modify critical nginx configuration commands via API endpoints that should be restricted,...

Jan 11, 2024
CVE-2024-42427
7.6

Dell ThinOS versions 2402 and 2405 contain a command injection vulnerability that allows unauthenticated attackers with physical access to execute arb...

Sep 10, 2024
CVE-2015-20107
7.6

This vulnerability in Python's mailcap module allows shell command injection when applications call mailcap.findmatch() with untrusted input. Attacker...

Apr 13, 2022
CVE-2021-45595
7.6

This vulnerability allows authenticated users to execute arbitrary commands on affected NETGEAR WiFi systems through command injection. It affects mul...

Dec 26, 2021
CVE-2021-45551
7.6

This vulnerability allows authenticated users on affected NETGEAR routers to execute arbitrary commands through command injection. Attackers with vali...

Dec 26, 2021
CVE-2026-21520
7.5

CVE-2026-21520 is an information disclosure vulnerability in Microsoft Copilot Studio that allows unauthenticated attackers to access sensitive inform...

Jan 22, 2026
CVE-2025-69256
7.5

A command injection vulnerability in Serverless Framework's experimental MCP server feature allows attackers to execute arbitrary system commands via ...

Dec 30, 2025
CVE-2024-56836
7.5

This vulnerability in Siemens RUGGEDCOM ROX devices allows attackers to inject additional configuration parameters during Dynamic DNS setup. Under cer...

Dec 9, 2025
CVE-2025-61141
7.5

CVE-2025-61141 allows remote command injection in sqls-server/sqls version 0.2.28 through the config command. Attackers can execute arbitrary commands...

Oct 30, 2025
CVE-2025-56406
7.5

CVE-2025-56406 is an improper neutralization vulnerability in mcp-neo4j 0.3.0 that allows attackers to execute arbitrary commands or access sensitive ...

Sep 10, 2025
CVE-2025-48978
7.5

This vulnerability allows attackers with network access adjacent to an EdgeSwitch to execute arbitrary commands on the device through improper input v...

Aug 21, 2025
CVE-2025-54073
7.5

A command injection vulnerability in mcp-package-docs MCP Server allows attackers to execute arbitrary system commands via unsanitized user input in c...

Jul 18, 2025
CVE-2025-53372
7.5

CVE-2025-53372 is a command injection vulnerability in node-code-sandbox-mcp that allows attackers to execute arbitrary system commands on the host ma...

Jul 8, 2025
CVE-2025-53107
7.5

CVE-2025-53107 is a command injection vulnerability in @cyanheads/git-mcp-server that allows remote code execution by injecting shell commands through...

Jul 1, 2025
CVE-2025-23119
7.5

This CVE describes an Improper Neutralization of Escape Sequences vulnerability in UniFi Protect Cameras that could allow an attacker on the same netw...

Mar 1, 2025
CVE-2025-24861
7.5

This vulnerability allows remote attackers to execute arbitrary commands on affected systems by sending specially crafted POST requests. It affects Ou...

Feb 13, 2025
CVE-2024-9579
7.5

A command injection vulnerability exists in certain Poly video conferencing devices due to improper input sanitization. This flaw could allow authenti...

Nov 5, 2024
CVE-2024-48139
7.5

A prompt injection vulnerability in Blackbox AI v1.3.95 allows attackers to access and exfiltrate all previous and subsequent chat data between users ...

Oct 24, 2024
CVE-2024-48141
7.5

A prompt injection vulnerability in Zhipu AI CodeGeeX allows attackers to access and exfiltrate all chat data between users and the AI assistant throu...

Oct 24, 2024
CVE-2024-38486
7.5

This vulnerability allows a low-privileged attacker with remote access to execute arbitrary commands on Dell SmartFabric OS10 networking devices throu...

Sep 6, 2024
CVE-2024-33342
7.5

This vulnerability allows remote attackers to execute arbitrary commands on D-Link DIR-822+ routers via command injection in the SetPlcNetworkpwd func...

Apr 26, 2024
CVE-2022-35503
7.5

CVE-2022-35503 is an improper input validation vulnerability in Open Source MANO (OSM) that allows authenticated attackers to execute arbitrary code w...

Apr 22, 2024
CVE-2024-20667
7.5

CVE-2024-20667 is a remote code execution vulnerability in Azure DevOps Server that allows attackers to execute arbitrary code on affected systems. Th...

Feb 13, 2024
CVE-2020-22570
7.5

This vulnerability in Memcached allows remote attackers to crash the daemon by sending specially crafted meta commands. It affects Memcached servers r...

Aug 22, 2023
CVE-2023-38286
7.5

This CVE describes a sandbox bypass vulnerability in Thymeleaf templates that allows Server-Side Template Injection (SSTI) and potential remote code e...

Jul 14, 2023
CVE-2023-20889
7.5

This vulnerability in VMware Aria Operations for Networks allows attackers with network access to execute arbitrary commands through command injection...

Jun 7, 2023
CVE-2023-31476
7.5

This vulnerability allows attackers to create empty files in arbitrary locations on GL.iNet device filesystems, limited to paths/filenames of 6 charac...

May 9, 2023
CVE-2023-27079
7.5

This CVE describes a command injection vulnerability in Tenda G103 routers that allows attackers to execute arbitrary commands on the device. Attacker...

Mar 23, 2023
CVE-2021-43663
7.5

This CVE describes a command injection vulnerability in TOTOLINK EX300_v2 routers that allows attackers to execute arbitrary commands on affected devi...

Mar 31, 2022
CVE-2021-23727
7.5

CVE-2021-23727 is a command injection vulnerability in Celery task queue software. Attackers who can access or manipulate metadata in Celery backends ...

Dec 29, 2021
CVE-2021-45557
7.5

This vulnerability allows authenticated users to execute arbitrary commands on affected NETGEAR switches through command injection. It affects multipl...

Dec 26, 2021
CVE-2021-43557
7.5

CVE-2021-43557 is a URI normalization bypass vulnerability in Apache APISIX's uri-block plugin that allows attackers to bypass block lists by using sp...

Nov 22, 2021
CVE-2025-70093
7.4

This vulnerability in OpenSourcePOS v3.4.1 allows attackers to execute arbitrary code on the server by sending a specially crafted AJAX response. This...

Feb 13, 2026
CVE-2023-47563
7.4

This CVE describes an OS command injection vulnerability in QNAP Video Station that allows authenticated users to execute arbitrary commands on the sy...

Sep 6, 2024

About Command Injection (CWE-77)

The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.

Our database tracks 1,171 CVEs classified as CWE-77, with 454 rated critical and 495 rated high severity. The average CVSS score for Command Injection vulnerabilities is 8.3.

External reference: View CWE-77 on MITRE CWE →

Monitor Command Injection Vulnerabilities

Get alerted when new Command Injection CVEs affect your infrastructure.

Start Monitoring Free