CWE-77: Command Injection
The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.
Yearly Trend
Top Affected Vendors
All Command Injection CVEs (1,171)
This vulnerability allows arbitrary command execution through crafted filenames in Percona XtraBackup. Attackers can execute shell commands on the sys...
Jun 7, 2023This vulnerability in LuaTeX allows arbitrary shell command execution when processing untrusted TeX files. Attackers can exploit this to run malicious...
May 20, 2023This vulnerability allows authenticated attackers with network access to the DrayTek Vigor2960 web management interface to execute arbitrary operating...
Mar 15, 2023This critical vulnerability in kylin-system-updater allows local attackers to execute arbitrary commands through command injection in the InstallSnap ...
Mar 8, 2023This CVE describes a command injection vulnerability in the firmware_update command of a device's restricted telnet interface. Authenticated attackers...
Feb 11, 2023This CVE describes a laser command injection vulnerability in Huawei AIS-BW80H-00 devices that allows attackers to execute voice commands on the devic...
Feb 25, 2022This CVE describes a command injection vulnerability in tcpdump command processing on Juniper Networks Junos OS Evolved. It allows authenticated users...
Oct 19, 2021This vulnerability allows local attackers on Juniper NFX Series devices to execute arbitrary code with elevated privileges via the Junos Device Manage...
Apr 22, 2021This vulnerability in Linux kernel BPF JIT compilers allows attackers to execute arbitrary code within kernel context due to incorrect branch displace...
Apr 8, 2021CVE-2020-28243 is a command injection vulnerability in SaltStack Salt's restartcheck feature that allows local privilege escalation. Any user who can ...
Feb 27, 2021This CVE describes a command injection vulnerability in IBM Security Guardium that allows a local attacker to execute arbitrary commands on the system...
Jan 20, 2021CVE-2018-19418 is a command injection vulnerability in Foxit PDF ActiveX that allows remote attackers to execute arbitrary code on affected systems. T...
Jan 7, 2021This vulnerability allows unauthenticated attackers on the local network to execute arbitrary commands on affected NETGEAR routers and Orbi WiFi syste...
Jan 28, 2026Zed code editor versions before 0.218.2-pre have an arbitrary code execution vulnerability where malicious Language Server Protocol configurations in ...
Dec 17, 2025Zed code editor versions before 0.218.2-pre have an arbitrary code execution vulnerability where malicious MCP configurations in project settings file...
Dec 17, 2025A local privilege escalation vulnerability in Agnitum Outpost Security Suite allows attackers to execute arbitrary code via the lock function. This af...
Nov 11, 2025This vulnerability in nginx-ui allows authenticated users to modify critical nginx configuration commands via API endpoints that should be restricted,...
Jan 11, 2024Dell ThinOS versions 2402 and 2405 contain a command injection vulnerability that allows unauthenticated attackers with physical access to execute arb...
Sep 10, 2024This vulnerability in Python's mailcap module allows shell command injection when applications call mailcap.findmatch() with untrusted input. Attacker...
Apr 13, 2022This vulnerability allows authenticated users to execute arbitrary commands on affected NETGEAR WiFi systems through command injection. It affects mul...
Dec 26, 2021This vulnerability allows authenticated users on affected NETGEAR routers to execute arbitrary commands through command injection. Attackers with vali...
Dec 26, 2021CVE-2026-21520 is an information disclosure vulnerability in Microsoft Copilot Studio that allows unauthenticated attackers to access sensitive inform...
Jan 22, 2026A command injection vulnerability in Serverless Framework's experimental MCP server feature allows attackers to execute arbitrary system commands via ...
Dec 30, 2025This vulnerability in Siemens RUGGEDCOM ROX devices allows attackers to inject additional configuration parameters during Dynamic DNS setup. Under cer...
Dec 9, 2025CVE-2025-61141 allows remote command injection in sqls-server/sqls version 0.2.28 through the config command. Attackers can execute arbitrary commands...
Oct 30, 2025CVE-2025-56406 is an improper neutralization vulnerability in mcp-neo4j 0.3.0 that allows attackers to execute arbitrary commands or access sensitive ...
Sep 10, 2025This vulnerability allows attackers with network access adjacent to an EdgeSwitch to execute arbitrary commands on the device through improper input v...
Aug 21, 2025A command injection vulnerability in mcp-package-docs MCP Server allows attackers to execute arbitrary system commands via unsanitized user input in c...
Jul 18, 2025CVE-2025-53372 is a command injection vulnerability in node-code-sandbox-mcp that allows attackers to execute arbitrary system commands on the host ma...
Jul 8, 2025CVE-2025-53107 is a command injection vulnerability in @cyanheads/git-mcp-server that allows remote code execution by injecting shell commands through...
Jul 1, 2025This CVE describes an Improper Neutralization of Escape Sequences vulnerability in UniFi Protect Cameras that could allow an attacker on the same netw...
Mar 1, 2025This vulnerability allows remote attackers to execute arbitrary commands on affected systems by sending specially crafted POST requests. It affects Ou...
Feb 13, 2025A command injection vulnerability exists in certain Poly video conferencing devices due to improper input sanitization. This flaw could allow authenti...
Nov 5, 2024A prompt injection vulnerability in Blackbox AI v1.3.95 allows attackers to access and exfiltrate all previous and subsequent chat data between users ...
Oct 24, 2024A prompt injection vulnerability in Zhipu AI CodeGeeX allows attackers to access and exfiltrate all chat data between users and the AI assistant throu...
Oct 24, 2024This vulnerability allows a low-privileged attacker with remote access to execute arbitrary commands on Dell SmartFabric OS10 networking devices throu...
Sep 6, 2024This vulnerability allows remote attackers to execute arbitrary commands on D-Link DIR-822+ routers via command injection in the SetPlcNetworkpwd func...
Apr 26, 2024CVE-2022-35503 is an improper input validation vulnerability in Open Source MANO (OSM) that allows authenticated attackers to execute arbitrary code w...
Apr 22, 2024CVE-2024-20667 is a remote code execution vulnerability in Azure DevOps Server that allows attackers to execute arbitrary code on affected systems. Th...
Feb 13, 2024This vulnerability in Memcached allows remote attackers to crash the daemon by sending specially crafted meta commands. It affects Memcached servers r...
Aug 22, 2023This CVE describes a sandbox bypass vulnerability in Thymeleaf templates that allows Server-Side Template Injection (SSTI) and potential remote code e...
Jul 14, 2023This vulnerability in VMware Aria Operations for Networks allows attackers with network access to execute arbitrary commands through command injection...
Jun 7, 2023This vulnerability allows attackers to create empty files in arbitrary locations on GL.iNet device filesystems, limited to paths/filenames of 6 charac...
May 9, 2023This CVE describes a command injection vulnerability in Tenda G103 routers that allows attackers to execute arbitrary commands on the device. Attacker...
Mar 23, 2023This CVE describes a command injection vulnerability in TOTOLINK EX300_v2 routers that allows attackers to execute arbitrary commands on affected devi...
Mar 31, 2022CVE-2021-23727 is a command injection vulnerability in Celery task queue software. Attackers who can access or manipulate metadata in Celery backends ...
Dec 29, 2021This vulnerability allows authenticated users to execute arbitrary commands on affected NETGEAR switches through command injection. It affects multipl...
Dec 26, 2021CVE-2021-43557 is a URI normalization bypass vulnerability in Apache APISIX's uri-block plugin that allows attackers to bypass block lists by using sp...
Nov 22, 2021This vulnerability in OpenSourcePOS v3.4.1 allows attackers to execute arbitrary code on the server by sending a specially crafted AJAX response. This...
Feb 13, 2026This CVE describes an OS command injection vulnerability in QNAP Video Station that allows authenticated users to execute arbitrary commands on the sy...
Sep 6, 2024About Command Injection (CWE-77)
The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.
Our database tracks 1,171 CVEs classified as CWE-77, with 454 rated critical and 495 rated high severity. The average CVSS score for Command Injection vulnerabilities is 8.3.
External reference: View CWE-77 on MITRE CWE →
Monitor Command Injection Vulnerabilities
Get alerted when new Command Injection CVEs affect your infrastructure.
Start Monitoring Free