CWE-77: Command Injection

The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.

1,172
Total CVEs
454
Critical
496
High
8.3
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
83
2025
378
2024
247
2023
225
2022
77

Top Affected Vendors

1 Totolink 107
2 Dlink 80
3 Netgear 77
4 Tenda 35
5 Arubanetworks 32
6 Linksys 28
7 Microsoft 24
8 Qnap 20
9 Siemens 18
10 Wavlink 17

All Command Injection CVEs (1,172)

CVE-2024-3116
7.4

pgAdmin versions up to 8.4 contain a remote code execution vulnerability in the validate binary path API. Attackers can exploit this to execute arbitr...

Apr 4, 2024
CVE-2023-47562
7.4

This CVE describes an OS command injection vulnerability in QNAP Photo Station that allows authenticated users to execute arbitrary commands on the sy...

Feb 2, 2024
CVE-2023-47560
7.4

This CVE describes an OS command injection vulnerability in QuMagie, a photo management application from QNAP. It allows authenticated users to execut...

Jan 5, 2024
CVE-2026-3696
7.3

This CVE describes a remote command injection vulnerability in Totolink N300RH routers. Attackers can execute arbitrary operating system commands by m...

Mar 8, 2026
CVE-2025-33181
7.3

This vulnerability allows low-privileged users on NVIDIA Cumulus Linux and NVOS systems to inject commands through the NVUE interface, potentially lea...

Feb 24, 2026
CVE-2026-2952
7.3

This vulnerability allows remote attackers to execute arbitrary operating system commands on systems running Vaelsys 4.1.0 by exploiting an OS command...

Feb 22, 2026
CVE-2026-2944
7.3

This CVE describes an OS command injection vulnerability in Tosei Online Store Management System 1.01. Attackers can execute arbitrary operating syste...

Feb 22, 2026
CVE-2026-2544
7.3

This vulnerability allows remote attackers to execute arbitrary operating system commands on systems running vulnerable versions of yued-fe LuLu UI. T...

Feb 16, 2026
CVE-2026-2184
7.3

This CVE describes an OS command injection vulnerability in the Great Developers Certificate Generation System that allows remote attackers to execute...

Feb 8, 2026
CVE-2025-15502
7.3

This CVE describes a remote command injection vulnerability in Sangfor Operation and Maintenance Management System. Attackers can execute arbitrary op...

Jan 10, 2026
CVE-2025-65292
7.3

A command injection vulnerability in Aqara Hub devices allows attackers to execute arbitrary commands with root privileges by exploiting malicious dom...

Dec 10, 2025
CVE-2025-60697
7.3

This CVE describes a command injection vulnerability in D-Link DIR-882 router firmware that allows unauthenticated remote attackers to execute arbitra...

Nov 13, 2025
CVE-2025-60698
7.3

This CVE describes a command injection vulnerability in D-Link DIR-882 router firmware that allows unauthenticated remote attackers to execute arbitra...

Nov 13, 2025
CVE-2025-10358
7.3

This CVE describes a remote command injection vulnerability in Wavlink WL-WN578W2 routers. Attackers can execute arbitrary operating system commands b...

Sep 13, 2025
CVE-2025-9026
7.3

This CVE describes a remote command injection vulnerability in D-Link DIR-860L routers via the Simple Service Discovery Protocol (SSDP) service. Attac...

Aug 15, 2025
CVE-2025-5952
7.3

This critical vulnerability in Zend.To allows remote attackers to execute arbitrary operating system commands through command injection in the exec fu...

Jun 10, 2025
CVE-2025-5621
7.3

This critical vulnerability in D-Link DIR-816 routers allows remote attackers to execute arbitrary operating system commands via command injection in ...

Jun 5, 2025
CVE-2025-5106
7.3

This critical vulnerability in Fujian Kelixun 1.0 allows remote attackers to execute arbitrary operating system commands via command injection in the ...

May 23, 2025
CVE-2024-40445
7.3

A directory traversal vulnerability in forkosh Mime TeX allows attackers on Windows systems to read or append arbitrary files by manipulating input pa...

Apr 22, 2025
CVE-2025-3729
7.3

This critical vulnerability allows remote attackers to execute arbitrary operating system commands on systems running SourceCodester Web-based Pharmac...

Apr 16, 2025
CVE-2024-53305
7.3

This vulnerability allows remote attackers to execute arbitrary code on Whoogle Search instances by sending specially crafted search queries. It affec...

Apr 16, 2025
CVE-2024-36842
7.3

This vulnerability allows remote attackers to execute arbitrary code on affected Oncord+ Android Infotainment Systems via the ADB (Android Debug Bridg...

Apr 15, 2025
CVE-2025-3002
7.3

This critical vulnerability in Digital China DCME-520 devices allows remote attackers to execute arbitrary operating system commands by manipulating t...

Mar 31, 2025
CVE-2025-1546
7.3

This critical vulnerability allows remote attackers to execute arbitrary operating system commands on BDCOM Behavior Management and Auditing Systems b...

Feb 21, 2025
CVE-2025-23094
EPSS 29% 7.3

This CVE describes a command injection vulnerability in Mitel OpenScape 4000 and OpenScape 4000 Manager platforms. Unauthenticated attackers can execu...

Feb 6, 2025
CVE-2024-12986
7.3

This critical vulnerability allows remote attackers to execute arbitrary operating system commands on affected DrayTek gateway devices through command...

Dec 27, 2024
CVE-2024-49194
7.3

This vulnerability in Databricks JDBC Driver allows remote code execution via JNDI injection through a crafted JDBC URL containing the krbJAASFile par...

Dec 17, 2024
CVE-2021-27702
7.3

This vulnerability allows attackers to bypass authentication via the diagnostic utility in the Sercomm Router Etisalat Model S3-AC2100 dashboard. It e...

Nov 12, 2024
CVE-2024-33508
7.3

An unauthenticated command injection vulnerability in Fortinet FortiClientEMS allows attackers to execute limited database operations via crafted requ...

Sep 10, 2024
CVE-2024-32283
7.3

This vulnerability allows remote attackers to execute arbitrary commands on Tenda FH1203 routers by injecting malicious commands through the cmdinput ...

Apr 17, 2024
CVE-2024-2642
7.3

This critical vulnerability in Ruijie RG-NBS2009G-P network switches allows remote attackers to execute arbitrary commands via command injection in th...

Mar 19, 2024
CVE-2024-25998
7.3

CVE-2024-25998 allows unauthenticated remote attackers to execute arbitrary commands on OCPP (Open Charge Point Protocol) services due to improper inp...

Mar 12, 2024
CVE-2024-21488
7.3

CVE-2024-21488 is a command injection vulnerability in the network npm package that allows attackers to execute arbitrary operating system commands. T...

Jan 30, 2024
CVE-2023-34230
7.3

The Snowflake Connector for .NET is vulnerable to command injection via SSO URL authentication, allowing remote code execution if an attacker tricks a...

Jun 8, 2023
CVE-2021-29069
7.3

This vulnerability allows authenticated users on certain NETGEAR routers to execute arbitrary commands through command injection. It affects XR450, XR...

Mar 23, 2021
CVE-2026-2846
7.2

This CVE describes a remote command injection vulnerability in the UTT HiPER 520 router's web management interface. Attackers can execute arbitrary op...

Feb 20, 2026
CVE-2026-2670
7.2

This CVE describes a remote command injection vulnerability in Advantech WISE-6610 devices. Attackers can execute arbitrary operating system commands ...

Feb 18, 2026
CVE-2026-2260
7.2

This CVE describes a remote command injection vulnerability in D-Link DCS-931L IP cameras. Attackers can execute arbitrary operating system commands b...

Feb 10, 2026
CVE-2026-2210
7.2

This CVE describes a remote command injection vulnerability in D-Link DIR-823X routers. Attackers can execute arbitrary operating system commands by m...

Feb 9, 2026
CVE-2026-2188
7.2

This vulnerability allows remote attackers to execute arbitrary operating system commands on UTT 进取 521G devices through command injection in the ...

Feb 8, 2026
CVE-2026-2175
7.2

This CVE describes an OS command injection vulnerability in D-Link DIR-823X routers that allows remote attackers to execute arbitrary commands on affe...

Feb 8, 2026
CVE-2026-2157
7.2

This CVE describes a remote command injection vulnerability in D-Link DIR-823X routers. Attackers can execute arbitrary operating system commands by m...

Feb 8, 2026
CVE-2026-2155
7.2

This CVE describes a remote command injection vulnerability in D-Link DIR-823X routers. Attackers can execute arbitrary operating system commands by m...

Feb 8, 2026
CVE-2026-2152
7.2

This CVE describes a remote command injection vulnerability in D-Link DIR-615 routers through the web configuration interface. Attackers can execute a...

Feb 8, 2026
CVE-2026-2151
7.2

This CVE describes an OS command injection vulnerability in D-Link DIR-615 routers affecting the DMZ Host feature. Attackers can execute arbitrary com...

Feb 8, 2026
CVE-2026-2143
7.2

This CVE describes a remote command injection vulnerability in D-Link DIR-823X routers. Attackers can execute arbitrary operating system commands by m...

Feb 8, 2026
CVE-2026-2142
7.2

This CVE describes a remote OS command injection vulnerability in D-Link DIR-823X routers. Attackers can execute arbitrary commands on affected device...

Feb 8, 2026
CVE-2026-2129
7.2

This CVE describes an OS command injection vulnerability in D-Link DIR-823X routers that allows remote attackers to execute arbitrary commands on affe...

Feb 8, 2026
CVE-2026-2120
7.2

This CVE describes a remote command injection vulnerability in D-Link DIR-823X routers. Attackers can execute arbitrary operating system commands by m...

Feb 8, 2026
CVE-2026-2084
7.2

This CVE describes an OS command injection vulnerability in D-Link DIR-823X routers. Attackers can remotely execute arbitrary commands by manipulating...

Feb 7, 2026

About Command Injection (CWE-77)

The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.

Our database tracks 1,172 CVEs classified as CWE-77, with 454 rated critical and 496 rated high severity. The average CVSS score for Command Injection vulnerabilities is 8.3.

External reference: View CWE-77 on MITRE CWE →

Monitor Command Injection Vulnerabilities

Get alerted when new Command Injection CVEs affect your infrastructure.

Start Monitoring Free