CWE-77: Command Injection
The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.
Yearly Trend
Top Affected Vendors
All Command Injection CVEs (1,173)
This CVE describes an OS command injection vulnerability in D-Link DIR-823X routers. Attackers can remotely execute arbitrary commands by manipulating...
Feb 7, 2026This vulnerability allows authenticated users of certain HIKSEMI NAS products to execute arbitrary commands on the device by sending specially crafted...
Jan 30, 2026This CVE describes an OS command injection vulnerability in D-Link DIR-615 routers via the MAC Filter Configuration component. Attackers can execute a...
Jan 28, 2026This CVE describes a remote OS command injection vulnerability in D-Link DIR-615 routers via the /set_temp_nodes.php file in the URL Filter component....
Jan 28, 2026This vulnerability allows remote attackers to execute arbitrary operating system commands on TRENDnet TEW-811DRU routers by manipulating the DeviceURL...
Jan 7, 2026This vulnerability in Siemens RUGGEDCOM ROX devices allows attackers to gain root access by exploiting insufficient validation during configuration fi...
Dec 9, 2025This vulnerability allows authenticated web users on Ruijie APs to execute arbitrary shell commands as root via command injection in the web_action.do...
Dec 8, 2025This CVE describes a command injection vulnerability in HPE Aruba Networking Airwave Platform's CLI that allows authenticated attackers to execute arb...
Nov 18, 2025This vulnerability allows authenticated remote attackers to execute arbitrary commands on network access point configuration services through the web-...
Oct 14, 2025An authenticated command injection vulnerability in the CLI binary of AOS-8 Controller/Mobility Conductor allows attackers with valid credentials to e...
Oct 14, 2025An authenticated command injection vulnerability in the CLI binary of AOS-8 Controller/Mobility Conductor allows authenticated attackers to execute ar...
Oct 14, 2025A command injection vulnerability in QuRouter 2.5.1 allows authenticated attackers with administrator privileges to execute arbitrary commands on affe...
Aug 29, 2025This CVE describes a command injection vulnerability in D-Link DSL-7740C routers that allows attackers to execute arbitrary commands via the ping6 fun...
Aug 25, 2025This CVE describes a command injection vulnerability in D-Link DSL-7740C routers that allows attackers to execute arbitrary commands via the backup fu...
Aug 25, 2025An authenticated command injection vulnerability in HPE Networking Instant On Access Points allows attackers with elevated privileges to execute arbit...
Jul 8, 2025An authenticated command injection vulnerability in Palo Alto Networks PAN-OS allows administrative users with management interface access to execute ...
Jun 13, 2025A command injection vulnerability in HPE StoreOnce Software allows remote attackers to execute arbitrary commands on affected systems. This affects or...
Jun 2, 2025A critical remote code execution vulnerability in GatesAir Maxiva UAXT/VAXT transmitters allows authenticated attackers to execute arbitrary commands ...
Feb 13, 2025This CVE describes an authenticated command injection vulnerability in a network management service's command-line interface. Attackers with valid cre...
Jan 14, 2025Authenticated command injection vulnerabilities in HPE 501 Wireless Client Bridge web interface allow attackers with administrative credentials to exe...
Jan 7, 2025This vulnerability allows authenticated remote attackers to execute arbitrary commands on HPE Aruba ClearPass Policy Manager systems through the web m...
Dec 3, 2024This vulnerability allows authenticated users with CREATE privilege on Azure Database for PostgreSQL Flexible Server to execute arbitrary commands thr...
Nov 12, 2024This vulnerability allows authenticated users with database access to execute arbitrary commands on the underlying operating system through PostgreSQL...
Nov 12, 2024An authenticated command injection vulnerability in Aruba Instant AOS-8 and AOS-10 CLI allows attackers to execute arbitrary commands as privileged us...
Nov 5, 2024This critical vulnerability allows remote attackers to execute arbitrary commands on affected WAVLINK routers by manipulating the dhcpGateway paramete...
Oct 27, 2024This CVE describes an OS command injection vulnerability in Ivanti CSA's admin web console that allows authenticated administrators to execute arbitra...
Oct 8, 2024This vulnerability allows authenticated attackers to execute arbitrary code on Microsoft SharePoint Server by sending specially crafted requests. It a...
Sep 10, 2024This vulnerability in Seacms v13.1 allows attackers to inject malicious IP parameters through the admin_ip.php file, which are then written to a confi...
Aug 30, 2024This CVE describes a command injection vulnerability in Enphase IQ Gateway devices (formerly Envoy) where authenticated attackers can execute arbitrar...
Aug 12, 2024This vulnerability allows remote authenticated users to execute arbitrary commands as root on HPE Aruba EdgeConnect SD-WAN gateways through the CLI. A...
Jul 24, 2024This vulnerability allows an attacker with administrative access to the Netwrix CoSoSys Endpoint Protector or Unify server to execute arbitrary system...
Jun 27, 2024TELSAT marKoni FM Transmitters contain a command injection vulnerability (CWE-77) that allows attackers to execute arbitrary commands by manipulating ...
Jun 27, 2024This vulnerability allows authenticated privileged remote attackers to execute arbitrary commands with root privileges on affected CPCI85 and SICORE B...
May 14, 2024This CVE describes a command injection vulnerability in certain Hikvision NVR devices that allows authenticated administrators to execute arbitrary co...
Apr 2, 2024Authenticated command injection vulnerabilities in ArubaOS CLI allow attackers with valid credentials to execute arbitrary commands as privileged user...
Mar 5, 2024Authenticated command injection vulnerabilities in ArubaOS CLI allow attackers with valid credentials to execute arbitrary commands as privileged user...
Mar 5, 2024This vulnerability in ClearPass Policy Manager allows authenticated remote attackers to execute arbitrary commands as root on the underlying operating...
Feb 27, 2024This vulnerability in Aruba ClearPass Policy Manager allows authenticated remote users to execute arbitrary commands on the underlying host with root ...
Feb 27, 2024This vulnerability in Aruba ClearPass Policy Manager allows authenticated remote attackers to execute arbitrary commands as root on the underlying ope...
Feb 27, 2024This vulnerability allows authenticated attackers to execute arbitrary commands on GTB Central Console systems through command injection in the DNS se...
Feb 2, 2024This critical vulnerability in TRENDnet TEW-822DRE routers allows remote attackers to execute arbitrary commands via command injection in the ping fun...
Jan 26, 2024This vulnerability in the Newsletters WordPress plugin allows administrators to execute arbitrary SQL queries and shell commands on the server due to ...
Jan 16, 2024This vulnerability allows authenticated administrators on Peplink Balance Two routers to execute arbitrary commands as root via command injection in t...
Dec 25, 2023This vulnerability in Apache StreamPark allows authenticated users with system-level permissions to execute arbitrary commands through Maven compilati...
Dec 15, 2023This vulnerability allows a malicious administrator in Jellyfin to execute arbitrary code on the server by exploiting a path traversal issue in the me...
Dec 13, 2023This CVE describes a command injection vulnerability in PRTG Network Monitor's DICOM C-ECHO sensor. Authenticated users with write permissions can exp...
Aug 9, 2023This CVE describes an OS command injection vulnerability in the libzebra.so library's change_hostname function in Milesight UR32L routers. Attackers c...
Jul 6, 2023This CVE describes an OS command injection vulnerability in the Milesight UR32L router's user deletion functionality. Attackers can execute arbitrary ...
Jul 6, 2023Authenticated command injection vulnerabilities in ArubaOS CLI allow attackers with valid credentials to execute arbitrary commands as privileged user...
Jul 5, 2023This vulnerability allows authenticated privileged remote attackers to execute arbitrary commands with root privileges on Siemens CP-8031 and CP-8050 ...
Jun 13, 2023About Command Injection (CWE-77)
The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.
Our database tracks 1,173 CVEs classified as CWE-77, with 454 rated critical and 497 rated high severity. The average CVSS score for Command Injection vulnerabilities is 8.3.
External reference: View CWE-77 on MITRE CWE →
Monitor Command Injection Vulnerabilities
Get alerted when new Command Injection CVEs affect your infrastructure.
Start Monitoring Free