CWE-77: Command Injection

The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.

1,188
Total CVEs
460
Critical
507
High
8.3
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
83
2025
378
2024
247
2023
225
2022
77

Top Affected Vendors

1 Totolink 107
2 Dlink 80
3 Netgear 80
4 Tenda 35
5 Arubanetworks 32
6 Linksys 28
7 Microsoft 24
8 Qnap 21
9 Siemens 18
10 Wavlink 17

All Command Injection CVEs (1,188)

CVE-2024-26296
7.2

This vulnerability in ClearPass Policy Manager allows authenticated remote attackers to execute arbitrary commands as root on the underlying operating...

Feb 27, 2024
CVE-2024-26298
7.2

This vulnerability in Aruba ClearPass Policy Manager allows authenticated remote users to execute arbitrary commands on the underlying host with root ...

Feb 27, 2024
CVE-2024-26294
7.2

This vulnerability in Aruba ClearPass Policy Manager allows authenticated remote attackers to execute arbitrary commands as root on the underlying ope...

Feb 27, 2024
CVE-2024-22107
7.2

This vulnerability allows authenticated attackers to execute arbitrary commands on GTB Central Console systems through command injection in the DNS se...

Feb 2, 2024
CVE-2024-0920
7.2

This critical vulnerability in TRENDnet TEW-822DRE routers allows remote attackers to execute arbitrary commands via command injection in the ping fun...

Jan 26, 2024
CVE-2023-4797
7.2

This vulnerability in the Newsletters WordPress plugin allows administrators to execute arbitrary SQL queries and shell commands on the server due to ...

Jan 16, 2024
CVE-2023-49226
7.2

This vulnerability allows authenticated administrators on Peplink Balance Two routers to execute arbitrary commands as root via command injection in t...

Dec 25, 2023
CVE-2023-49898
7.2

This vulnerability in Apache StreamPark allows authenticated users with system-level permissions to execute arbitrary commands through Maven compilati...

Dec 15, 2023
CVE-2023-48702
7.2

This vulnerability allows a malicious administrator in Jellyfin to execute arbitrary code on the server by exploiting a path traversal issue in the me...

Dec 13, 2023
CVE-2023-32782
7.2

This CVE describes a command injection vulnerability in PRTG Network Monitor's DICOM C-ECHO sensor. Authenticated users with write permissions can exp...

Aug 9, 2023
CVE-2023-22659
7.2

This CVE describes an OS command injection vulnerability in the libzebra.so library's change_hostname function in Milesight UR32L routers. Attackers c...

Jul 6, 2023
CVE-2023-23550
7.2

This CVE describes an OS command injection vulnerability in the Milesight UR32L router's user deletion functionality. Attackers can execute arbitrary ...

Jul 6, 2023
CVE-2023-35973
7.2

Authenticated command injection vulnerabilities in ArubaOS CLI allow attackers with valid credentials to execute arbitrary commands as privileged user...

Jul 5, 2023
CVE-2023-33919
7.2

This vulnerability allows authenticated privileged remote attackers to execute arbitrary commands with root privileges on Siemens CP-8031 and CP-8050 ...

Jun 13, 2023
CVE-2022-38156
7.2

This vulnerability allows authenticated admin users to execute arbitrary Linux commands as root on Kratos SpectralNet Narrowband devices. Attackers ca...

Jun 12, 2023
CVE-2023-31460
7.2

This vulnerability allows authenticated attackers with internal network access to execute arbitrary commands on MiVoice Connect systems through comman...

May 24, 2023
CVE-2023-31740
7.2

This is a command injection vulnerability in Linksys E2000 routers that allows authenticated attackers to execute arbitrary commands with shell privil...

May 23, 2023
CVE-2023-31742
7.2

This CVE describes a command injection vulnerability in Linksys WRT54GL routers that allows authenticated attackers to execute arbitrary commands with...

May 22, 2023
CVE-2023-28832
7.2

This vulnerability allows authenticated privileged remote attackers to execute arbitrary commands with root privileges on affected SIMATIC Cloud Conne...

May 9, 2023
CVE-2023-22789
7.2

This CVE describes authenticated command injection vulnerabilities in Aruba InstantOS and ArubaOS 10 command line interfaces. Attackers with authentic...

May 8, 2023
CVE-2023-29855
7.2

WBCE CMS 1.5.3 contains a command injection vulnerability in admin/languages/install.php that allows authenticated attackers to execute arbitrary comm...

Apr 18, 2023
CVE-2023-29084
7.2

This vulnerability allows authenticated users in Zoho ManageEngine ADManager Plus to execute arbitrary commands through proxy settings. Attackers with...

Apr 13, 2023
CVE-2022-4934
7.2

This CVE describes a post-authentication command injection vulnerability in Sophos Web Appliance's exception wizard. It allows authenticated administr...

Apr 4, 2023
CVE-2023-1458
7.2

CVE-2023-1458 is a command injection vulnerability in Ubiquiti EdgeRouter X's OSPF handler that allows authenticated attackers to execute arbitrary co...

Mar 25, 2023
CVE-2023-1456
7.2

CVE-2023-1456 is a post-authentication command injection vulnerability in Ubiquiti EdgeRouter X's NAT Configuration Handler. Attackers with administra...

Mar 25, 2023
CVE-2023-1168
7.2

This CVE describes an authenticated remote code execution vulnerability in Aruba's AOS-CX Network Analytics Engine. Attackers with valid credentials c...

Mar 22, 2023
CVE-2023-28460
7.2

A command injection vulnerability in Array Networks APV products allows authenticated administrators to execute arbitrary shell commands via crafted p...

Mar 15, 2023
CVE-2023-1162
7.2

This is a critical command injection vulnerability in DrayTek Vigor 2960 routers that allows attackers to execute arbitrary commands on the device by ...

Mar 3, 2023
CVE-2023-22759
7.2

CVE-2023-22759 is an authenticated remote command injection vulnerability in ArubaOS web management interfaces. It allows authenticated attackers to e...

Mar 1, 2023
CVE-2023-22761
7.2

CVE-2023-22761 allows authenticated attackers to execute arbitrary commands as privileged users on ArubaOS devices through the web management interfac...

Mar 1, 2023
CVE-2023-22763
7.2

This CVE describes authenticated command injection vulnerabilities in ArubaOS command line interface that allow attackers to execute arbitrary command...

Mar 1, 2023
CVE-2023-22765
7.2

Authenticated command injection vulnerabilities in ArubaOS CLI allow attackers with valid credentials to execute arbitrary commands as privileged user...

Mar 1, 2023
CVE-2023-22767
7.2

CVE-2023-22767 allows authenticated attackers to execute arbitrary commands with privileged access on ArubaOS devices through command injection in the...

Mar 1, 2023
CVE-2023-22769
7.2

This CVE describes authenticated command injection vulnerabilities in ArubaOS command line interface. Attackers with valid credentials can execute arb...

Mar 1, 2023
CVE-2023-0861
7.2

This vulnerability allows authenticated users of NetModule NSRW web administration interface to execute arbitrary operating system commands with eleva...

Feb 16, 2023
CVE-2023-0638
7.2

This critical vulnerability in TRENDnet TEW-811DRU routers allows remote attackers to execute arbitrary commands through the web interface. Attackers ...

Feb 2, 2023
CVE-2023-0640
7.2

This critical vulnerability in TRENDnet TEW-652BRP routers allows remote attackers to execute arbitrary commands via the web interface's ping.ccp file...

Feb 2, 2023
CVE-2022-28935
7.2

This CVE describes a command injection vulnerability in multiple Totolink router models that allows attackers to execute arbitrary commands on affecte...

Jul 6, 2022
CVE-2022-26007
7.2

This CVE describes an OS command injection vulnerability in InHand Networks InRouter302's console factory functionality. Attackers can execute arbitra...

May 12, 2022
CVE-2021-40345
7.2

This is a command injection vulnerability in Nagios XI 5.8.5 that allows authenticated administrators to execute arbitrary system commands by uploadin...

Oct 26, 2021
CVE-2021-40998
7.2

This CVE describes a remote arbitrary command execution vulnerability in Aruba ClearPass Policy Manager. Attackers can execute arbitrary commands on a...

Oct 15, 2021
CVE-2021-40986
7.2

This CVE describes a remote arbitrary command execution vulnerability in Aruba ClearPass Policy Manager. Attackers can execute arbitrary commands on a...

Oct 15, 2021
CVE-2021-40999
7.2

This CVE allows remote attackers to execute arbitrary commands on Aruba ClearPass Policy Manager systems without authentication. It affects ClearPass ...

Oct 15, 2021
CVE-2021-41383
7.2

This vulnerability allows authenticated administrators on NETGEAR R6020 routers to execute arbitrary shell commands by injecting shell metacharacters ...

Sep 17, 2021
CVE-2020-14109
7.2

This vulnerability allows remote command injection in the meshd routing service on Xiaomi AX3600 routers, enabling attackers to execute arbitrary comm...

Sep 16, 2021
CVE-2021-37718
7.2

This CVE allows remote attackers to execute arbitrary commands on affected Aruba SD-WAN and gateway devices. The vulnerability stems from improper neu...

Sep 7, 2021
CVE-2021-37720
7.2

This CVE allows remote attackers to execute arbitrary commands on Aruba SD-WAN and gateway devices running vulnerable ArubaOS versions. Attackers can ...

Sep 7, 2021
CVE-2021-37722
7.2

This CVE allows remote attackers to execute arbitrary commands on Aruba SD-WAN and gateway devices through improper neutralization of special elements...

Sep 7, 2021
CVE-2021-37724
7.2

This CVE allows remote attackers to execute arbitrary commands on ArubaOS network devices without authentication. It affects ArubaOS versions prior to...

Sep 7, 2021
CVE-2020-12967
7.2

CVE-2020-12967 is a vulnerability in AMD's SEV/SEV-ES memory encryption technology where lack of nested page table protection could allow a compromise...

May 13, 2021

About Command Injection (CWE-77)

The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.

Our database tracks 1,188 CVEs classified as CWE-77, with 460 rated critical and 507 rated high severity. The average CVSS score for Command Injection vulnerabilities is 8.3.

External reference: View CWE-77 on MITRE CWE →

Monitor Command Injection Vulnerabilities

Get alerted when new Command Injection CVEs affect your infrastructure.

Start Monitoring Free