CWE-77: Command Injection
The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.
Yearly Trend
Top Affected Vendors
All Command Injection CVEs (1,188)
CVE-2021-20527 is an improper neutralization of special elements vulnerability in IBM Resilient SOAR that allows a privileged user to create malicious...
Apr 19, 2021CVE-2020-25217 is a command injection vulnerability in Grandstream GRP261x VoIP phones that allows attackers to execute arbitrary commands as root thr...
Mar 29, 2021This CVE-2020-2508 is a command injection vulnerability in QNAP QTS and QuTS hero operating systems that allows attackers to execute arbitrary command...
Jan 11, 2021This CVE describes an authenticated command injection vulnerability in Barco TransForm N's NDN-210 web administration panel. It allows authenticated u...
Jan 8, 2021This CVE describes an authenticated command injection vulnerability in the Barco NDN-210 web administration panel. Authenticated attackers can execute...
Jan 8, 2021This CVE allows authenticated administrators to execute arbitrary commands on affected Zyxel firewall and VPN products by injecting malicious input du...
Dec 27, 2020This command injection vulnerability in QNAP QTS allows remote attackers to execute arbitrary commands on affected systems. It affects QNAP NAS device...
Nov 16, 2020This vulnerability allows authenticated remote attackers to execute arbitrary commands with root privileges on Cisco IOS XE devices via the web UI. At...
Jun 3, 2020This vulnerability in Vim's tar.vim plugin allows arbitrary shell command execution when opening specially crafted tar archives. Attackers can exploit...
Mar 3, 2025Authenticated users in Logpoint UniversalNormalizer can inject malicious payloads while creating Universal Normalizer configurations, leading to remot...
Dec 16, 2024Authenticated users in Logpoint versions before 7.5.0 can inject malicious payloads into Report Templates. When backups are initiated, these payloads ...
Dec 16, 2024This CVE describes a command injection vulnerability in Dell SmartFabric OS10 Software that allows low-privileged remote attackers to execute arbitrar...
Sep 26, 2024CVE-2024-4638 is a command injection vulnerability in OnCell G3470A-LTE Series industrial cellular routers. Attackers can execute arbitrary commands b...
Jun 25, 2024CVE-2023-35932 is a configuration injection vulnerability in the jcvi Python library that allows malicious user input to reach configuration files uns...
Jun 23, 2023This vulnerability allows authenticated users on NETGEAR D6220 routers to execute arbitrary commands through command injection. Attackers with valid c...
Dec 26, 2021This command injection vulnerability in Azure Arc allows authenticated attackers to execute arbitrary commands on affected systems, potentially leadin...
Mar 11, 2025CVE-2020-7384 is a command injection vulnerability in Rapid7's Metasploit msfvenom framework that allows attackers to execute arbitrary commands on sy...
Oct 29, 2020This vulnerability allows local physical attackers with access to the device's SD card slot to execute arbitrary code by overriding the bootloader. It...
Nov 24, 2025This vulnerability in alist-tvbox v1.7.1 allows remote attackers to execute arbitrary commands on affected systems via the /atv-cli endpoint. This is ...
Nov 21, 2024This command injection vulnerability in Visual Studio allows authenticated attackers to execute arbitrary code on the local system by injecting malici...
Nov 11, 2025This CVE describes a command injection vulnerability in Dell SmartFabric OS10 Software that allows high-privileged attackers with local access to exec...
Mar 17, 2025Dell SmartFabric OS10 Software contains a command injection vulnerability that allows authenticated high-privileged attackers to execute arbitrary com...
Feb 17, 2026This CVE describes a command injection vulnerability in Aqara Camera Hub G3 devices that allows attackers to execute arbitrary commands with root priv...
Dec 10, 2025This CVE describes an OS command injection vulnerability in QNAP operating systems that allows authenticated administrators to execute arbitrary comma...
Sep 6, 2024This vulnerability allows an administrative remote attacker controlling a SINEMA Remote Connect Server to execute arbitrary code with system privilege...
Jul 9, 2024This CVE describes an OS command injection vulnerability in QNAP operating systems that allows remote authenticated administrators to execute arbitrar...
Mar 29, 2023A command injection vulnerability in AOS-8 allows authenticated privileged users to inject shell commands by manipulating package headers. This could ...
Jan 13, 2026This DLL hijacking vulnerability in Axtion ODISSAAS ODIS v1.8.4 allows attackers to place a malicious DLL in a location where the application searches...
Jan 9, 2026A command injection vulnerability in sonirico mcp-shell v0.3.1 allows attackers to execute arbitrary system commands by supplying malicious input to t...
Jan 7, 2026CVE-2025-67436 is an authenticated remote code execution vulnerability in PluXml CMS 5.8.22. Attackers with administrator panel access can inject mali...
Dec 22, 2025This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK N200RE routers by injecting malicious input into the hostName par...
Dec 15, 2025This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK A3300R routers by injecting malicious input into the host_time pa...
Dec 15, 2025This CVE describes an authenticated command injection vulnerability in AVTECH SECURITY Corporation's DGM1104 FullImg-1015-1004-1006-1003 firmware. Att...
Dec 3, 2025CVE-2025-65657 is a remote code execution vulnerability in FeehiCMS version 2.1.1 that allows authenticated attackers to upload malicious PHP files th...
Dec 2, 2025This vulnerability allows authenticated remote attackers to inject malicious commands through the device's command line interface, potentially executi...
Nov 18, 2025CVE-2025-63749 is a command injection vulnerability in pnetlab 5.3.11 that allows attackers to execute arbitrary commands on the system by manipulatin...
Nov 18, 2025A remote command execution vulnerability in H3C ERG3/ERG5 series routers, XiaoBei series routers, cloud gateways, and wireless access points allows at...
Nov 18, 2025This CVE describes a remote code execution vulnerability in baryhuang/mcp-server-aws-resources-python version 0.1.0. Attackers can execute arbitrary P...
Nov 18, 2025This CVE describes an unauthenticated command injection vulnerability in D-Link DIR-878A1 router firmware that allows remote attackers to execute arbi...
Nov 13, 2025This vulnerability allows unauthenticated remote attackers to execute arbitrary commands on D-Link DIR-878A1 routers by exploiting a command injection...
Nov 13, 2025This CVE describes a command injection vulnerability in D-Link DIR-882 router firmware that allows unauthenticated remote attackers to execute arbitra...
Nov 13, 2025This CVE describes a command injection vulnerability in ToToLink A720R router firmware that allows unauthenticated remote attackers to execute arbitra...
Nov 13, 2025This CVE describes a command injection vulnerability in ToToLink A720R router firmware that allows arbitrary command execution. Attackers with write a...
Nov 13, 2025An unauthenticated command injection vulnerability in ToToLink LR1200GB routers allows attackers to execute arbitrary system commands by sending malic...
Nov 13, 2025This vulnerability allows arbitrary code execution as root on KERUI K259 5MP Wi-Fi/Tuya Smart Security Cameras. During startup, the camera automatical...
Nov 10, 2025A command injection vulnerability in NetSurf browser version 3.11 allows remote attackers to execute arbitrary code via the dom_node_normalize functio...
Nov 3, 2025The Reolink desktop application version 8.18.12 contains a command injection vulnerability in its scheduled cache-clearing mechanism. An attacker coul...
Oct 21, 2025CVE-2025-57164 allows remote code execution in Flowise AI platforms through unsanitized user input in the Supabase RPC Filter field. Attackers can exe...
Oct 17, 2025An arbitrary file upload vulnerability in CoCalc allows attackers to upload malicious SVG files that can execute arbitrary code on the server. This af...
Oct 16, 2025This vulnerability in MCMS v6.0.1 allows attackers to upload malicious files to the server, which can then be executed to run arbitrary code. This aff...
Oct 10, 2025About Command Injection (CWE-77)
The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.
Our database tracks 1,188 CVEs classified as CWE-77, with 460 rated critical and 507 rated high severity. The average CVSS score for Command Injection vulnerabilities is 8.3.
External reference: View CWE-77 on MITRE CWE →
Monitor Command Injection Vulnerabilities
Get alerted when new Command Injection CVEs affect your infrastructure.
Start Monitoring Free