CWE-77: Command Injection

The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.

1,188
Total CVEs
460
Critical
507
High
8.3
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
83
2025
378
2024
247
2023
225
2022
77

Top Affected Vendors

1 Totolink 107
2 Dlink 80
3 Netgear 80
4 Tenda 35
5 Arubanetworks 32
6 Linksys 28
7 Microsoft 24
8 Qnap 21
9 Siemens 18
10 Wavlink 17

All Command Injection CVEs (1,188)

CVE-2021-20527
7.2

CVE-2021-20527 is an improper neutralization of special elements vulnerability in IBM Resilient SOAR that allows a privileged user to create malicious...

Apr 19, 2021
CVE-2020-25217
7.2

CVE-2020-25217 is a command injection vulnerability in Grandstream GRP261x VoIP phones that allows attackers to execute arbitrary commands as root thr...

Mar 29, 2021
CVE-2020-2508
7.2

This CVE-2020-2508 is a command injection vulnerability in QNAP QTS and QuTS hero operating systems that allows attackers to execute arbitrary command...

Jan 11, 2021
CVE-2020-17502
7.2

This CVE describes an authenticated command injection vulnerability in Barco TransForm N's NDN-210 web administration panel. It allows authenticated u...

Jan 8, 2021
CVE-2020-17504
7.2

This CVE describes an authenticated command injection vulnerability in the Barco NDN-210 web administration panel. Authenticated attackers can execute...

Jan 8, 2021
CVE-2020-29299
7.2

This CVE allows authenticated administrators to execute arbitrary commands on affected Zyxel firewall and VPN products by injecting malicious input du...

Dec 27, 2020
CVE-2020-2490
7.2

This command injection vulnerability in QNAP QTS allows remote attackers to execute arbitrary commands on affected systems. It affects QNAP NAS device...

Nov 16, 2020
CVE-2020-3211
7.2

This vulnerability allows authenticated remote attackers to execute arbitrary commands with root privileges on Cisco IOS XE devices via the web UI. At...

Jun 3, 2020
CVE-2025-27423
7.1

This vulnerability in Vim's tar.vim plugin allows arbitrary shell command execution when opening specially crafted tar archives. Attackers can exploit...

Mar 3, 2025
CVE-2024-56084
7.1

Authenticated users in Logpoint UniversalNormalizer can inject malicious payloads while creating Universal Normalizer configurations, leading to remot...

Dec 16, 2024
CVE-2024-56086
7.1

Authenticated users in Logpoint versions before 7.5.0 can inject malicious payloads into Report Templates. When backups are initiated, these payloads ...

Dec 16, 2024
CVE-2024-39577
7.1

This CVE describes a command injection vulnerability in Dell SmartFabric OS10 Software that allows low-privileged remote attackers to execute arbitrar...

Sep 26, 2024
CVE-2024-4638
7.1

CVE-2024-4638 is a command injection vulnerability in OnCell G3470A-LTE Series industrial cellular routers. Attackers can execute arbitrary commands b...

Jun 25, 2024
CVE-2023-35932
7.1

CVE-2023-35932 is a configuration injection vulnerability in the jcvi Python library that allows malicious user input to reach configuration files uns...

Jun 23, 2023
CVE-2021-45531
7.1

This vulnerability allows authenticated users on NETGEAR D6220 routers to execute arbitrary commands through command injection. Attackers with valid c...

Dec 26, 2021
CVE-2025-26627
7.0

This command injection vulnerability in Azure Arc allows authenticated attackers to execute arbitrary commands on affected systems, potentially leadin...

Mar 11, 2025
CVE-2020-7384
7.0

CVE-2020-7384 is a command injection vulnerability in Rapid7's Metasploit msfvenom framework that allows attackers to execute arbitrary commands on sy...

Oct 29, 2020
CVE-2025-63674
6.8

This vulnerability allows local physical attackers with access to the device's SD card slot to execute arbitrary code by overriding the bootloader. It...

Nov 24, 2025
CVE-2024-48747
6.8

This vulnerability in alist-tvbox v1.7.1 allows remote attackers to execute arbitrary commands on affected systems via the /atv-cli endpoint. This is ...

Nov 21, 2024
CVE-2025-62214
6.7

This command injection vulnerability in Visual Studio allows authenticated attackers to execute arbitrary code on the local system by injecting malici...

Nov 11, 2025
CVE-2024-48015
6.7

This CVE describes a command injection vulnerability in Dell SmartFabric OS10 Software that allows high-privileged attackers with local access to exec...

Mar 17, 2025
CVE-2026-22284
6.6

Dell SmartFabric OS10 Software contains a command injection vulnerability that allows authenticated high-privileged attackers to execute arbitrary com...

Feb 17, 2026
CVE-2025-65293
6.6

This CVE describes a command injection vulnerability in Aqara Camera Hub G3 devices that allows attackers to execute arbitrary commands with root priv...

Dec 10, 2025
CVE-2024-21903
6.6

This CVE describes an OS command injection vulnerability in QNAP operating systems that allows authenticated administrators to execute arbitrary comma...

Sep 6, 2024
CVE-2024-39569
6.6

This vulnerability allows an administrative remote attacker controlling a SINEMA Remote Connect Server to execute arbitrary code with system privilege...

Jul 9, 2024
CVE-2023-23355
6.6

This CVE describes an OS command injection vulnerability in QNAP operating systems that allows remote authenticated administrators to execute arbitrar...

Mar 29, 2023
CVE-2025-37176
6.5

A command injection vulnerability in AOS-8 allows authenticated privileged users to inject shell commands by manipulating package headers. This could ...

Jan 13, 2026
CVE-2025-66715
6.5

This DLL hijacking vulnerability in Axtion ODISSAAS ODIS v1.8.4 allows attackers to place a malicious DLL in a location where the application searches...

Jan 9, 2026
CVE-2025-61489
6.5

A command injection vulnerability in sonirico mcp-shell v0.3.1 allows attackers to execute arbitrary system commands by supplying malicious input to t...

Jan 7, 2026
CVE-2025-67436
6.5

CVE-2025-67436 is an authenticated remote code execution vulnerability in PluXml CMS 5.8.22. Attackers with administrator panel access can inject mali...

Dec 22, 2025
CVE-2025-55893
6.5

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK N200RE routers by injecting malicious input into the hostName par...

Dec 15, 2025
CVE-2025-55901
6.5

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK A3300R routers by injecting malicious input into the host_time pa...

Dec 15, 2025
CVE-2025-57200
6.5

This CVE describes an authenticated command injection vulnerability in AVTECH SECURITY Corporation's DGM1104 FullImg-1015-1004-1006-1003 firmware. Att...

Dec 3, 2025
CVE-2025-65657
6.5

CVE-2025-65657 is a remote code execution vulnerability in FeehiCMS version 2.1.1 that allows authenticated attackers to upload malicious PHP files th...

Dec 2, 2025
CVE-2025-37162
6.5

This vulnerability allows authenticated remote attackers to inject malicious commands through the device's command line interface, potentially executi...

Nov 18, 2025
CVE-2025-63749
6.5

CVE-2025-63749 is a command injection vulnerability in pnetlab 5.3.11 that allows attackers to execute arbitrary commands on the system by manipulatin...

Nov 18, 2025
CVE-2025-63258
6.5

A remote command execution vulnerability in H3C ERG3/ERG5 series routers, XiaoBei series routers, cloud gateways, and wireless access points allows at...

Nov 18, 2025
CVE-2025-63604
6.5

This CVE describes a remote code execution vulnerability in baryhuang/mcp-server-aws-resources-python version 0.1.0. Attackers can execute arbitrary P...

Nov 18, 2025
CVE-2025-60673
6.5

This CVE describes an unauthenticated command injection vulnerability in D-Link DIR-878A1 router firmware that allows remote attackers to execute arbi...

Nov 13, 2025
CVE-2025-60676
6.5

This vulnerability allows unauthenticated remote attackers to execute arbitrary commands on D-Link DIR-878A1 routers by exploiting a command injection...

Nov 13, 2025
CVE-2025-60701
6.5

This CVE describes a command injection vulnerability in D-Link DIR-882 router firmware that allows unauthenticated remote attackers to execute arbitra...

Nov 13, 2025
CVE-2025-60682
6.5

This CVE describes a command injection vulnerability in ToToLink A720R router firmware that allows unauthenticated remote attackers to execute arbitra...

Nov 13, 2025
CVE-2025-60683
EPSS 15% 6.5

This CVE describes a command injection vulnerability in ToToLink A720R router firmware that allows arbitrary command execution. Attackers with write a...

Nov 13, 2025
CVE-2025-60687
6.5

An unauthenticated command injection vulnerability in ToToLink LR1200GB routers allows attackers to execute arbitrary system commands by sending malic...

Nov 13, 2025
CVE-2025-63296
6.5

This vulnerability allows arbitrary code execution as root on KERUI K259 5MP Wi-Fi/Tuya Smart Security Cameras. During startup, the camera automatical...

Nov 10, 2025
CVE-2024-51317
6.5

A command injection vulnerability in NetSurf browser version 3.11 allows remote attackers to execute arbitrary code via the dom_node_normalize functio...

Nov 3, 2025
CVE-2025-56799
6.5

The Reolink desktop application version 8.18.12 contains a command injection vulnerability in its scheduled cache-clearing mechanism. An attacker coul...

Oct 21, 2025
CVE-2025-57164
6.5

CVE-2025-57164 allows remote code execution in Flowise AI platforms through unsanitized user input in the Supabase RPC Filter field. Attackers can exe...

Oct 17, 2025
CVE-2025-61514
6.5

An arbitrary file upload vulnerability in CoCalc allows attackers to upload malicious SVG files that can execute arbitrary code on the server. This af...

Oct 16, 2025
CVE-2025-60838
6.5

This vulnerability in MCMS v6.0.1 allows attackers to upload malicious files to the server, which can then be executed to run arbitrary code. This aff...

Oct 10, 2025

About Command Injection (CWE-77)

The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.

Our database tracks 1,188 CVEs classified as CWE-77, with 460 rated critical and 507 rated high severity. The average CVSS score for Command Injection vulnerabilities is 8.3.

External reference: View CWE-77 on MITRE CWE →

Monitor Command Injection Vulnerabilities

Get alerted when new Command Injection CVEs affect your infrastructure.

Start Monitoring Free