CWE-77: Command Injection
The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.
Yearly Trend
Top Affected Vendors
All Command Injection CVEs (1,188)
This CVE describes a command injection vulnerability in TOTOLINK A6000R routers where an attacker can execute arbitrary commands via the devname param...
Jan 10, 2025This CVE describes a command injection vulnerability in TOTOLINK EX200 routers that allows attackers to execute arbitrary system commands via the 'uss...
Nov 21, 2024This critical vulnerability in Tenda AC1206 routers allows remote attackers to execute arbitrary commands via command injection in the ate_iwpriv_set/...
Oct 10, 2024This critical vulnerability allows remote attackers to execute arbitrary commands on affected D-Link NAS devices by injecting malicious input into the...
Aug 27, 2024This critical vulnerability allows remote attackers to execute arbitrary commands on affected D-Link NAS devices by injecting malicious input into the...
Aug 27, 2024This critical vulnerability allows remote attackers to execute arbitrary commands on affected D-Link NAS devices via command injection in the HTTP POS...
Aug 24, 2024This critical vulnerability allows remote attackers to execute arbitrary commands on affected D-Link NAS devices by exploiting a command injection fla...
Aug 24, 2024This critical vulnerability allows remote attackers to execute arbitrary commands on affected D-Link NAS devices by injecting malicious commands throu...
Aug 24, 2024This critical vulnerability in TOTOLINK X6000R routers allows remote attackers to execute arbitrary commands via command injection in the setSyslogCfg...
Aug 18, 2024This critical vulnerability in Tosei Online Store Management System allows remote attackers to execute arbitrary commands via command injection in the...
Aug 17, 2024This critical vulnerability allows remote attackers to execute arbitrary commands on affected D-Link NAS devices through command injection in the phot...
Aug 13, 2024This critical vulnerability in Vivotek IB8367A VVTK-0100b allows remote attackers to execute arbitrary commands via command injection in the upload_fi...
Aug 3, 2024This CVE describes a critical command injection vulnerability in TOTOLINK LR350 routers. Attackers can remotely execute arbitrary commands by manipula...
Jul 30, 2024An authenticated command injection vulnerability in AOS-10 GW and AOS-8 Controllers/Mobility Conductor allows attackers with physical access to execut...
Oct 14, 2025Bambu Studio versions 2.1.1.52 and earlier contain a vulnerability that allows local attackers to execute arbitrary code during application startup. T...
Oct 21, 2025This vulnerability allows attackers to create arbitrary files on Windows PaperCut NG/MF servers with Web Print enabled, potentially flooding disk spac...
Sep 26, 2024This vulnerability allows authenticated local attackers with administrative credentials to execute arbitrary commands as root on affected Cisco Unifie...
Jun 4, 2025CVE-2025-5525 is a critical command injection vulnerability in Jrohy trojan versions up to 2.15.3. Attackers can execute arbitrary operating system co...
Jun 3, 2025This vulnerability allows remote attackers to execute arbitrary commands on PCAN-Ethernet Gateway devices by injecting shell metacharacters in softwar...
Oct 1, 2024This CVE describes an image processing vulnerability in Apple operating systems where improper bounds checks could allow maliciously crafted images to...
Feb 11, 2026This CVE describes an SMTP injection vulnerability in JetBrains TeamCity that allows attackers to modify email content sent by the application. Attack...
Aug 20, 2025This critical vulnerability in D-Link DI-7300G+ routers allows remote attackers to execute arbitrary operating system commands by manipulating the Tim...
Jun 30, 2025A critical command injection vulnerability in Edimax IP cameras allows attackers to execute arbitrary commands on affected devices by manipulating the...
Aug 12, 2024A stored HTML injection vulnerability in Mealie 3.3.1 allows authenticated users to inject arbitrary HTML into recipe notes, which can lead to user in...
Feb 11, 2026This vulnerability allows attackers within Wi-Fi range to execute arbitrary code on affected Ubiquiti airMAX and airFiber devices by exploiting a flaw...
Jan 8, 2026A command injection vulnerability in D-Link DIR-823G router firmware allows attackers with write access to /var/system/linux_vlan_reinit to execute ar...
Nov 13, 2025An unauthenticated command injection vulnerability in Linksys E1200 v2 routers allows remote attackers to execute arbitrary commands on the device wit...
Nov 13, 2025CVE-2025-50817 is a disputed vulnerability in Python-Future 1.0.0 where the module automatically imports a file named test.py if present in accessible...
Aug 14, 2025CVE-2025-54393 is a static code injection vulnerability in Netwrix Directory Manager (formerly Imanami GroupID) that allows authenticated users to exe...
Aug 7, 2025This command injection vulnerability in Nexxt Solutions NCM-X1800 Mesh Router allows authenticated attackers to execute arbitrary commands as root via...
Jul 15, 2025An unauthenticated remote attacker can inject arbitrary commands into emails sent by Cisco Duo's self-service portal due to insufficient input validat...
May 21, 2025MRCMS v3.1.2 contains a server-side template injection vulnerability in DispatcherServlet.java that allows attackers to execute arbitrary code on the ...
Feb 21, 2025Dell CloudLink versions before 8.1.1 contain a command injection vulnerability that allows authenticated attackers to execute arbitrary commands on af...
Nov 5, 2025A command injection vulnerability in D-Link DSL-7740C routers allows attackers to execute arbitrary commands via crafted GET requests targeting the EX...
Aug 25, 2025This CVE describes a command injection vulnerability in neurobin shc versions up to 4.0.3. Attackers with local access can execute arbitrary operating...
Aug 20, 2025This vulnerability in neurobin shc up to version 4.0.3 allows local command injection through the filename handler component. Attackers with local acc...
Aug 19, 2025A HTML injection vulnerability in PHPGurukul Park Ticketing Management System v2.0 allows remote attackers to inject malicious HTML/JavaScript via the...
Apr 30, 2025A HTML injection vulnerability in PHPGurukul Park Ticketing Management System v2.0 allows remote attackers to inject malicious HTML/JavaScript via the...
Apr 30, 2025This command injection vulnerability in Fortinet FortiNAC allows attackers to execute arbitrary commands on affected systems via specially crafted req...
Mar 14, 2025This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of sparkshop by uploading a specially craf...
Feb 24, 2025This CVE describes a command injection vulnerability in WAVLINK WN551K1 routers where attackers can execute arbitrary commands via the IP parameter in...
Jun 24, 2024This CVE describes a command injection vulnerability in WAVLINK WN551K1 routers through the start_hour parameter of the nightled.cgi script. Attackers...
Jun 24, 2024This vulnerability allows local attackers to inject startup scripts via crafted .txt files in the Data directory on Nokia Symbian Belle devices runnin...
Dec 26, 2025This vulnerability allows unauthenticated attackers on the same local network to execute arbitrary system commands on Fanvil x210 V2 IP phones. Attack...
Dec 5, 2025CVE-2025-60855 is a firmware validation vulnerability in Reolink Video Doorbell WiFi DB_566128M5MP_W that allows attackers to bypass signature checks ...
Oct 16, 2025This vulnerability in Firefox and Thunderbird's 'copy as cURL' feature allows attackers to craft malicious commands with insufficient escaping of spec...
Apr 29, 2025SeaCMS v13.3 contains a remote code execution vulnerability in the admin_ip.php component that allows attackers to execute arbitrary code on affected ...
Feb 26, 2025SeaCMS v13.3 contains a remote code execution vulnerability in the admin_notify.php component that allows attackers to execute arbitrary code on affec...
Feb 26, 2025SeaCMS v13.3 contains a remote code execution vulnerability in admin_template.php that allows attackers to execute arbitrary code on affected systems....
Feb 26, 2025This CVE describes a command injection vulnerability in TOTOLINK A6000R routers that allows attackers to execute arbitrary commands via the opmode par...
Jan 10, 2025About Command Injection (CWE-77)
The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.
Our database tracks 1,188 CVEs classified as CWE-77, with 460 rated critical and 507 rated high severity. The average CVSS score for Command Injection vulnerabilities is 8.3.
External reference: View CWE-77 on MITRE CWE →
Monitor Command Injection Vulnerabilities
Get alerted when new Command Injection CVEs affect your infrastructure.
Start Monitoring Free