CWE-77: Command Injection

The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.

1,147
Total CVEs
443
Critical
482
High
8.3
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
82
2025
378
2024
247
2023
225
2022
77

Top Affected Vendors

1 Totolink 107
2 Dlink 78
3 Netgear 73
4 Tenda 35
5 Arubanetworks 32
6 Linksys 28
7 Microsoft 24
8 Qnap 18
9 Siemens 18
10 Wavlink 17

All Command Injection CVEs (1,147)

CVE-2024-55956
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary Bash or PowerShell commands on affected Cleo systems by exploiting the defaul...

Dec 13, 2024
CVE-2024-55547
9.8

This vulnerability allows remote attackers to execute arbitrary commands on ORing IAP-420 devices through SNMP objects in NET-SNMP. Attackers can inje...

Dec 10, 2024
CVE-2024-48860
9.8

This CVE describes an OS command injection vulnerability in QNAP QuRouter software that allows remote attackers to execute arbitrary commands on affec...

Nov 22, 2024
CVE-2024-11320
9.8

This vulnerability allows attackers to execute arbitrary commands on Pandora FMS servers by exploiting a command injection flaw in the LDAP authentica...

Nov 21, 2024
CVE-2024-28729
9.8

This vulnerability allows a local attacker to execute arbitrary code on affected D-Link 5G CPE devices via a crafted request. It affects DWR-2000M 5G ...

Nov 12, 2024
CVE-2024-51115
9.8

DCME-320 v7.4.12.90 contains a command injection vulnerability (CWE-77) that allows attackers to execute arbitrary commands on affected systems. This ...

Nov 5, 2024
CVE-2024-42509
9.8

This critical vulnerability allows unauthenticated attackers to execute arbitrary commands with privileged access on Aruba access points by sending sp...

Nov 5, 2024
CVE-2024-51255
9.8

CVE-2024-51255 is a command injection vulnerability in DrayTek Vigor3900 routers that allows attackers to execute arbitrary commands via the mainfunct...

Oct 31, 2024
CVE-2024-51259
9.8

This vulnerability allows remote attackers to execute arbitrary commands on DrayTek Vigor3900 routers by injecting malicious commands into the mainfun...

Oct 31, 2024
CVE-2024-48904
9.8

A critical command injection vulnerability in Trend Micro Cloud Edge allows unauthenticated remote attackers to execute arbitrary commands on affected...

Oct 22, 2024
CVE-2024-35285
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary commands on Mitel MiCollab systems running vulnerable NuPoint Messenger versi...

Oct 21, 2024
CVE-2024-48659
9.8

This vulnerability allows remote attackers to execute arbitrary code on DCME-320-L devices via the log_u_umount.php component. It affects all systems ...

Oct 21, 2024
CVE-2024-46256
9.8

This CVE describes a command injection vulnerability in NginxProxyManager's Let's Encrypt certificate request function. An attacker can execute arbitr...

Sep 27, 2024
CVE-2024-42505
9.8

This critical vulnerability allows unauthenticated attackers to execute arbitrary commands on Aruba access points by sending specially crafted packets...

Sep 25, 2024
CVE-2024-42507
9.8

This critical vulnerability allows unauthenticated attackers to execute arbitrary commands with privileged access on Aruba access points by sending ma...

Sep 25, 2024
CVE-2024-46048
9.8

CVE-2024-46048 is a command injection vulnerability in Tenda FH451 routers that allows remote attackers to execute arbitrary commands on the device. T...

Sep 13, 2024
CVE-2024-45824
9.8

CVE-2024-45824 is a critical remote code execution vulnerability affecting Rockwell Automation products. Attackers can chain path traversal, command i...

Sep 12, 2024
CVE-2024-44466
9.8

COMFAST CF-XR11 routers running firmware V2.7.2 have a command injection vulnerability in the web management interface. Attackers can send specially c...

Sep 11, 2024
CVE-2023-36103
9.8

This CVE describes a command injection vulnerability in Tenda AC15 routers that allows remote attackers to execute arbitrary commands via crafted POST...

Sep 10, 2024
CVE-2024-44410
9.8

This vulnerability allows remote attackers to execute arbitrary commands on D-Link DI-8300 routers via command injection in the upgrade_filter_asp fun...

Sep 9, 2024
CVE-2024-44401
9.8

This vulnerability allows remote attackers to execute arbitrary commands on D-Link DI-8100G routers via command injection in the upgrade_filter.asp fi...

Sep 6, 2024
CVE-2024-44400
9.8

This critical vulnerability in D-Link DI-8400 firmware version 16.07.26A1 allows remote attackers to execute arbitrary commands on affected devices. T...

Sep 4, 2024
CVE-2024-42905
9.8

This vulnerability allows remote attackers to execute arbitrary commands on Beijing Digital China Cloud Technology DCME-320 devices via the getVar fun...

Aug 28, 2024
CVE-2024-44381
9.8

This vulnerability allows remote attackers to execute arbitrary commands on D-Link DI-8004W routers through the jhttpd msp_info_htm function. Attacker...

Aug 23, 2024
CVE-2024-42947
9.8

This vulnerability allows attackers to execute arbitrary commands on Tenda FH1201 routers by sending a specially crafted HTTP request to the /goform/t...

Aug 15, 2024
CVE-2024-42360
9.8

CVE-2024-42360 is a command injection vulnerability in SequenceServer BLAST+ server software where improper input sanitization in HTTP endpoints allow...

Aug 14, 2024
CVE-2024-5914
9.8

CVE-2024-5914 is a critical command injection vulnerability in Palo Alto Networks Cortex XSOAR CommonScripts Pack that allows unauthenticated attacker...

Aug 14, 2024
CVE-2024-21878
9.8

This CVE describes a command injection vulnerability in Enphase IQ Gateway (formerly Envoy) devices that allows attackers to execute arbitrary operati...

Aug 12, 2024
CVE-2024-41319
9.8

This CVE describes a command injection vulnerability in TOTOLINK A6000R routers that allows attackers to execute arbitrary commands on the device via ...

Jul 23, 2024
CVE-2024-41316
9.8

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK A6000R routers by injecting malicious commands through the ifname...

Jul 22, 2024
CVE-2024-41318
9.8

This CVE describes a command injection vulnerability in TOTOLINK A6000R routers that allows attackers to execute arbitrary commands on the device. The...

Jul 22, 2024
CVE-2024-40110
9.8

CVE-2024-40110 is an unauthenticated remote code execution vulnerability in Sourcecodester Poultry Farm Management System v1.0. Attackers can execute ...

Jul 12, 2024
CVE-2024-39914
9.8

This vulnerability allows remote attackers to execute arbitrary commands on FOG Project servers via command injection in the filename parameter. It af...

Jul 12, 2024
CVE-2024-39028
9.8

This vulnerability in SeaCMS allows remote attackers to execute arbitrary code via the admin_ping.php file. It affects SeaCMS versions up to and inclu...

Jul 5, 2024
CVE-2024-4883
9.8

This vulnerability allows unauthenticated remote attackers to execute arbitrary code on WhatsUp Gold systems through the NmApi.exe component. Attacker...

Jun 25, 2024
CVE-2024-37385
9.8

This vulnerability allows remote command injection in Roundcube Webmail on Windows systems through the im_convert_path and im_identify_path parameters...

Jun 7, 2024
CVE-2024-36604
9.8

This vulnerability allows remote attackers to execute arbitrary commands with root privileges on Tenda O3V2 routers via a blind command injection in t...

Jun 4, 2024
CVE-2024-4267
9.8

This CVE describes a critical command injection vulnerability in the parisneo/lollms-webui's 'open_file' module. Attackers can exploit it by providing...

May 22, 2024
CVE-2024-4078
9.8

This vulnerability in parisneo/lollms allows remote attackers to execute arbitrary code by exploiting insufficient input sanitization in the /unInstal...

May 16, 2024
CVE-2024-32353
9.8

This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK X5000R routers by injecting malicious commands through the 'port'...

May 14, 2024
CVE-2024-33789
9.8

This CVE describes a command injection vulnerability in Linksys E5600 routers where an attacker can execute arbitrary commands via the ipurl parameter...

May 3, 2024
CVE-2024-33344
9.8

This vulnerability allows remote attackers to execute arbitrary commands on D-Link DIR-822+ routers via command injection in the firmware upload funct...

Apr 26, 2024
CVE-2024-22061
9.8

A heap overflow vulnerability in the WLInfoRailService component of Ivanti Avalanche allows remote unauthenticated attackers to execute arbitrary comm...

Apr 19, 2024
CVE-2024-3871
9.8

Delta Electronics DVW-W02W2-E2 devices have critical vulnerabilities in their web administration interface that allow remote unauthenticated attackers...

Apr 16, 2024
CVE-2024-3271
9.8

A command injection vulnerability in the run-llama/llama_index repository allows attackers to bypass security checks and execute arbitrary code on ser...

Apr 16, 2024
CVE-2024-3566
9.8

CVE-2024-3566 is a command injection vulnerability affecting Windows applications that use CreateProcess function with improper argument quoting. Atta...

Apr 10, 2024
CVE-2024-29864
9.8

CVE-2024-29864 is a command injection vulnerability in Distrobox that allows attackers to execute arbitrary code by injecting malicious commands into ...

Mar 21, 2024
CVE-2023-49959
9.8

This is a critical command injection vulnerability in Indo-Sol PROFINET-INspektor NT devices that allows remote attackers to execute arbitrary system ...

Feb 26, 2024
CVE-2024-25850
9.8

This CVE describes a command injection vulnerability in Netis WF2780 routers that allows attackers to execute arbitrary commands on the device by mani...

Feb 22, 2024
CVE-2023-24331
9.8

This CVE describes a command injection vulnerability in D-Link DIR-816 routers that allows attackers to execute arbitrary commands via the urlAdd para...

Feb 21, 2024

About Command Injection (CWE-77)

The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.

Our database tracks 1,147 CVEs classified as CWE-77, with 443 rated critical and 482 rated high severity. The average CVSS score for Command Injection vulnerabilities is 8.3.

External reference: View CWE-77 on MITRE CWE →

Monitor Command Injection Vulnerabilities

Get alerted when new Command Injection CVEs affect your infrastructure.

Start Monitoring Free