CWE-77: Command Injection

The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.

1,157
Total CVEs
445
Critical
490
High
8.3
Avg CVSS
1
In CISA KEV

Yearly Trend

2026
82
2025
378
2024
247
2023
225
2022
77

Top Affected Vendors

1 Totolink 107
2 Dlink 80
3 Netgear 73
4 Tenda 35
5 Arubanetworks 32
6 Linksys 28
7 Microsoft 24
8 Qnap 19
9 Siemens 18
10 Wavlink 17

All Command Injection CVEs (1,157)

CVE-2020-26907
9.6

This vulnerability allows unauthenticated attackers to execute arbitrary commands on affected NETGEAR WiFi systems. It affects RBK852, RBR850, and RBS...

Oct 9, 2020
CVE-2020-25067
9.6

This vulnerability allows unauthenticated attackers to execute arbitrary commands on NETGEAR R8300 routers by exploiting a command injection flaw. Att...

Sep 1, 2020
CVE-2025-46816
9.4

CVE-2025-46816 is a critical command injection vulnerability in goshs (SimpleHTTPServer written in Go) that allows unauthenticated remote attackers to...

May 6, 2025
CVE-2020-28435
9.4

CVE-2020-28435 is a command injection vulnerability in the ffmpeg-sdk npm package that allows attackers to execute arbitrary commands on affected syst...

Jul 25, 2022
CVE-2025-59252
9.3

This command injection vulnerability in Copilot allows unauthorized attackers to execute arbitrary commands on affected systems, potentially leading t...

Oct 9, 2025
CVE-2025-59272
9.3

This command injection vulnerability in Copilot allows unauthorized local attackers to execute arbitrary commands, potentially leading to information ...

Oct 9, 2025
CVE-2024-23346
9.3

CVE-2024-23346 is a critical remote code execution vulnerability in Pymatgen's JonesFaithfulTransformation.from_transformation_str() method that uses ...

Feb 21, 2024
CVE-2025-56425
9.1

This vulnerability allows authenticated remote attackers to inject arbitrary SMTP commands via crafted input to the /osrest/api/organization/sendmail ...

Jan 8, 2026
CVE-2025-67397
9.1

CVE-2025-67397 is a command injection vulnerability in Passy v1.6.3 that allows authenticated remote attackers to execute arbitrary commands on affect...

Jan 5, 2026
CVE-2025-54416
9.1

This vulnerability in tj-actions/branch-names GitHub Action allows arbitrary command execution in downstream workflows due to improper input sanitizat...

Jul 26, 2025
CVE-2025-46122
9.1

This vulnerability allows authenticated attackers to execute arbitrary commands as root on Ruckus Unleashed wireless controllers by exploiting insuffi...

Jul 21, 2025
CVE-2025-53104
9.1

A command injection vulnerability in gluestack-ui's GitHub Actions workflow allowed attackers to execute arbitrary shell commands on the Actions runne...

Jul 1, 2025
CVE-2024-54794
9.1

CVE-2024-54794 is a command injection vulnerability in SpagoBI 3.5.1 that allows attackers to execute arbitrary code through the script input feature....

Jan 21, 2025
CVE-2024-41783
9.1

This vulnerability in IBM Sterling Secure Proxy allows privileged users to execute arbitrary operating system commands through improper input validati...

Jan 19, 2025
CVE-2024-39782
9.1

This CVE describes multiple OS command injection vulnerabilities in the Wavlink AC3000 router's web interface. Authenticated attackers can execute arb...

Jan 14, 2025
CVE-2024-39762
9.1

This CVE describes multiple OS command injection vulnerabilities in the Wavlink AC3000 router's internet.cgi functionality. An authenticated attacker ...

Jan 14, 2025
CVE-2024-39764
9.1

This CVE describes multiple OS command injection vulnerabilities in Wavlink AC3000 routers that allow authenticated attackers to execute arbitrary com...

Jan 14, 2025
CVE-2024-39360
9.1

This vulnerability allows authenticated attackers to execute arbitrary operating system commands on Wavlink AC3000 routers through the nas.cgi interfa...

Jan 14, 2025
CVE-2024-39367
9.1

This CVE describes an authenticated OS command injection vulnerability in the Wavlink AC3000 router's firewall.cgi functionality. Attackers with valid...

Jan 14, 2025
CVE-2024-33439
9.1

This vulnerability allows authenticated remote attackers to execute arbitrary operating system commands on Kasda LinkSmart Router KW5515 devices via C...

Nov 20, 2024
CVE-2024-29292
9.1

This CVE describes multiple OS command injection vulnerabilities in Kasda LinkSmart Router KW6512 firmware. Authenticated remote attackers can execute...

Nov 20, 2024
CVE-2024-48145
9.1

A prompt injection vulnerability in Netangular Technologies ChatNet AI v1.0 allows attackers to bypass chat restrictions and exfiltrate all chat data,...

Oct 24, 2024
CVE-2024-40089
9.1

A command injection vulnerability in Vilo 5 Mesh WiFi System allows authenticated attackers to execute arbitrary shell commands by injecting them into...

Oct 21, 2024
CVE-2024-0005
9.1

This vulnerability allows remote attackers to execute arbitrary commands on FlashArray and FlashBlade Purity storage systems by sending specially craf...

Sep 23, 2024
CVE-2024-37023
9.1

This vulnerability allows authenticated remote attackers to execute arbitrary operating system commands on Vonets industrial WiFi bridge devices. Atta...

Aug 12, 2024
CVE-2024-37642
9.1

This vulnerability allows remote attackers to execute arbitrary commands on TRENDnet TEW-814DAP wireless access points by injecting malicious commands...

Jun 14, 2024
CVE-2024-34792
9.1

This CVE describes a command injection vulnerability in the Dextaz Ping WordPress plugin that allows attackers to execute arbitrary commands on the se...

Jun 4, 2024
CVE-2024-32025
9.1

CVE-2024-32025 is a command injection vulnerability in Kohya_ss's group_images_gui.py that allows attackers to execute arbitrary commands on the syste...

Apr 16, 2024
CVE-2024-32027
9.1

CVE-2024-32027 is a command injection vulnerability in Kohya_ss GUI for Stable Diffusion trainers. Attackers can execute arbitrary commands on affecte...

Apr 16, 2024
CVE-2024-32022
9.1

CVE-2024-32022 is a command injection vulnerability in Kohya_ss, a GUI for Stable Diffusion trainers. Attackers can execute arbitrary commands on affe...

Apr 16, 2024
CVE-2024-21887
9.1

This is a command injection vulnerability in Ivanti Connect Secure and Policy Secure gateways that allows authenticated administrators to execute arbi...

Jan 12, 2024
CVE-2023-36750
9.1

This vulnerability allows authenticated privileged remote attackers to execute arbitrary code with root privileges on affected RUGGEDCOM ROX devices. ...

Jul 11, 2023
CVE-2023-36752
9.1

This vulnerability allows authenticated privileged remote attackers to execute arbitrary code with root privileges on affected RUGGEDCOM ROX devices. ...

Jul 11, 2023
CVE-2023-36754
9.1

This vulnerability allows authenticated privileged remote attackers to execute arbitrary code with root privileges on affected Siemens RUGGEDCOM ROX d...

Jul 11, 2023
CVE-2021-4406
9.1

This vulnerability allows authenticated attackers to create alerts that trigger stored cross-site scripting (XSS) attacks, which can lead to remote co...

Jul 10, 2023
CVE-2023-28365
9.1

This vulnerability allows authenticated UniFi application administrators to execute arbitrary commands on the host system during backup restoration. I...

Jul 1, 2023
CVE-2020-24561
9.1

This command injection vulnerability in Trend Micro ServerProtect for Linux 3.0 allows authenticated attackers with admin/root console access to execu...

Sep 15, 2020
CVE-2025-59468
9.0

This vulnerability allows a Backup Administrator with legitimate credentials to execute arbitrary code as the postgres user by sending a malicious pas...

Jan 8, 2026
CVE-2025-59470
9.0

This vulnerability allows authenticated Backup Operators to execute arbitrary code as the postgres user by sending malicious interval or order paramet...

Jan 8, 2026
CVE-2024-2366
9.0

This CVE describes a remote code execution vulnerability in the parisneo/lollms-webui application. Attackers can exploit insufficient path sanitizatio...

May 16, 2024
CVE-2024-29385
9.0

CVE-2024-29385 is an unauthenticated remote code execution vulnerability in D-Link DIR-845L routers. Attackers can exploit the soapcgi_main function i...

Mar 22, 2024
CVE-2023-45025
9.0

This CVE describes an OS command injection vulnerability in multiple QNAP operating system versions that allows authenticated users to execute arbitra...

Feb 2, 2024
CVE-2024-23628
9.0

A command injection vulnerability in the Motorola MR2600 router's 'SaveStaticRouteIPv6Params' parameter allows authenticated remote attackers to execu...

Jan 26, 2024
CVE-2024-23626
9.0

A command injection vulnerability in the Motorola MR2600 router's SaveSysLogParams parameter allows authenticated remote attackers to execute arbitrar...

Jan 26, 2024
CVE-2023-23369
9.0

This OS command injection vulnerability in QNAP operating systems allows attackers to execute arbitrary commands on affected devices via network reque...

Nov 3, 2023
CVE-2026-21516
8.8

CVE-2026-21516 is a command injection vulnerability in GitHub Copilot that allows unauthorized attackers to execute arbitrary code over a network. Thi...

Feb 10, 2026
CVE-2026-25761
8.8

Super-linter GitHub Action versions 6.0.0 to 8.3.0 are vulnerable to command injection via specially crafted filenames containing shell command substi...

Feb 9, 2026
CVE-2026-24685
8.8

OpenProject versions before 16.6.6 and 17.0.2 have a command injection vulnerability that allows authenticated users with repository browsing permissi...

Jan 28, 2026
CVE-2026-1324
8.8

This CVE describes a remote command injection vulnerability in Sangfor Operation and Maintenance Management System's SSH Protocol Handler. Attackers c...

Jan 22, 2026
CVE-2026-21638
8.8

This vulnerability allows attackers within Wi-Fi range to execute arbitrary code on affected Ubiquiti airMAX devices by exploiting a flaw in the wirel...

Jan 8, 2026

About Command Injection (CWE-77)

The product constructs all or part of a command using externally-influenced input, but does not neutralize special elements that could modify the intended command.

Our database tracks 1,157 CVEs classified as CWE-77, with 445 rated critical and 490 rated high severity. The average CVSS score for Command Injection vulnerabilities is 8.3.

External reference: View CWE-77 on MITRE CWE →

Monitor Command Injection Vulnerabilities

Get alerted when new Command Injection CVEs affect your infrastructure.

Start Monitoring Free