CWE-77: Command Injection
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
1,882 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-8037 — OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF
- CVE-2026-42271 — LiteLLM: Authenticated command execution via MCP stdio test endpoints
- CVE-2025-10035 — Deserialization Vulnerability in GoAnywhere MFT's License Servlet
- CVE-2024-9380 — An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authen
- CVE-2024-12987 — DrayTek Vigor2960/Vigor300B Web Management Interface apmcfgupload os command injection
- CVE-2025-4008 — Arbitrary Command Injection in Smartbedded MeteoBridge
- CVE-2024-10697 — Tenda AC6 API Endpoint WriteFacMac formWriteFacMac command injection
- CVE-2025-4653 — Remote Code Execution leads to Command Injection
- CVE-2025-54782 — @nestjs/devtools-integration's CSRF to Sandbox Escape Allows for RCE against JS Developers
- CVE-2026-47670 — DbGate Vulnerable to Authenticated Remote Code Execution via loadReader functionName code injection
- CVE-2025-15471 — TRENDnet TEW-713RE formFSrvX os command injection
- CVE-2024-20432 — Cisco Nexus Dashboard Fabric Controller Web UI Command Injection Vulnerability
- CVE-2026-4585 — Tiandy Easy7 Integrated Management Platform Configuration ImportSystemConfiguration.jsp os command injection
- CVE-2026-4170 — Topsec TopACM HTTP Request nmc_sync.php os command injection
- CVE-2026-4164 — Wavlink WL-WN578W2 POST Request wireless.cgi GuestWifi command injection
- CVE-2026-4163 — Wavlink WL-WN579A3 POST Request wireless.cgi GuestWifi command injection
- CVE-2026-3485 — D-Link DIR-868L SSDP Service sub_1BF84 os command injection
- CVE-2026-3301 — Totolink N300RH Web Management cstecgi.cgi setWebWlanIdx os command injection
- CVE-2026-22688 — WeKnora has Command Injection in MCP stdio test
- CVE-2025-15501 — Sangfor Operation and Maintenance Management System getCmd WriterHandle.getCmd os command injection
Recently published
- CVE-2026-78484 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-79945 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-78493 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-79741 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-79941 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains
- CVE-2026-84387 — A improper neutralization of special elements used in a command ('command injection') vulnerability in Fortinet FortiSan
- CVE-2026-86427 — LibreNMS before 26.8.0 Argument Injection via graph_title
- CVE-2026-86299 — Linksys RE7000 PingTest json.cgi platform_event_pingTest os command injection
- CVE-2026-86295 — D-Link DIR-895L udhcpcd serverpacket.c sendACK command injection
- CVE-2026-79698 — Advantech WISE-6610-NB Node-RED nodered_lib_apply command injection
- CVE-2026-79697 — Advantech WISE-6610-NB Basic Station Certificate-Deletion basicstation_apply command injection
- CVE-2026-86167 — Tenda HG10 Boa formgponConf os command injection
- CVE-2026-86152 — Tenda CP3 Kylin AutoAddWifi.cpp ThreadProc os command injection
- CVE-2026-86151 — Tenda CP3 Network Configuration Management system.c sub_2F77E8 os command injection
- CVE-2026-86149 — Tenda CP3 NetCheckPing.cpp os command injection
- CVE-2026-86148 — Tenda CP3 Kylin system.c SystemAsh os command injection
- CVE-2026-53932 — wnx/laravel-backup-restore: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') and Improper Neutralization of Special Elements used in a Command ('Command Injection')
- CVE-2026-85224 — D-Link DNS-320 ShareCenter File Sharing file_sharing.cgi os command injection
- CVE-2026-85223 — D-Link DNS-340L CGI dropbox.cgi os command injection
- CVE-2026-85222 — D-Link DNS-340L Add-On Center addon_center.cgi os command injection