Skip to content
Noroxi

CWE-77 · 3,230 records

Improper Neutralization of Special Elements used in a Command ('Command Injection')

CVEs in this class

3,228 records

  • A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    sophos · web applianceApr 4, 2023

  • sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle que

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    php · phpMay 11, 2012

  • D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    dlink · dns-320l firmwareApr 3, 2024

  • Deserialization Vulnerability in GoAnywhere MFT's License Servlet

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    fortra · goanywhere managed file transferSep 18, 2025

  • (1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear WN604 before 3.3.3

    CriticalCVSS 9.8KEVWeaponizedEPSS 98%

    netgear · wnap320 firmwareApr 21, 2017

  • Aria Operations for Networks contains a command injection vulnerability.

    CriticalCVSS 9.8KEVWeaponizedEPSS 98%

    vmware · aria operations for networksJun 7, 2023

  • masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to exe

    CriticalCVSS 9.8KEVWeaponizedEPSS 97%

    al-enterprise · omnipcx enterprise communication serverSep 18, 2007

  • In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbit

    CriticalCVSS 9.8KEVWeaponizedEPSS 94%

    cleo · harmonyDec 13, 2024

  • A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an aut

    CriticalCVSS 9.1KEVWeaponizedEPSS 100%

    ivanti · connect secureJan 12, 2024

  • TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form o

    HighCVSS 8.8KEVWeaponizedEPSS 100%

    tp-link · archer ax21 firmwareMar 15, 2023

  • Command Injection Vulnerability in Remote Support(RS) & Privileged Remote Access (PRA)

    CriticalCVSS 9.8KEVWeaponizedEPSS 87%

    beyondtrust · privileged remote accessDec 17, 2024

  • The D-Link DIR-645 Wired/Wireless Router Rev.

    HighCVSS 8.8KEVWeaponizedEPSS 97%

    dlink · dir-645 firmwareFeb 23, 2015

  • Arbitrary Command Injection in Smartbedded MeteoBridge

    HighCVSS 8.7KEVWeaponizedEPSS 94%

    smartbedded · meteobridge vmMay 21, 2025

  • OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF

    CriticalCVSS 9.8KEVWeaponizedEPSS 77%

    progress · connection manager for objectscaleJun 4, 2026

  • HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1)

    CriticalCVSS 9.8KEVWeaponizedEPSS 75%

    hp · openview network node managerSep 2, 2005

  • D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wil

    CriticalCVSS 9.8KEVWeaponizedEPSS 64%

    dlink · dsl-2750b firmwareOct 19, 2022

  • DrayTek Vigor2960/Vigor300B Web Management Interface apmcfgupload os command injection

    MediumCVSS 6.9KEVWeaponizedEPSS 98%

    draytek · vigor300b firmwareDec 27, 2024

  • A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote

    HighCVSS 7.2KEVWeaponizedEPSS 88%

    dlink · dir-823x firmwareMar 25, 2025

  • An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices.

    HighCVSS 8.8KEVWeaponizedEPSS 54%

    dlink · dcs-4703e firmwareSep 2, 2020

  • A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Ex

    HighCVSS 8.8KEVWeaponizedEPSS 53%

    microsoft · internet explorerJan 8, 2019

  • On certain Ubiquiti devices, Command Injection exists via a GET request to stainfo.cgi (aka Show AP info) because the ifname variable is not

    CriticalCVSS 9.8KEVWeaponizedEPSS 39%

    ui · airosJun 11, 2019

  • CVE-2020-2509
    79This week

    Command Injection Vulnerability in QTS and QuTS hero

    CriticalCVSS 9.8KEVWeaponizedEPSS 34%

    qnap · qtsApr 17, 2021

  • CVE-2023-33538
    77This week

    TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerability via the component

    HighCVSS 8.8KEVWeaponizedEPSS 42%

    tp-link · tl-wr940n firmwareJun 7, 2023

  • CVE-2024-9380
    76This week

    An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker wit

    HighCVSS 7.2KEVWeaponizedEPSS 60%

    ivanti · endpoint manager cloud services applianceOct 8, 2024

  • CVE-2017-6327
    76This week

    The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution, which describes a situation whereby an ind

    HighCVSS 8.8KEVWeaponizedEPSS 36%

    symantec · message gatewayAug 11, 2017

All vulnerability classes