CWE-77 · 3,230 records
Improper Neutralization of Special Elements used in a Command ('Command Injection')
CVEs in this class
3,228 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2023-1671Weaponized | A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution sophos · web appliance · CWE-77 | Critical9.8 | KEV | 100.0% | Apr 4, 2023 |
99Now | CVE-2012-1823Weaponized | sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle quephp · php · CWE-77 | Critical9.8 | KEV | 100.0% | May 11, 2012 |
99Now | CVE-2024-3273Weaponized | D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injectiondlink · dns-320l firmware · CWE-77 | Critical9.8 | KEV | 100.0% | Apr 3, 2024 |
99Now | CVE-2025-10035Weaponized | Deserialization Vulnerability in GoAnywhere MFT's License Servletfortra · goanywhere managed file transfer · CWE-77 | Critical9.8 | KEV | 99.8% | Sep 18, 2025 |
98Now | CVE-2016-1555Weaponized | (1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear WN604 before 3.3.3 netgear · wnap320 firmware · CWE-77 | Critical9.8 | KEV | 98.3% | Apr 21, 2017 |
98Now | CVE-2023-20887Weaponized | Aria Operations for Networks contains a command injection vulnerability.vmware · aria operations for networks · CWE-77 | Critical9.8 | KEV | 98.3% | Jun 7, 2023 |
98Now | CVE-2007-3010Weaponized | masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to exeal-enterprise · omnipcx enterprise communication server · CWE-77 | Critical9.8 | KEV | 97.4% | Sep 18, 2007 |
97Now | CVE-2024-55956Weaponized | In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbitcleo · harmony · CWE-77 | Critical9.8 | KEV | 94.0% | Dec 13, 2024 |
96Now | CVE-2024-21887Weaponized | A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an autivanti · connect secure · CWE-77 | Critical9.1 | KEV | 100.0% | Jan 12, 2024 |
95Now | CVE-2023-1389Weaponized | TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form otp-link · archer ax21 firmware · CWE-77 | High8.8 | KEV | 100.0% | Mar 15, 2023 |
95Now | CVE-2024-12356Weaponized | Command Injection Vulnerability in Remote Support(RS) & Privileged Remote Access (PRA)beyondtrust · privileged remote access · CWE-77 | Critical9.8 | KEV | 87.3% | Dec 17, 2024 |
94Now | CVE-2015-2051Weaponized | The D-Link DIR-645 Wired/Wireless Router Rev.dlink · dir-645 firmware · CWE-77 | High8.8 | KEV | 97.1% | Feb 23, 2015 |
92Now | CVE-2025-4008Weaponized | Arbitrary Command Injection in Smartbedded MeteoBridgesmartbedded · meteobridge vm · CWE-77 | High8.7 | KEV | 93.7% | May 21, 2025 |
92Now | CVE-2026-8037Weaponized | OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAFprogress · connection manager for objectscale · CWE-77 | Critical9.8 | KEV | 77.4% | Jun 4, 2026 |
91Now | CVE-2005-2773Weaponized | HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) hp · openview network node manager · CWE-77 | Critical9.8 | KEV | 74.6% | Sep 2, 2005 |
88Now | CVE-2016-20017Weaponized | D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wildlink · dsl-2750b firmware · CWE-77 | Critical9.8 | KEV | 64.2% | Oct 19, 2022 |
86Now | CVE-2024-12987Weaponized | DrayTek Vigor2960/Vigor300B Web Management Interface apmcfgupload os command injectiondraytek · vigor300b firmware · CWE-77 | Medium6.9 | KEV | 98.1% | Dec 27, 2024 |
84Now | CVE-2025-29635Weaponized | A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remotedlink · dir-823x firmware · CWE-77 | High7.2 | KEV | 87.9% | Mar 25, 2025 |
81Now | CVE-2020-25079Weaponized | An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices.dlink · dcs-4703e firmware · CWE-77 | High8.8 | KEV | 54.0% | Sep 2, 2020 |
81Now | CVE-2019-0541Weaponized | A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Exmicrosoft · internet explorer · CWE-77 | High8.8 | KEV | 53.2% | Jan 8, 2019 |
81Now | CVE-2010-5330Weaponized | On certain Ubiquiti devices, Command Injection exists via a GET request to stainfo.cgi (aka Show AP info) because the ifname variable is notui · airos · CWE-77 | Critical9.8 | KEV | 39.4% | Jun 11, 2019 |
79This week | CVE-2020-2509Weaponized | Command Injection Vulnerability in QTS and QuTS heroqnap · qts · CWE-77 | Critical9.8 | KEV | 34.0% | Apr 17, 2021 |
77This week | CVE-2023-33538Weaponized | TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerability via the componenttp-link · tl-wr940n firmware · CWE-77 | High8.8 | KEV | 41.6% | Jun 7, 2023 |
76This week | CVE-2024-9380Weaponized | An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker witivanti · endpoint manager cloud services appliance · CWE-77 | High7.2 | KEV | 59.7% | Oct 8, 2024 |
76This week | CVE-2017-6327Weaponized | The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution, which describes a situation whereby an indsymantec · message gateway · CWE-77 | High8.8 | KEV | 35.9% | Aug 11, 2017 |
- CVE-2023-167199Now
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution
CriticalCVSS 9.8KEVWeaponizedEPSS 100%sophos · web applianceApr 4, 2023
- CVE-2012-182399Now
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle que
CriticalCVSS 9.8KEVWeaponizedEPSS 100%php · phpMay 11, 2012
- CVE-2024-327399Now
D-Link DNS-320L/DNS-325/DNS-327L/DNS-340L HTTP GET Request nas_sharing.cgi command injection
CriticalCVSS 9.8KEVWeaponizedEPSS 100%dlink · dns-320l firmwareApr 3, 2024
- CVE-2025-1003599Now
Deserialization Vulnerability in GoAnywhere MFT's License Servlet
CriticalCVSS 9.8KEVWeaponizedEPSS 100%fortra · goanywhere managed file transferSep 18, 2025
- CVE-2016-155598Now
(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear WN604 before 3.3.3
CriticalCVSS 9.8KEVWeaponizedEPSS 98%netgear · wnap320 firmwareApr 21, 2017
- CVE-2023-2088798Now
Aria Operations for Networks contains a command injection vulnerability.
CriticalCVSS 9.8KEVWeaponizedEPSS 98%vmware · aria operations for networksJun 7, 2023
- CVE-2007-301098Now
masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to exe
CriticalCVSS 9.8KEVWeaponizedEPSS 97%al-enterprise · omnipcx enterprise communication serverSep 18, 2007
- CVE-2024-5595697Now
In Cleo Harmony before 5.8.0.24, VLTrader before 5.8.0.24, and LexiCom before 5.8.0.24, an unauthenticated user can import and execute arbit
CriticalCVSS 9.8KEVWeaponizedEPSS 94%cleo · harmonyDec 13, 2024
- CVE-2024-2188796Now
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an aut
CriticalCVSS 9.1KEVWeaponizedEPSS 100%ivanti · connect secureJan 12, 2024
- CVE-2023-138995Now
TP-Link Archer AX21 (AX1800) firmware versions before 1.1.4 Build 20230219 contained a command injection vulnerability in the country form o
HighCVSS 8.8KEVWeaponizedEPSS 100%tp-link · archer ax21 firmwareMar 15, 2023
- CVE-2024-1235695Now
Command Injection Vulnerability in Remote Support(RS) & Privileged Remote Access (PRA)
CriticalCVSS 9.8KEVWeaponizedEPSS 87%beyondtrust · privileged remote accessDec 17, 2024
- CVE-2015-205194Now
The D-Link DIR-645 Wired/Wireless Router Rev.
HighCVSS 8.8KEVWeaponizedEPSS 97%dlink · dir-645 firmwareFeb 23, 2015
- CVE-2025-400892Now
Arbitrary Command Injection in Smartbedded MeteoBridge
HighCVSS 8.7KEVWeaponizedEPSS 94%smartbedded · meteobridge vmMay 21, 2025
- CVE-2026-803792Now
OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF
CriticalCVSS 9.8KEVWeaponizedEPSS 77%progress · connection manager for objectscaleJun 4, 2026
- CVE-2005-277391Now
HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1)
CriticalCVSS 9.8KEVWeaponizedEPSS 75%hp · openview network node managerSep 2, 2005
- CVE-2016-2001788Now
D-Link DSL-2750B devices before 1.05 allow remote unauthenticated command injection via the login.cgi cli parameter, as exploited in the wil
CriticalCVSS 9.8KEVWeaponizedEPSS 64%dlink · dsl-2750b firmwareOct 19, 2022
- CVE-2024-1298786Now
DrayTek Vigor2960/Vigor300B Web Management Interface apmcfgupload os command injection
MediumCVSS 6.9KEVWeaponizedEPSS 98%draytek · vigor300b firmwareDec 27, 2024
- CVE-2025-2963584Now
A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote
HighCVSS 7.2KEVWeaponizedEPSS 88%dlink · dir-823x firmwareMar 25, 2025
- CVE-2020-2507981Now
An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices.
HighCVSS 8.8KEVWeaponizedEPSS 54%dlink · dcs-4703e firmwareSep 2, 2020
- CVE-2019-054181Now
A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Ex
HighCVSS 8.8KEVWeaponizedEPSS 53%microsoft · internet explorerJan 8, 2019
- CVE-2010-533081Now
On certain Ubiquiti devices, Command Injection exists via a GET request to stainfo.cgi (aka Show AP info) because the ifname variable is not
CriticalCVSS 9.8KEVWeaponizedEPSS 39%ui · airosJun 11, 2019
- CVE-2020-250979This week
Command Injection Vulnerability in QTS and QuTS hero
CriticalCVSS 9.8KEVWeaponizedEPSS 34%qnap · qtsApr 17, 2021
- CVE-2023-3353877This week
TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection vulnerability via the component
HighCVSS 8.8KEVWeaponizedEPSS 42%tp-link · tl-wr940n firmwareJun 7, 2023
- CVE-2024-938076This week
An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker wit
HighCVSS 7.2KEVWeaponizedEPSS 60%ivanti · endpoint manager cloud services applianceOct 8, 2024
- CVE-2017-632776This week
The Symantec Messaging Gateway before 10.6.3-267 can encounter an issue of remote code execution, which describes a situation whereby an ind
HighCVSS 8.8KEVWeaponizedEPSS 36%symantec · message gatewayAug 11, 2017