CWE-77
High likelihoodImproper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
3,629 vulnerabilities with CWE-77
CVE-2026-58635
HIGH
Microsoft Windows 10 Version 1809 - Windows Narrator Braille Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-50520
HIGH
Visual Studio Code Remote Code Execution Vulnerability
CVSS 8.4
CVE-2026-48561
CRITICAL
Microsoft Copilot Remote Code Execution Vulnerability
CVSS 9.6
CVE-2026-15669
MEDIUM
louisho5 picobot exec Tool exec.go ExecTool.Execute os command injection
CVSS 5.3
CVE-2026-22103
CRITICAL
EVbee DC-80 - Command Injection in NPC Start Web Endpoint
CVE-2026-22095
CRITICAL
EVbee DC-80 - Command Injection in Diagnosis Web Endpoint
CVE-2026-15547
MEDIUM
Shibby Tomato CIFS Mount sub_2D048 os command injection
CVSS 6.3
CVE-2026-15546
MEDIUM
Shibby Tomato start_jffs2 sub_2D568 os command injection
CVSS 6.3
CVE-2026-15513
MEDIUM
Wavlink WL-NU516U1 adm.cgi wlink_uci_set_value os command injection
CVSS 6.3
CVE-2026-15511
CRITICAL
Comfast CF-WR631AX V3 FastCGI Backend webmgnt system_wl_upload_pic_file os command injection
CVSS 9.8
CVE-2026-15496
MEDIUM
SonicCloudOrg sonic-agent Groovy Script GroovyScriptImpl.java evalIsFailed os command injection
CVSS 6.3
CVE-2026-15495
MEDIUM
SonicCloudOrg sonic-agent Android WebSocket Server AndroidWSServer.java os command injection
CVSS 6.3
CVE-2026-15487
MEDIUM
TRENDnet TEW-821DAP Firmware Update system_ntp sub_41FBD0 os command injection
CVSS 6.3
CVE-2026-15486
MEDIUM
TRENDnet TEW-821DAP Firmware Update tools_ddns sub_42026C os command injection
CVSS 6.3
CVE-2026-15485
MEDIUM
TRENDnet TEW-821DAP DNS Lookup tools_nslookup sub_43F2C4 os command injection
CVSS 6.3
CVE-2026-15481
HIGH
Trendnet TEW-635BRM IPoA WAN Connection Setup rc ipoa_test command injection
CVSS 8.8
CVE-2026-59721
HIGH
Hoppscotch: Admin RCE via MAILER_SMTP_URL nodemailer sendmail-transport injection
CVSS 7.2
CVE-2026-15193
MEDIUM
AidanPark openclaw-android Android WebView Bridge JsBridge.kt os command injection
CVSS 5.3
CVE-2026-15035
MEDIUM
bentoml OpenLLM Model Repository Directory Name common.py async_run_command command injection
CVSS 5.3
CVE-2026-15033
MEDIUM
christopherthielen check-peer-dependencies peerDependencies packageUtils.js shelljs.exec os command injection
CVSS 6.3
CVE-2026-14802
HIGH
react create-react-app react-dev-utils openBrowser.js startBrowserProcess os command injection
CVSS 7.3
CVE-2026-54402
CRITICAL
Ubiquiti INC UniFi OS Server - Improper Input Validation
CVSS 9.9
CVE-2026-9834
HIGH
WP Database Backup <= 7.11 - Authenticated (Administrator+) OS Command Injection via 'wp_db_exclude_table' Parameter
CVSS 7.2
CVE-2026-38142
MEDIUM
Tenda AC18 15.03.05.05 - Unauthenticated OS Command Injection via /goform/fast_setting_internet_set mac Parameter
CVSS 6.5
CVE-2026-13581
MEDIUM
Edimax EW-7478APC POST Request formStaDrvSetup os command injection
CVSS 6.3
Details
Vulnerabilities
3,629
Exploit Likelihood
High