CWE-77

High likelihood

Improper Neutralization of Special Elements used in a Command ('Command Injection')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

3,629 vulnerabilities with CWE-77
CVE-2026-58635 HIGH
Microsoft Windows 10 Version 1809 - Windows Narrator Braille Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-50520 HIGH
Visual Studio Code Remote Code Execution Vulnerability
CVSS 8.4
CVE-2026-48561 CRITICAL
Microsoft Copilot Remote Code Execution Vulnerability
CVSS 9.6
CVE-2026-15669 MEDIUM
louisho5 picobot exec Tool exec.go ExecTool.Execute os command injection
CVSS 5.3
CVE-2026-22103 CRITICAL
EVbee DC-80 - Command Injection in NPC Start Web Endpoint
CVE-2026-22095 CRITICAL
EVbee DC-80 - Command Injection in Diagnosis Web Endpoint
CVE-2026-15547 MEDIUM
Shibby Tomato CIFS Mount sub_2D048 os command injection
CVSS 6.3
CVE-2026-15546 MEDIUM
Shibby Tomato start_jffs2 sub_2D568 os command injection
CVSS 6.3
CVE-2026-15513 MEDIUM
Wavlink WL-NU516U1 adm.cgi wlink_uci_set_value os command injection
CVSS 6.3
CVE-2026-15511 CRITICAL
Comfast CF-WR631AX V3 FastCGI Backend webmgnt system_wl_upload_pic_file os command injection
CVSS 9.8
CVE-2026-15496 MEDIUM
SonicCloudOrg sonic-agent Groovy Script GroovyScriptImpl.java evalIsFailed os command injection
CVSS 6.3
CVE-2026-15495 MEDIUM
SonicCloudOrg sonic-agent Android WebSocket Server AndroidWSServer.java os command injection
CVSS 6.3
CVE-2026-15487 MEDIUM
TRENDnet TEW-821DAP Firmware Update system_ntp sub_41FBD0 os command injection
CVSS 6.3
CVE-2026-15486 MEDIUM
TRENDnet TEW-821DAP Firmware Update tools_ddns sub_42026C os command injection
CVSS 6.3
CVE-2026-15485 MEDIUM
TRENDnet TEW-821DAP DNS Lookup tools_nslookup sub_43F2C4 os command injection
CVSS 6.3
CVE-2026-15481 HIGH
Trendnet TEW-635BRM IPoA WAN Connection Setup rc ipoa_test command injection
CVSS 8.8
CVE-2026-59721 HIGH
Hoppscotch: Admin RCE via MAILER_SMTP_URL nodemailer sendmail-transport injection
CVSS 7.2
CVE-2026-15193 MEDIUM
AidanPark openclaw-android Android WebView Bridge JsBridge.kt os command injection
CVSS 5.3
CVE-2026-15035 MEDIUM
bentoml OpenLLM Model Repository Directory Name common.py async_run_command command injection
CVSS 5.3
CVE-2026-15033 MEDIUM
christopherthielen check-peer-dependencies peerDependencies packageUtils.js shelljs.exec os command injection
CVSS 6.3
CVE-2026-14802 HIGH
react create-react-app react-dev-utils openBrowser.js startBrowserProcess os command injection
CVSS 7.3
CVE-2026-54402 CRITICAL
Ubiquiti INC UniFi OS Server - Improper Input Validation
CVSS 9.9
CVE-2026-9834 HIGH
WP Database Backup <= 7.11 - Authenticated (Administrator+) OS Command Injection via 'wp_db_exclude_table' Parameter
CVSS 7.2
CVE-2026-38142 MEDIUM
Tenda AC18 15.03.05.05 - Unauthenticated OS Command Injection via /goform/fast_setting_internet_set mac Parameter
CVSS 6.5
CVE-2026-13581 MEDIUM
Edimax EW-7478APC POST Request formStaDrvSetup os command injection
CVSS 6.3
Details
Vulnerabilities 3,629
Exploit Likelihood High