CWE-77
High likelihoodImproper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
3,553 vulnerabilities with CWE-77
CVE-2026-3696
HIGH
Totolink N300RH 6..1c.1353_B20190305 - Command Injection
CVSS 7.3
CVE-2026-3680
MEDIUM
RyuzakiShinji biome-mcp-server <=1.0.0 - Command Injection
CVSS 6.3
CVE-2026-3662
MEDIUM
Wavlink WL-NU516U1 240425 - Command Injection
CVSS 4.7
CVE-2026-3661
MEDIUM
Wavlink WL-NU516U1 240425 - Command Injection
CVSS 4.7
CVE-2026-3612
HIGH
Wavlink WL-NU516U1 V240425 - Command Injection
CVSS 7.2
CVE-2026-3485
CRITICAL
D-Link DIR-868L 110b03 - Command Injection
CVSS 9.8
CVE-2026-3484
MEDIUM
PhialsBasement nmap-mcp-server - Command Injection
CVSS 6.3
CVE-2026-2256
MEDIUM
ModelScope ms-agent <v1.6.0rc1 - Command Injection
CVSS 6.5
CVE-2026-3301
CRITICAL
Totolink N300RH 6.1c.1353_B20190305 - Command Injection
CVSS 9.8
CVE-2026-22719
HIGH
KEV
VMware Aria Operations - Command Injection
CVSS 8.1
CVE-2026-3102
MEDIUM
exiftool <=13.49 - Command Injection
CVSS 6.3
CVE-2026-3101
MEDIUM
Intelbras TIP 635G 1.12.3.5 - Command Injection
CVSS 6.3
CVE-2026-3066
MEDIUM
HummerRisk <1.5.0 - Command Injection
CVSS 6.3
CVE-2026-3065
MEDIUM
HummerRisk <1.5.0 - Command Injection
CVSS 6.3
CVE-2026-3064
MEDIUM
HummerRisk <1.5.0 - Command Injection
CVSS 6.3
CVE-2026-3040
MEDIUM
DrayTek Vigor 300B <=1.5.1.6 - Command Injection
CVSS 4.7
CVE-2026-2956
MEDIUM
qinming99 dst-admin <=1.5.0 - Command Injection
CVSS 6.3
CVE-2026-2952
HIGH
Vaelsys 4.1.0 - OS Command Injection via xajaxargs Parameter
CVSS 7.3
CVE-2026-2944
HIGH
Tosei Online Store Management System 1.01 - Command Injection
CVSS 7.3
CVE-2026-2333
CRITICAL
Owl opds 2.2.0.4 - Command Injection
CVSS 9.8
CVE-2026-26093
CRITICAL
Owl opds 2.2.0.4 - Command Injection
CVSS 9.8
CVE-2026-2847
HIGH
UTT HiPER 520 1.7.7-160105 - Command Injection
CVSS 7.2
CVE-2026-2846
HIGH
UTT HiPER 520 1.7.7-160105 - Command Injection
CVSS 7.2
CVE-2026-20761
HIGH
EnOcean SmartServer IoT <4.60.009 - Command Injection
CVSS 8.1
CVE-2026-2824
MEDIUM
Comfast CF-E7 2.6.0.9 - Command Injection
CVSS 6.3
Details
Vulnerabilities
3,553
Exploit Likelihood
High