CWE-77
High likelihoodImproper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
3,629 vulnerabilities with CWE-77
CVE-2026-13561
MEDIUM
Edimax EW-7478APC POST Request formiNICbasic os command injection
CVSS 6.3
CVE-2026-13560
MEDIUM
Edimax EW-7478APC POST Request formAccept os command injection
CVSS 6.3
CVE-2026-13545
HIGH
D-Link DCS-935L POST Parameter setconf.cgi sub_400E40 os command injection
CVSS 8.8
CVE-2026-13538
MEDIUM
Wavlink WL-NU516U1-A POST Parameter wireless.cgi sub_401D68 command injection
CVSS 6.3
CVE-2026-13501
MEDIUM
antlr ANTLR4 gofmt GoTarget.java GoTarget command injection
CVSS 5.3
CVE-2026-54090
HIGH
File Browser: Command Allowlist Bypass via Shell Metacharacter Injection
CVE-2026-57453
MEDIUM
Vim: PowerShell Command Injection via Unescaped Filename in zip.vim Extraction
CVSS 6.5
CVE-2026-52806
CRITICAL
Gogs: RCE via git rebase --exec argument injection in pull request merge
CVSS 9.9
CVE-2026-47242
MEDIUM
Net::IMAP: Command Injection via ID command argument
CVE-2026-47240
MEDIUM
Net::IMAP: Command Injection via non-synchronizing literal in "raw" argument
CVE-2026-12815
MEDIUM
coollabsio coolify Image Name os command injection
CVSS 6.3
CVE-2026-12814
MEDIUM
Comfast CF-WR631AX V3 API Endpoint mbox-config system os command injection
CVSS 6.3
CVE-2026-12810
MEDIUM
Edimax BR-6478AC V2 POST Request mp command injection
CVSS 6.3
CVE-2026-12809
MEDIUM
Edimax BR-6478AC V2 POST Request wiz_5in1_redirect command injection
CVSS 6.3
CVE-2026-12808
MEDIUM
Edimax BR-6478AC V2 POST Request stainfo command injection
CVSS 6.3
CVE-2026-12807
MEDIUM
Edimax BR-6478AC V2 POST Request setWAN command injection
CVSS 6.3
CVE-2026-42895
MEDIUM
Microsoft Copilot Tampering Vulnerability
CVSS 6.5
CVE-2026-12045
CRITICAL
pgAdmin 4: AI Assistant read-only transaction bypass allows unauthorised writes and remote code execution
CVSS 9.0
CVE-2026-38717
CRITICAL
InHand Networks IR912 and IR915 <= V1.0.0.r20042 - Remote Command Execution via File Upload Function
CVSS 9.8
CVE-2026-38716
CRITICAL
InHand Networks IR912 and IR915 <= V1.0.0.r20042 - Remote Code Execution via Python Application Export Function
CVSS 9.8
CVE-2026-38715
CRITICAL
InHand Networks IR912 and IR915 <= V1.0.0.r20042 - Remote Code Execution via Log Viewing Function
CVSS 9.8
CVE-2026-38714
CRITICAL
InHand Networks IR912 and IR915 <= V1.0.0.r20042 - Remote Command Execution via Python Configuration Function
CVSS 9.8
CVE-2026-12223
MEDIUM
Yealink SIP-T46U Web FastCGI Service tftpuploadiperf mod_webd.TFTPUploadIperf command injection
CVSS 5.5
CVE-2026-12219
MEDIUM
Yealink SIP-T46U Web FastCGI Service start mod_diagnose.CommandShellByType command injection
CVSS 6.3
CVE-2026-12197
HIGH
Ruijie EG105G-P JSON-RPC Diagnose Endpoint diagnose nslookup command injection
CVSS 7.2
Details
Vulnerabilities
3,629
Exploit Likelihood
High