Rosetta Intel
Datasets/KEV CatalogThreat Actors
Rosetta Lab ↗Blur Horizon LLC
Datasets

KEV Catalog

CISA, queryable

Known exploited vulnerabilities as a queryable table — by CVE, vendor or product.

1676 entries·352 Ransomware·Updated 2026-08-25

CWE-77 · Command injectionDefinition on MITRE ↗Clear

30 results

CVE-2026-8037
2026-08-07
Progress LoadMaster Command Injection Vulnerability
Progress

Progress LoadMaster contains a command injection vulnerability that allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints.

CWE-77 · Command injection
Refscommunity.progress.comBOD 26-04Forensics Triage Requirementsnvd.nist.gov
Federal remediation due 2026-08-10
CVE-2026-42271
2026-06-08
BerriAI LiteLLM Command Injection Vulnerability
BerriAI

BerriAI LiteLLM contains a command injection vulnerability that could allow any authenticated user, including holders of low-privilege internal-user keys, to run arbitrary commands on the host.

CWE-78 · OS command injectionCWE-77 · Command injection
RefsThis vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please seegithub.comnvd.nist.gov
Federal remediation due 2026-06-22
CVE-2025-29635
2026-04-24
D-Link DIR-823X Command Injection Vulnerability
D-Link

D-Link DIR-823X contains a command injection vulnerability that allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

CWE-77 · Command injection
Refssupportannouncement.us.dlink.comnvd.nist.gov
Federal remediation due 2026-05-08
CVE-2026-22719
2026-03-03
Broadcom VMware Aria Operations Command Injection Vulnerability
Broadcom

Broadcom VMware Aria Operations formerly known as vRealize Operations (vROps) contains a command injection vulnerability that allows an unauthenticated attacker to execute arbitrary commands, potentially leading to remote code execution during support‑assisted product migration.

CWE-77 · Command injection
Refssupport.broadcom.comknowledge.broadcom.comnvd.nist.gov
Federal remediation due 2026-03-24
CVE-2025-4008
2025-10-02
Smartbedded Meteobridge Command Injection Vulnerability
Smartbedded

Smartbedded Meteobridge contains a command injection vulnerability that could allow remote unauthenticated attackers to gain arbitrary command execution with elevated privileges (root) on affected devices.

CWE-306 · Missing authenticationCWE-77 · Command injection
Refsforum.meteohub.denvd.nist.gov
Federal remediation due 2025-10-23
CVE-2025-59689
2025-09-29
Libraesva Email Security Gateway Command Injection Vulnerability
Libraesva

Libraesva Email Security Gateway (ESG) contains a command injection vulnerability which allows command injection via a compressed e-mail attachment.

CWE-77 · Command injection
Refsdocs.libraesva.comnvd.nist.gov
Federal remediation due 2025-10-20
CVE-2025-10035
2025-09-29
Fortra GoAnywhere MFT Deserialization of Untrusted Data VulnerabilityRansomware
Fortra

Fortra GoAnywhere MFT contains a deserialization of untrusted data vulnerability allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection.

CWE-502 · Deserialization of untrusted dataCWE-77 · Command injection
Refsfortra.comnvd.nist.gov
Federal remediation due 2025-10-20
CVE-2020-25079
2025-08-05
D-Link DCS-2530L and DCS-2670L Command Injection Vulnerability
D-Link / DCS-2530L and DCS-2670L Devices

D-Link DCS-2530L and DCS-2670L devices contains a command injection vulnerability in the cgi-bin/ddns_enc.cgi. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

CWE-77 · Command injection
Refssupport.dlink.comsupportannouncement.us.dlink.comnvd.nist.gov
Federal remediation due 2025-08-26
CVE-2016-10033
2025-07-07
PHPMailer Command Injection Vulnerability
PHP

PHPMailer contains a command injection vulnerability because it fails to sanitize user-supplied input. Specifically, this issue affects the 'mail()' function of 'class.phpmailer.php' script. An attacker can exploit this issue to execute arbitrary code within the context of the application. Failed exploit attempts will result in a denial-of-service condition.

CWE-77 · Command injectionCWE-88
RefsThis vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please seegithub.comnvd.nist.gov
Federal remediation due 2025-07-28
CVE-2023-33538
2025-06-16
TP-Link Multiple Routers Command Injection Vulnerability
TP-Link

TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 contain a command injection vulnerability via the component /userRpm/WlanNetworkRpm. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

CWE-77 · Command injection
Refstp-link.comnvd.nist.gov
Federal remediation due 2025-07-07
CVE-2023-20118
2025-03-03
Cisco Small Business RV Series Routers Command Injection Vulnerability
Cisco

Multiple Cisco Small Business RV Series Routers contains a command injection vulnerability in the web-based management interface. Successful exploitation could allow an authenticated, remote attacker to gain root-level privileges and access unauthorized data.

CWE-77 · Command injection
Refssec.cloudapps.cisco.comnvd.nist.gov
Federal remediation due 2025-03-24
CVE-2024-12356
2024-12-19
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) Command Injection Vulnerability
BeyondTrust

BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain a command injection vulnerability, which can allow an unauthenticated attacker to inject commands that are run as a site user.

CWE-77 · Command injection
Refsbeyondtrust.comnvd.nist.gov
Federal remediation due 2024-12-27
CVE-2024-9474
2024-11-18
Palo Alto Networks PAN-OS Management Interface OS Command Injection VulnerabilityRansomware
Palo Alto Networks

Palo Alto Networks PAN-OS contains an OS command injection vulnerability that allows for privilege escalation through the web-based management interface for several PAN products, including firewalls and VPN concentrators.

CWE-77 · Command injection
Refssecurity.paloaltonetworks.comnvd.nist.gov
Federal remediation due 2024-12-09
CVE-2024-9380
2024-10-09
Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability
Ivanti

Ivanti Cloud Services Appliance (CSA) contains an OS command injection vulnerability in the administrative console which can allow an authenticated attacker with application admin privileges to pass commands to the underlying OS.

CWE-77 · Command injection
Refsforums.ivanti.comnvd.nist.gov
Federal remediation due 2024-10-30
CVE-2024-3400
2024-04-12
Palo Alto Networks PAN-OS Command Injection VulnerabilityRansomware
Palo Alto Networks

Palo Alto Networks PAN-OS GlobalProtect feature contains a command injection vulnerability that allows an unauthenticated attacker to execute commands with root privileges on the firewall.

CWE-20 · Improper input validationCWE-77 · Command injection
Refssecurity.paloaltonetworks.comnvd.nist.gov
Federal remediation due 2024-04-19
CVE-2024-3273
2024-04-11
D-Link Multiple NAS Devices Command Injection Vulnerability
D-Link

D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L contain a command injection vulnerability. When combined with CVE-2024-3272, this can lead to remote, unauthorized code execution.

CWE-77 · Command injection
Refssupportannouncement.us.dlink.comnvd.nist.gov
Federal remediation due 2024-05-02
CVE-2024-21887
2024-01-10
Ivanti Connect Secure and Policy Secure Command Injection VulnerabilityRansomware
Ivanti

Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure contain a command injection vulnerability in the web components of these products, which can allow an authenticated administrator to send crafted requests to execute code on affected appliances. This vulnerability can be leveraged in conjunction with CVE-2023-46805, an authenticated bypass issue.

CWE-77 · Command injection
RefsPlease apply mitigations per vendor instructions. For more information, please seenvd.nist.gov
Federal remediation due 2024-01-22
CVE-2016-20017
2024-01-08
D-Link DSL-2750B Devices Command Injection Vulnerability
D-Link

D-Link DSL-2750B devices contain a command injection vulnerability that allows remote, unauthenticated command injection via the login.cgi cli parameter.

CWE-77 · Command injection
Refssupportannouncement.us.dlink.comnvd.nist.gov
Federal remediation due 2024-01-29
CVE-2023-1671
2023-11-16
Sophos Web Appliance Command Injection Vulnerability
Sophos

Sophos Web Appliance contains a command injection vulnerability in the warn-proceed handler that allows for remote code execution.

CWE-77 · Command injection
Refssophos.comnvd.nist.gov
Federal remediation due 2023-12-07
CVE-2023-20887
2023-06-22
Vmware Aria Operations for Networks Command Injection Vulnerability
VMware

VMware Aria Operations for Networks (formerly vRealize Network Insight) contains a command injection vulnerability that allows a malicious actor with network access to perform an attack resulting in remote code execution.

CWE-77 · Command injection
Refsvmware.comnvd.nist.gov
Federal remediation due 2023-07-13
CVE-2023-1389
2023-05-01
TP-Link Archer AX-21 Command Injection Vulnerability
TP-Link / Archer AX21

TP-Link Archer AX-21 contains a command injection vulnerability that allows for remote code execution.

CWE-77 · Command injection
Refstp-link.comnvd.nist.gov
Federal remediation due 2023-05-22
CVE-2022-40765
2023-02-21
Mitel MiVoice Connect Command Injection VulnerabilityRansomware
Mitel

The Mitel Edge Gateway component of MiVoice Connect allows an authenticated attacker with internal network access to execute commands within the context of the system.

CWE-77 · Command injection
Refsmitel.comnvd.nist.gov
Federal remediation due 2023-03-14
CVE-2018-19949
2022-05-24
QNAP NAS File Station Command Injection VulnerabilityRansomware
QNAP / Network Attached Storage (NAS)

A command injection vulnerability affecting QNAP NAS File Station could allow remote attackers to run commands.

CWE-20 · Improper input validationCWE-77 · Command injectionCWE-78 · OS command injection
Refsnvd.nist.gov
Federal remediation due 2022-06-14
CVE-2016-6367
2022-05-24
Cisco Adaptive Security Appliance (ASA) CLI Remote Code Execution Vulnerability
Cisco

A vulnerability in the command-line interface (CLI) parser of Cisco ASA software could allow an authenticated, local attacker to create a denial-of-service (DoS) condition or potentially execute code.

CWE-77 · Command injection
Refsnvd.nist.gov
Federal remediation due 2022-06-14
CVE-2010-5330
2022-04-15
Ubiquiti AirOS Command Injection Vulnerability
Ubiquiti

Certain Ubiquiti devices contain a command injection vulnerability via a GET request to stainfo.cgi.

CWE-77 · Command injection
Refsnvd.nist.gov
Federal remediation due 2022-05-06
CVE-2020-2509
2022-04-11
QNAP Network-Attached Storage (NAS) Command Injection Vulnerability
QNAP

QNAP NAS devices contain a command injection vulnerability which could allow attackers to perform remote code execution.

CWE-77 · Command injectionCWE-78 · OS command injection
Refsnvd.nist.gov
Federal remediation due 2022-05-02
CVE-2016-1555
2022-03-25
NETGEAR Multiple WAP Devices Command Injection Vulnerability
NETGEAR / Wireless Access Point (WAP) Devices

Multiple NETGEAR Wireless Access Point devices allows unauthenticated web pages to pass form input directly to the command-line interface. Exploitation allows for arbitrary code execution.

CWE-77 · Command injection
Refsnvd.nist.gov
Federal remediation due 2022-04-15
CVE-2015-2051
2022-02-10
D-Link DIR-645 Router Remote Code Execution Vulnerability
D-Link

D-Link DIR-645 Wired/Wireless Router allows remote attackers to execute arbitrary commands via a GetDeviceSettings action to the HNAP interface.

CWE-77 · Command injection
Refsnvd.nist.gov
Federal remediation due 2022-08-10
CVE-2021-22899
2021-11-03
Ivanti Pulse Connect Secure Command Injection Vulnerability
Ivanti

Ivanti Pulse Connect Secure contains a command injection vulnerability that allows remote authenticated users to perform remote code execution via Windows File Resource Profiles.

CWE-77 · Command injection
RefsReference CISA's ED 21-03 (
Federal remediation due 2022-05-03
CVE-2019-0541
2021-11-03
Microsoft MSHTML Remote Code Execution Vulnerability
Microsoft

Microsoft MSHTML engine contains an improper input validation vulnerability that allows for remote code execution vulnerability.

CWE-77 · Command injection
Refsnvd.nist.gov
Federal remediation due 2022-05-03