CWE-78: OS Command Injection

The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.

1,687
Total CVEs
629
Critical
888
High
8.5
Avg CVSS
11
In CISA KEV

Yearly Trend

2026
146
2025
465
2024
405
2023
253
2022
163

Top Affected Vendors

1 Dlink 89
2 Totolink 85
3 Dell 58
4 Fortinet 57
5 Tp Link 35
6 Zyxel 33
7 Ruijie 30
8 Cisco 28
9 Arubanetworks 27
10 Jvckenwood 26

All OS Command Injection CVEs (1,687)

CVE-2021-35402
10.0

This vulnerability allows remote attackers to execute arbitrary operating system commands on PROLiNK PRC2402M routers by injecting shell metacharacter...

Feb 20, 2026
CVE-2024-58338
10.0

Anevia Flamingo XL 3.2.9 contains a restricted shell escape vulnerability that allows remote attackers to bypass the sandboxed environment via the tra...

Dec 30, 2025
CVE-2025-64126
10.0

This critical OS command injection vulnerability allows unauthenticated attackers to execute arbitrary commands on affected systems by injecting malic...

Nov 26, 2025
CVE-2025-64127
10.0

This critical vulnerability allows unauthenticated remote attackers to execute arbitrary operating system commands on affected systems due to improper...

Nov 26, 2025
CVE-2025-64128
10.0

An OS command injection vulnerability (CWE-78) allows unauthenticated attackers to execute arbitrary commands on affected systems by injecting malicio...

Nov 26, 2025
CVE-2025-10230
10.0

This critical vulnerability in Samba allows unauthenticated remote attackers to execute arbitrary commands on affected systems by sending specially cr...

Nov 7, 2025
CVE-2025-9588
10.0

This critical OS command injection vulnerability in Iron Mountain Archiving Services EnVision allows attackers to execute arbitrary commands on the un...

Sep 23, 2025
CVE-2025-26389
10.0

This critical vulnerability allows unauthenticated remote attackers to execute arbitrary code with root privileges on affected OZW672 and OZW772 devic...

May 13, 2025
CVE-2021-47667
10.0

This CVE describes an unauthenticated remote OS command injection vulnerability in ZendTo file transfer software. Attackers can execute arbitrary comm...

Apr 5, 2025
CVE-2025-27364
10.0

This CVE describes a critical Remote Code Execution vulnerability in MITRE Caldera's agent compilation functionality. Attackers can execute arbitrary ...

Feb 24, 2025
CVE-2024-50603
KEV EPSS 94.4% 10.0

This is a critical command injection vulnerability in Aviatrix Controller that allows unauthenticated attackers to execute arbitrary operating system ...

Jan 8, 2025
CVE-2024-52034
10.0

CVE-2024-52034 is a critical OS command injection vulnerability in myPRO Manager that allows unauthenticated remote attackers to execute arbitrary ope...

Nov 22, 2024
CVE-2024-51378
10.0

This vulnerability allows remote attackers to bypass authentication and execute arbitrary commands on CyberPanel servers. Attackers can exploit unauth...

Oct 29, 2024
CVE-2024-51568
10.0

CVE-2024-51568 is a critical command injection vulnerability in CyberPanel that allows unauthenticated attackers to execute arbitrary commands on affe...

Oct 29, 2024
CVE-2024-45519
10.0

This critical vulnerability in Zimbra Collaboration's postjournal service allows unauthenticated attackers to execute arbitrary commands on affected s...

Oct 2, 2024
CVE-2024-7591
10.0

CVE-2024-7591 is an OS command injection vulnerability in Progress LoadMaster load balancers that allows attackers to execute arbitrary commands on th...

Sep 5, 2024
CVE-2024-24576
10.0

This critical vulnerability in Rust's standard library allows arbitrary command execution when spawning batch files on Windows with untrusted argument...

Apr 9, 2024
CVE-2024-2389
10.0

CVE-2024-2389 is a critical command injection vulnerability in Flowmon network monitoring software that allows unauthenticated attackers to execute ar...

Apr 2, 2024
CVE-2024-30247
10.0

CVE-2024-30247 is a critical command injection vulnerability in NextCloudPi that allows unauthenticated attackers to execute arbitrary commands as roo...

Mar 29, 2024
CVE-2024-1212
10.0

CVE-2024-1212 is a critical vulnerability in LoadMaster load balancers that allows unauthenticated remote attackers to execute arbitrary system comman...

Feb 21, 2024
CVE-2024-23108
10.0

This CVE describes an OS command injection vulnerability in Fortinet products that allows attackers to execute arbitrary commands via crafted API requ...

Feb 5, 2024
CVE-2023-3991
10.0

This CVE describes a critical OS command injection vulnerability in FreshTomato router firmware's iperfrun.cgi component. Attackers can execute arbitr...

Oct 16, 2023
CVE-2023-34992
10.0

This critical OS command injection vulnerability in Fortinet products allows attackers to execute arbitrary commands on affected systems by sending sp...

Oct 10, 2023
CVE-2023-3572
10.0

CVE-2023-3572 is a critical vulnerability in PHOENIX CONTACT WP 6xxx series web panels that allows remote, unauthenticated attackers to execute arbitr...

Aug 8, 2023
CVE-2023-2564
10.0

This CVE describes an OS command injection vulnerability in scanservjs web scanning software that allows attackers to execute arbitrary commands on th...

May 7, 2023
CVE-2023-2131
10.0

CVE-2023-2131 is a critical OS command injection vulnerability in INEA ME RTU firmware that allows remote attackers to execute arbitrary code on affec...

Apr 20, 2023
CVE-2022-31137
10.0

CVE-2022-31137 is a critical remote code execution vulnerability in Roxy-WI web interface that allows unauthenticated attackers to execute arbitrary s...

Jul 8, 2022
CVE-2022-24803
10.0

CVE-2022-24803 is a critical command injection vulnerability in Asciidoctor-include-ext that allows attackers to execute arbitrary system commands whe...

Apr 1, 2022
CVE-2022-24796
10.0

CVE-2022-24796 is a critical remote code execution vulnerability in RaspberryMatic's WebUI file upload feature. Unauthenticated attackers with network...

Mar 31, 2022
CVE-2021-27476
10.0

This vulnerability allows remote, unauthenticated attackers to execute arbitrary operating system commands on Rockwell Automation FactoryTalk AssetCen...

Mar 23, 2022
CVE-2021-43981
10.0

CVE-2021-43981 is a critical OS command injection vulnerability in mySCADA myPRO versions 8.20.0 and earlier. Attackers can execute arbitrary operatin...

Dec 23, 2021
CVE-2021-44453
10.0

CVE-2021-44453 is a critical command injection vulnerability in mySCADA myPRO's debug interface that allows attackers to execute arbitrary operating s...

Dec 23, 2021
CVE-2021-22657
10.0

This vulnerability allows remote attackers to execute arbitrary operating system commands on mySCADA myPRO systems by injecting malicious commands thr...

Dec 23, 2021
CVE-2021-33032
10.0

This vulnerability allows unauthenticated remote attackers to execute arbitrary system commands as root on affected HomeMatic CCU devices via a simple...

Jul 22, 2021
CVE-2021-33841
10.0

CVE-2021-33841 is a critical OS command injection vulnerability in the SGE-PLC1000 device's firmware, allowing remote attackers to execute arbitrary c...

Jun 9, 2021
CVE-2020-12522
10.0

This critical vulnerability allows remote attackers with network access to execute arbitrary operating system commands on affected WAGO industrial con...

Dec 17, 2020
CVE-2020-6364
10.0

CVE-2020-6364 is a critical OS command injection vulnerability in SAP Solution Manager and SAP Focused Run that allows attackers to execute arbitrary ...

Oct 15, 2020
CVE-2026-27965
9.9

This vulnerability allows attackers with read/write access to Vitess backup storage locations to manipulate backup manifest files, leading to arbitrar...

Feb 26, 2026
CVE-2026-27728
9.9

CVE-2026-27728 is an OS command injection vulnerability in OneUptime's NetworkPathMonitor.performTraceroute() function that allows authenticated proje...

Feb 25, 2026
CVE-2026-27626
9.9

CVE-2026-27626 allows authenticated users to execute arbitrary OS commands on OliveTin hosts by injecting shell metacharacters through password-type a...

Feb 25, 2026
CVE-2026-25763
9.9

OpenProject versions before 16.6.7 and 17.0.3 contain an arbitrary file write vulnerability that can lead to remote code execution. Attackers with rep...

Feb 6, 2026
CVE-2026-25053
9.9

This vulnerability in n8n workflow automation platform allows authenticated users with workflow creation/modification permissions to execute arbitrary...

Feb 4, 2026
CVE-2026-23515
9.9

Signal K Server versions before 1.5.0 contain a command injection vulnerability in the set-system-time plugin that allows authenticated users with wri...

Feb 2, 2026
CVE-2026-24841
9.9

CVE-2026-24841 is a critical command injection vulnerability in Dokploy, a self-hosted PaaS, allowing authenticated attackers to execute arbitrary com...

Jan 28, 2026
CVE-2026-22844
9.9

A command injection vulnerability in Zoom Node Multimedia Routers allows meeting participants to execute arbitrary commands on the MMR system via netw...

Jan 20, 2026
CVE-2025-59157
9.9

CVE-2025-59157 is a command injection vulnerability in Coolify's Git Repository field during project creation. Unauthenticated user input is not prope...

Jan 5, 2026
CVE-2025-66203
9.9

StreamVault versions before 251126 contain a remote code execution vulnerability that allows attackers to execute arbitrary commands on the server. Ad...

Dec 27, 2025
CVE-2025-66209
9.9

CVE-2025-66209 is an authenticated command injection vulnerability in Coolify's Database Backup functionality. It allows users with application/servic...

Dec 23, 2025
CVE-2025-67164
9.9

An authenticated arbitrary file upload vulnerability in Pagekit CMS v1.0.18 allows attackers to upload malicious PHP files and execute arbitrary code ...

Dec 17, 2025
CVE-2025-54469
9.9

This CVE describes a command injection vulnerability in NeuVector's enforcer container where environment variables CLUSTER_RPC_PORT and CLUSTER_LAN_PO...

Oct 30, 2025

About OS Command Injection (CWE-78)

The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.

Our database tracks 1,687 CVEs classified as CWE-78, with 629 rated critical and 888 rated high severity. The average CVSS score for OS Command Injection vulnerabilities is 8.5.

External reference: View CWE-78 on MITRE CWE →

Monitor OS Command Injection Vulnerabilities

Get alerted when new OS Command Injection CVEs affect your infrastructure.

Start Monitoring Free