CWE-78: OS Command Injection

The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.

1,699
Total CVEs
635
Critical
894
High
8.5
Avg CVSS
11
In CISA KEV

Yearly Trend

2026
146
2025
465
2024
405
2023
253
2022
163

Top Affected Vendors

1 Dlink 89
2 Totolink 85
3 Fortinet 58
4 Dell 58
5 Tp Link 36
6 Zyxel 33
7 Ruijie 30
8 Cisco 28
9 Arubanetworks 27
10 Jvckenwood 26

All OS Command Injection CVEs (1,699)

CVE-2021-22502
9.8

CVE-2021-22502 is an unauthenticated command injection vulnerability in Micro Focus Operation Bridge Reporter (OBR) that allows remote attackers to ex...

Feb 8, 2021
CVE-2020-7786
9.8

CVE-2020-7786 is a critical OS command injection vulnerability in the macfromip npm package. It allows attackers to execute arbitrary commands on syst...

Feb 8, 2021
CVE-2020-7782
9.8

CVE-2020-7782 is an OS command injection vulnerability in the spritesheet-js package that allows attackers to execute arbitrary commands on the host s...

Feb 8, 2021
CVE-2021-26541
9.8

CVE-2021-26541 is a command injection vulnerability in the gitlog npm package that allows attackers to execute arbitrary commands on the host system. ...

Feb 8, 2021
CVE-2020-11920
9.8

This CVE describes a command injection vulnerability in the Svakom Siime Eye device's web interface. Attackers can inject shell commands via the NFS s...

Feb 8, 2021
CVE-2021-3122
9.8

CVE-2021-3122 is a critical remote code execution vulnerability in NCR Command Center Agent (CMCAgent) on Aloha POS/BOH servers. It allows unauthentic...

Feb 7, 2021
CVE-2020-7775
9.8

CVE-2020-7775 is a critical OS command injection vulnerability in the freediskspace npm package. Attackers can execute arbitrary commands on affected ...

Feb 2, 2021
CVE-2020-25506
9.8

This vulnerability allows remote attackers to execute arbitrary commands on D-Link DNS-320 network storage devices by injecting malicious commands thr...

Feb 2, 2021
CVE-2021-23330
9.8

CVE-2021-23330 is a command injection vulnerability in the launchpad npm package that allows attackers to execute arbitrary commands on the host syste...

Feb 1, 2021
CVE-2013-2512
9.8

This vulnerability in the Ruby ftpd gem allows remote attackers to execute arbitrary operating system commands by injecting shell metacharacters in LI...

Jan 26, 2021
CVE-2020-35458
9.8

CVE-2020-35458 is a critical remote code execution vulnerability in ClusterLabs Hawk web interface versions 2.x through 2.3.0-x. Unauthenticated attac...

Jan 12, 2021
CVE-2020-7784
9.8

CVE-2020-7784 is a command injection vulnerability in the ts-process-promises npm package that allows attackers to execute arbitrary commands on the h...

Jan 8, 2021
CVE-2021-3029
9.8

CVE-2021-3029 is a critical OS command injection vulnerability in EVOLUCARE ECSIMAGING software that allows attackers to execute arbitrary commands wi...

Jan 7, 2021
CVE-2020-36178
9.8

This CVE allows remote attackers to execute arbitrary operating system commands on TP-Link TL-WR840N routers by injecting malicious commands into an I...

Jan 6, 2021
CVE-2020-35729
9.8

CVE-2020-35729 is a critical OS command injection vulnerability in KLog Server 2.4.1 that allows attackers to execute arbitrary commands on the server...

Dec 27, 2020
CVE-2020-35665
9.8

CVE-2020-35665 is an unauthenticated remote code execution vulnerability in TerraMaster TOS. Attackers can execute arbitrary commands on affected syst...

Dec 23, 2020
CVE-2020-25494
9.8

This vulnerability allows remote attackers to execute arbitrary operating system commands on Xinuos (formerly SCO) Openserver systems via shell metach...

Dec 18, 2020
CVE-2020-7781
9.8

CVE-2020-7781 is an OS command injection vulnerability in the connection-tester npm package that allows attackers to execute arbitrary commands on the...

Dec 16, 2020
CVE-2020-35476
9.8

This vulnerability allows remote attackers to execute arbitrary commands on OpenTSDB servers by injecting malicious code into the yrange parameter. At...

Dec 16, 2020
CVE-2020-20184
9.8

CVE-2020-20184 is a critical remote code execution vulnerability in GateOne web-based terminal emulator. Attackers can execute arbitrary commands by i...

Dec 14, 2020
CVE-2020-28439
9.8

CVE-2020-28439 is a critical OS command injection vulnerability in the corenlp-js-prefab npm package that allows attackers to execute arbitrary comman...

Dec 11, 2020
CVE-2020-15357
9.8

This vulnerability allows remote attackers to execute arbitrary commands on Askey AP5100W Dual-SIG WiFi mesh access points by injecting shell metachar...

Dec 11, 2020
CVE-2020-29311
9.8

CVE-2020-29311 is a critical remote command execution vulnerability in Ubilling v1.0.9 that allows attackers to execute arbitrary commands as the root...

Dec 10, 2020
CVE-2020-19527
9.8

CVE-2020-19527 is a critical OS command injection vulnerability in iCMS 7.0.14 that allows attackers to execute arbitrary commands on the server by in...

Dec 10, 2020
CVE-2020-29390
9.8

CVE-2020-29390 is a critical command injection vulnerability in Zeroshell 3.9.3 that allows unauthenticated attackers to execute arbitrary system comm...

Nov 30, 2020
CVE-2020-29381
9.8

This vulnerability allows remote attackers to execute arbitrary commands on affected V-SOL OLT devices by injecting malicious commands into filenames ...

Nov 29, 2020
CVE-2020-29056
9.8

This vulnerability allows attackers to escape from a restricted shell and gain root privileges on affected CDATA optical line terminal devices by expl...

Nov 24, 2020
CVE-2020-24719
9.8

CVE-2020-24719 is a critical vulnerability in Couchbase Server where the Erlang magic cookie (authentication secret) can be exposed in logs. Attackers...

Nov 12, 2020
CVE-2020-28347
9.8

CVE-2020-28347 is a command injection vulnerability in the tdpServer component of TP-Link Archer A7 AC1750 routers that allows remote attackers to exe...

Nov 8, 2020
CVE-2020-27744
9.8

CVE-2020-27744 is a critical remote code execution vulnerability affecting Western Digital My Cloud NAS devices. It allows attackers to execute arbitr...

Oct 29, 2020
CVE-2020-16257
9.8

CVE-2020-16257 is a command injection vulnerability in Winston Privacy devices version 1.5.4 that allows attackers to execute arbitrary commands via t...

Oct 28, 2020
CVE-2020-27976
9.8

CVE-2020-27976 is a critical remote command injection vulnerability in osCommerce Phoenix CE that allows attackers to execute arbitrary operating syst...

Oct 28, 2020
CVE-2020-27158
9.8

This vulnerability allows remote attackers to execute arbitrary code on Western Digital My Cloud NAS devices via the cgi_api.php file, potentially lea...

Oct 27, 2020
CVE-2020-12124
9.8

This vulnerability allows unauthenticated remote attackers to execute arbitrary Linux commands as root on affected WAVLINK routers. Attackers can gain...

Oct 2, 2020
CVE-2020-25223
9.8

This vulnerability allows remote attackers to execute arbitrary commands on Sophos SG UTM devices through the WebAdmin interface. It affects organizat...

Sep 25, 2020
CVE-2020-16147
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary code with root privileges on Telmat AccessLog systems via the login page. It ...

Sep 24, 2020
CVE-2020-13802
9.8

CVE-2020-13802 allows remote attackers to execute arbitrary operating system commands on systems running vulnerable Rebar3 versions by injecting malic...

Sep 2, 2020
CVE-2020-24054
9.8

This vulnerability allows remote attackers to execute arbitrary commands as root on Moog EXO Series units by exploiting a command injection flaw in th...

Aug 21, 2020
CVE-2020-16279
9.8

This vulnerability allows remote attackers to execute arbitrary commands on systems running RangeeOS 8.0.4 with the Kommbox component. Attackers can e...

Aug 20, 2020
CVE-2020-17456
9.8

This vulnerability allows unauthenticated remote attackers to execute arbitrary commands on affected SEOWON INTECH routers via the ipAddr parameter in...

Aug 20, 2020
CVE-2020-24032
9.8

CVE-2020-24032 is a command injection vulnerability in tz.pl on XoruX LPAR2RRD and STOR2RRD virtual appliances that allows attackers to execute arbitr...

Aug 18, 2020
CVE-2020-17368
9.8

CVE-2020-17368 is a command injection vulnerability in Firejail up to version 0.9.62 that allows attackers to execute arbitrary commands on the host s...

Aug 11, 2020
CVE-2020-13151
9.8

CVE-2020-13151 allows unauthenticated remote attackers to execute arbitrary operating system commands on Aerospike database servers by submitting mali...

Aug 5, 2020
CVE-2020-8178
9.8

CVE-2020-8178 is a critical OS command injection vulnerability in the jison npm package that allows attackers to execute arbitrary commands on affecte...

Jul 15, 2020
CVE-2020-13925
9.8

CVE-2020-13925 is a critical OS command injection vulnerability in Apache Kylin's REST API that allows remote attackers to execute arbitrary commands ...

Jul 14, 2020
CVE-2020-10987
9.8

This vulnerability allows remote attackers to execute arbitrary system commands on Tenda AC15 AC1900 routers via a specific endpoint. Attackers can ex...

Jul 13, 2020
CVE-2020-15489
9.8

This vulnerability allows remote attackers to execute arbitrary commands with root privileges on affected Wavlink routers by injecting shell metachara...

Jul 1, 2020
CVE-2019-15310
9.8

This vulnerability allows remote attackers to execute arbitrary code on Linkplay devices without user interaction. Attackers can retrieve AWS keys fro...

Jul 1, 2020
CVE-2020-13619
9.8

CVE-2020-13619 is a command injection vulnerability in Locutus PHP's escapeshellarg function that allows attackers to execute arbitrary commands on af...

Jul 1, 2020
CVE-2026-25130
9.6

CVE-2026-25130 is a critical argument injection vulnerability in the Cybersecurity AI (CAI) framework that allows remote code execution. Attackers can...

Jan 30, 2026

About OS Command Injection (CWE-78)

The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.

Our database tracks 1,699 CVEs classified as CWE-78, with 635 rated critical and 894 rated high severity. The average CVSS score for OS Command Injection vulnerabilities is 8.5.

External reference: View CWE-78 on MITRE CWE →

Monitor OS Command Injection Vulnerabilities

Get alerted when new OS Command Injection CVEs affect your infrastructure.

Start Monitoring Free