CWE-78: OS Command Injection
The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.
Yearly Trend
Top Affected Vendors
All OS Command Injection CVEs (1,699)
Cursor code editor versions 1.17 through 1.2 contain a UI information disclosure vulnerability in the MCP deeplink handler that allows attackers to ex...
Aug 2, 2025CVE-2025-6514 is a critical OS command injection vulnerability in mcp-remote that allows remote code execution when connecting to malicious MCP server...
Jul 9, 2025CVE-2025-5277 is a command injection vulnerability in aws-mcp-server that allows attackers to execute arbitrary commands on the host system by craftin...
May 28, 2025CVE-2023-29120 is a critical OS command injection vulnerability in Waybox Enel X web management applications that allows authenticated attackers to ex...
Nov 5, 2024CVE-2023-51698 is a critical command injection vulnerability in Atril document viewer that allows remote code execution when a user opens a malicious ...
Jan 12, 2024This vulnerability in PaddlePaddle allows attackers to execute arbitrary operating system commands through command injection in the convert_shape_comp...
Jan 3, 2024This vulnerability in PaddlePaddle allows attackers to execute arbitrary operating system commands through command injection in the get_online_pass_in...
Jan 3, 2024CVE-2023-38673 is a command injection vulnerability in PaddlePaddle's fs.py module that allows attackers to execute arbitrary operating system command...
Jul 26, 2023CVE-2023-33965 is a command injection vulnerability in Brook's tproxy server that allows remote code execution. Attackers can exploit this by tricking...
Jun 1, 2023This CVE describes an OS command injection vulnerability in the Abode iota security system's wirelessConnect handler. An attacker can inject arbitrary...
Dec 20, 2021This vulnerability allows authenticated remote attackers to execute arbitrary CLI commands on devices managed by Cisco DNA Center through command inje...
Jan 20, 2021This CVE describes an OS command injection vulnerability in EasyCorp ZenTao Pro that allows authenticated attackers to execute arbitrary commands with...
Aug 6, 2020A critical vulnerability in Trend Micro Apex One (on-premise) management console allows unauthenticated remote attackers to upload malicious code and ...
Aug 5, 2025This CVE describes an OS command injection vulnerability in Dassault Systèmes' 3DEXPERIENCE platform and related products. Attackers can execute arbi...
Mar 1, 2024This CVE describes an operating system command injection vulnerability in ekorCCP and ekorRCI software from Ormazabal. Authenticated attackers can exe...
Sep 19, 2023CVE-2021-21386 is a command injection vulnerability in APKLeaks that allows remote attackers to execute arbitrary operating system commands via malici...
Mar 24, 2021CVE-2020-15271 is a critical vulnerability in the lookatme Python package that allows remote code execution when rendering untrusted markdown content....
Oct 26, 2020This vulnerability allows attackers to execute arbitrary operating system commands with root privileges within the container running bleon-ethical/api...
Feb 24, 2026A typo in Froxlor's input validation code (== instead of =) disables email format checking for admin email settings. This allows authenticated admins ...
Mar 3, 2026CVE-2026-25643 is a critical Remote Command Execution vulnerability in Frigate NVR software that allows attackers to execute arbitrary system commands...
Feb 6, 2026ChurchCRM versions before 6.5.3 have a critical vulnerability in the Database Restore functionality that allows attackers to upload malicious files wi...
Dec 17, 2025This vulnerability allows remote command injection in the HexStrike AI MCP server. Attackers can execute arbitrary commands with root privileges by se...
Nov 30, 2025Dell CloudLink versions 8.0 through 8.1.2 have a vulnerability where privileged users with known passwords can escape the restricted shell, gaining fu...
Nov 5, 2025This CVE describes an OS command injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server firmware that allows attackers to execu...
Oct 6, 2025This vulnerability allows authenticated admin users with process-definition creation/modification privileges in Valtimo Business Process Automation pl...
Aug 28, 2025CVE-2025-50989 is an authenticated command injection vulnerability in OPNsense firewall software that allows administrators to execute arbitrary syste...
Aug 27, 2025A critical vulnerability in dedupe's GitHub Actions workflow allows attackers to execute arbitrary code by manipulating pull request comments. This co...
Jul 30, 2025This vulnerability allows authenticated attackers to execute arbitrary commands as root on Ruckus wireless controllers by exploiting improper input sa...
Jul 21, 2025This critical vulnerability allows remote attackers with administrator credentials to execute arbitrary operating system commands on affected devices ...
Jul 7, 2025UNI-NMS-Lite contains a command injection vulnerability that allows unauthenticated attackers to execute arbitrary commands on affected systems. This ...
Apr 24, 2025This vulnerability allows authenticated remote attackers to execute arbitrary code with root privileges on SENTRON 7KT PAC1260 Data Manager devices. A...
Apr 8, 2025This vulnerability allows authenticated remote attackers to execute arbitrary code with root privileges on SENTRON 7KT PAC1260 Data Manager devices. T...
Apr 8, 2025Dell Unity storage systems running version 5.4 or earlier contain an OS command injection vulnerability that allows unauthenticated remote attackers t...
Mar 28, 2025This vulnerability allows authenticated administrators in Ivanti Cloud Services Application (CSA) to execute arbitrary operating system commands throu...
Feb 11, 2025CVE-2024-51450 is an OS command injection vulnerability in IBM Security Verify Directory that allows authenticated remote attackers to execute arbitra...
Feb 6, 2025CVE-2025-22604 is a command injection vulnerability in Cacti's SNMP result parser that allows authenticated users to execute arbitrary system commands...
Jan 27, 2025This CVE describes a command injection vulnerability in Ivanti Connect Secure and Policy Secure that allows authenticated administrators to execute ar...
Nov 12, 2024This CVE describes a command injection vulnerability in Ivanti Connect Secure and Ivanti Policy Secure that allows authenticated administrators to exe...
Nov 12, 2024This vulnerability allows authenticated remote attackers with high privileges in SINEC INS to execute arbitrary operating system commands through impr...
Nov 12, 2024This critical vulnerability in Dell Enterprise SONiC OS allows authenticated high-privileged attackers to execute arbitrary operating system commands ...
Nov 8, 2024This vulnerability allows remote attackers to execute arbitrary operating system commands on WordPress servers running vulnerable versions of the Medi...
Nov 4, 2024This vulnerability in pyLoad allows remote code execution by downloading executable files to the /.pyload/scripts folder and triggering script executi...
Oct 25, 2024This vulnerability allows authenticated users with application creation permissions to execute arbitrary operating system commands by creating applica...
Aug 12, 2024This vulnerability allows remote authenticated attackers to execute arbitrary commands on IBM Security Guardium systems by sending specially crafted r...
May 14, 2024An OS command injection vulnerability in Peplink Smart Reader v1.2.0 allows authenticated attackers to execute arbitrary commands via the web interfac...
Apr 17, 2024This CVE describes a command injection vulnerability in WBSAirback's Active Directory integration that allows attackers to execute arbitrary commands ...
Apr 15, 2024This CVE describes a command injection vulnerability in LG webOS TVs that allows authenticated attackers to execute arbitrary commands as the dbus use...
Apr 9, 2024This CVE describes a command injection vulnerability in LG webOS TV software that allows authenticated attackers to execute arbitrary commands as root...
Apr 9, 2024This vulnerability allows admin users in Foreman to bypass safe mode restrictions in templates, enabling arbitrary code execution on the underlying op...
Sep 20, 2023This CVE describes an XML injection vulnerability in Magento Commerce that allows authenticated administrators to execute arbitrary code remotely. Att...
Sep 6, 2023About OS Command Injection (CWE-78)
The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.
Our database tracks 1,699 CVEs classified as CWE-78, with 635 rated critical and 894 rated high severity. The average CVSS score for OS Command Injection vulnerabilities is 8.5.
External reference: View CWE-78 on MITRE CWE →
Monitor OS Command Injection Vulnerabilities
Get alerted when new OS Command Injection CVEs affect your infrastructure.
Start Monitoring Free