CWE-78: OS Command Injection
The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.
Yearly Trend
Top Affected Vendors
All OS Command Injection CVEs (1,723)
A critical vulnerability in dedupe's GitHub Actions workflow allows attackers to execute arbitrary code by manipulating pull request comments. This co...
Jul 30, 2025This vulnerability allows authenticated attackers to execute arbitrary commands as root on Ruckus wireless controllers by exploiting improper input sa...
Jul 21, 2025This critical vulnerability allows remote attackers with administrator credentials to execute arbitrary operating system commands on affected devices ...
Jul 7, 2025UNI-NMS-Lite contains a command injection vulnerability that allows unauthenticated attackers to execute arbitrary commands on affected systems. This ...
Apr 24, 2025This vulnerability allows authenticated remote attackers to execute arbitrary code with root privileges on SENTRON 7KT PAC1260 Data Manager devices. A...
Apr 8, 2025This vulnerability allows authenticated remote attackers to execute arbitrary code with root privileges on SENTRON 7KT PAC1260 Data Manager devices. T...
Apr 8, 2025Dell Unity storage systems running version 5.4 or earlier contain an OS command injection vulnerability that allows unauthenticated remote attackers t...
Mar 28, 2025This vulnerability allows authenticated administrators in Ivanti Cloud Services Application (CSA) to execute arbitrary operating system commands throu...
Feb 11, 2025CVE-2024-51450 is an OS command injection vulnerability in IBM Security Verify Directory that allows authenticated remote attackers to execute arbitra...
Feb 6, 2025CVE-2025-22604 is a command injection vulnerability in Cacti's SNMP result parser that allows authenticated users to execute arbitrary system commands...
Jan 27, 2025This CVE describes a command injection vulnerability in Ivanti Connect Secure and Policy Secure that allows authenticated administrators to execute ar...
Nov 12, 2024This CVE describes a command injection vulnerability in Ivanti Connect Secure and Ivanti Policy Secure that allows authenticated administrators to exe...
Nov 12, 2024This vulnerability allows authenticated remote attackers with high privileges in SINEC INS to execute arbitrary operating system commands through impr...
Nov 12, 2024This critical vulnerability in Dell Enterprise SONiC OS allows authenticated high-privileged attackers to execute arbitrary operating system commands ...
Nov 8, 2024This vulnerability allows remote attackers to execute arbitrary operating system commands on WordPress servers running vulnerable versions of the Medi...
Nov 4, 2024This vulnerability in pyLoad allows remote code execution by downloading executable files to the /.pyload/scripts folder and triggering script executi...
Oct 25, 2024This vulnerability allows authenticated users with application creation permissions to execute arbitrary operating system commands by creating applica...
Aug 12, 2024This vulnerability allows remote authenticated attackers to execute arbitrary commands on IBM Security Guardium systems by sending specially crafted r...
May 14, 2024An OS command injection vulnerability in Peplink Smart Reader v1.2.0 allows authenticated attackers to execute arbitrary commands via the web interfac...
Apr 17, 2024This CVE describes a command injection vulnerability in WBSAirback's Active Directory integration that allows attackers to execute arbitrary commands ...
Apr 15, 2024This CVE describes a command injection vulnerability in LG webOS TVs that allows authenticated attackers to execute arbitrary commands as the dbus use...
Apr 9, 2024This CVE describes a command injection vulnerability in LG webOS TV software that allows authenticated attackers to execute arbitrary commands as root...
Apr 9, 2024This vulnerability allows admin users in Foreman to bypass safe mode restrictions in templates, enabling arbitrary code execution on the underlying op...
Sep 20, 2023This CVE describes an XML injection vulnerability in Magento Commerce that allows authenticated administrators to execute arbitrary code remotely. Att...
Sep 6, 2023CVE-2023-3267 is an OS command injection vulnerability in CyberPower PowerPanel Enterprise that allows authenticated users to execute arbitrary comman...
Aug 14, 2023This CVE describes an OS command injection vulnerability in Adobe Commerce (formerly Magento) that allows authenticated administrators to execute arbi...
Aug 9, 2023This vulnerability allows authenticated attackers to execute arbitrary operating system commands on SAP ECC and S/4HANA systems with IS-OIL component....
Jul 11, 2023This vulnerability allows authenticated administrators to execute arbitrary shell commands through the API in OSNexus QuantaStor storage systems. Atta...
Jul 10, 2023This CVE describes a command injection vulnerability in Netgear Orbi RBR750 routers running firmware version 4.6.8.5. An authenticated attacker can se...
Mar 21, 2023This CVE describes an authenticated remote command injection vulnerability in Aruba ClearPass Policy Manager. An attacker with valid credentials can e...
May 16, 2022This CVE describes an authenticated remote command injection vulnerability in Aruba ClearPass Policy Manager. Attackers with valid credentials can exe...
May 16, 2022This CVE describes an authenticated remote command injection vulnerability in Aruba ClearPass Policy Manager. Attackers with valid credentials can exe...
May 16, 2022CVE-2022-25017 is a command injection vulnerability in Hitron CHITA devices that allows attackers to execute arbitrary commands on the system by injec...
Apr 1, 2022This vulnerability allows authenticated high-privileged attackers with network access to the VMware Carbon Black App Control administration interface ...
Mar 23, 2022This vulnerability allows authenticated attackers to execute arbitrary operating system commands with root/admin privileges on affected systems. It af...
Feb 4, 2022This vulnerability allows authenticated attackers to execute arbitrary commands on affected systems by sending specially crafted HTTP requests contain...
Dec 22, 2021CVE-2021-21876 allows authenticated attackers to execute arbitrary commands via specially crafted HTTP PUT requests. This vulnerability affects system...
Dec 22, 2021CVE-2021-41243 is a critical vulnerability in baserCMS that combines Zip Slip and OS command injection flaws. Authenticated users with file upload per...
Nov 26, 2021This vulnerability allows remote attackers to execute arbitrary commands on InHand Networks IR615 routers by injecting commands through ping tools. At...
Oct 19, 2021This vulnerability allows remote attackers to execute arbitrary commands on InHand Networks IR615 routers by injecting commands through traceroute too...
Oct 19, 2021This CVE describes an XML injection vulnerability in Magento Commerce that allows authenticated attackers with admin privileges to execute arbitrary c...
Sep 1, 2021CVE-2021-21585 is an OS command injection vulnerability in Dell OpenManage Enterprise's RACADM and IPMI tools. Remote authenticated users with high pr...
Aug 9, 2021CVE-2020-5322 is a command injection vulnerability in Dell EMC OpenManage Enterprise-Modular (OME-M) that allows remote authenticated users with high ...
Jul 19, 2021This CVE describes a command injection vulnerability in QSAN Storage Manager that allows remote privileged users to execute arbitrary commands on the ...
Jul 7, 2021This vulnerability allows authenticated administrators in Moodle to execute arbitrary commands on the server through the legacy spellchecker plugin. A...
Jun 23, 2021CVE-2020-28490 is a command injection vulnerability in async-git npm package versions before 1.13.2. Attackers can execute arbitrary shell commands by...
Feb 18, 2021CVE-2021-21018 is an OS command injection vulnerability in Magento's scheduled operation module that allows authenticated attackers with admin console...
Feb 11, 2021This vulnerability allows authenticated attackers with admin console access to execute arbitrary operating system commands on Magento servers via the ...
Feb 11, 2021This CVE-2020-14324 is an authenticated OS command injection vulnerability in Red Hat CloudForms that allows attackers to execute arbitrary commands o...
Aug 11, 2020CVE-2026-23520 is a command injection vulnerability in Arcane's docker management platform that allows authenticated users to execute arbitrary shell ...
Jan 15, 2026About OS Command Injection (CWE-78)
The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.
Our database tracks 1,723 CVEs classified as CWE-78, with 659 rated critical and 894 rated high severity. The average CVSS score for OS Command Injection vulnerabilities is 8.6.
External reference: View CWE-78 on MITRE CWE →
Monitor OS Command Injection Vulnerabilities
Get alerted when new OS Command Injection CVEs affect your infrastructure.
Start Monitoring Free