CWE-78: OS Command Injection

The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.

1,723
Total CVEs
659
Critical
894
High
8.6
Avg CVSS
11
In CISA KEV

Yearly Trend

2026
146
2025
465
2024
405
2023
253
2022
163

Top Affected Vendors

1 Dlink 89
2 Totolink 85
3 Fortinet 58
4 Dell 58
5 Tp Link 36
6 Zyxel 33
7 Ruijie 30
8 Cisco 28
9 Arubanetworks 27
10 Jvckenwood 26

All OS Command Injection CVEs (1,723)

CVE-2025-54430
9.1

A critical vulnerability in dedupe's GitHub Actions workflow allows attackers to execute arbitrary code by manipulating pull request comments. This co...

Jul 30, 2025
CVE-2025-46117
9.1

This vulnerability allows authenticated attackers to execute arbitrary commands as root on Ruckus wireless controllers by exploiting improper input sa...

Jul 21, 2025
CVE-2025-3626
9.1

This critical vulnerability allows remote attackers with administrator credentials to execute arbitrary operating system commands on affected devices ...

Jul 7, 2025
CVE-2025-46271
9.1

UNI-NMS-Lite contains a command injection vulnerability that allows unauthenticated attackers to execute arbitrary commands on affected systems. This ...

Apr 24, 2025
CVE-2024-41790
9.1

This vulnerability allows authenticated remote attackers to execute arbitrary code with root privileges on SENTRON 7KT PAC1260 Data Manager devices. A...

Apr 8, 2025
CVE-2024-41788
9.1

This vulnerability allows authenticated remote attackers to execute arbitrary code with root privileges on SENTRON 7KT PAC1260 Data Manager devices. T...

Apr 8, 2025
CVE-2025-24383
EPSS 11.8% 9.1

Dell Unity storage systems running version 5.4 or earlier contain an OS command injection vulnerability that allows unauthenticated remote attackers t...

Mar 28, 2025
CVE-2024-47908
EPSS 13.5% 9.1

This vulnerability allows authenticated administrators in Ivanti Cloud Services Application (CSA) to execute arbitrary operating system commands throu...

Feb 11, 2025
CVE-2024-51450
9.1

CVE-2024-51450 is an OS command injection vulnerability in IBM Security Verify Directory that allows authenticated remote attackers to execute arbitra...

Feb 6, 2025
CVE-2025-22604
EPSS 52.5% 9.1

CVE-2025-22604 is a command injection vulnerability in Cacti's SNMP result parser that allows authenticated users to execute arbitrary system commands...

Jan 27, 2025
CVE-2024-11005
9.1

This CVE describes a command injection vulnerability in Ivanti Connect Secure and Policy Secure that allows authenticated administrators to execute ar...

Nov 12, 2024
CVE-2024-11007
9.1

This CVE describes a command injection vulnerability in Ivanti Connect Secure and Ivanti Policy Secure that allows authenticated administrators to exe...

Nov 12, 2024
CVE-2024-46890
9.1

This vulnerability allows authenticated remote attackers with high privileges in SINEC INS to execute arbitrary operating system commands through impr...

Nov 12, 2024
CVE-2024-45763
9.1

This critical vulnerability in Dell Enterprise SONiC OS allows authenticated high-privileged attackers to execute arbitrary operating system commands ...

Nov 8, 2024
CVE-2024-51661
9.1

This vulnerability allows remote attackers to execute arbitrary operating system commands on WordPress servers running vulnerable versions of the Medi...

Nov 4, 2024
CVE-2024-47821
9.1

This vulnerability in pyLoad allows remote code execution by downloading executable files to the /.pyload/scripts folder and triggering script executi...

Oct 25, 2024
CVE-2024-42166
9.1

This vulnerability allows authenticated users with application creation permissions to execute arbitrary operating system commands by creating applica...

Aug 12, 2024
CVE-2023-47709
9.1

This vulnerability allows remote authenticated attackers to execute arbitrary commands on IBM Security Guardium systems by sending specially crafted r...

May 14, 2024
CVE-2023-39367
9.1

An OS command injection vulnerability in Peplink Smart Reader v1.2.0 allows authenticated attackers to execute arbitrary commands via the web interfac...

Apr 17, 2024
CVE-2024-3781
9.1

This CVE describes a command injection vulnerability in WBSAirback's Active Directory integration that allows attackers to execute arbitrary commands ...

Apr 15, 2024
CVE-2023-6320
9.1

This CVE describes a command injection vulnerability in LG webOS TVs that allows authenticated attackers to execute arbitrary commands as the dbus use...

Apr 9, 2024
CVE-2023-6318
9.1

This CVE describes a command injection vulnerability in LG webOS TV software that allows authenticated attackers to execute arbitrary commands as root...

Apr 9, 2024
CVE-2023-0118
9.1

This vulnerability allows admin users in Foreman to bypass safe mode restrictions in templates, enabling arbitrary code execution on the underlying op...

Sep 20, 2023
CVE-2021-36023
9.1

This CVE describes an XML injection vulnerability in Magento Commerce that allows authenticated administrators to execute arbitrary code remotely. Att...

Sep 6, 2023
CVE-2023-3267
9.1

CVE-2023-3267 is an OS command injection vulnerability in CyberPower PowerPanel Enterprise that allows authenticated users to execute arbitrary comman...

Aug 14, 2023
CVE-2023-38208
9.1

This CVE describes an OS command injection vulnerability in Adobe Commerce (formerly Magento) that allows authenticated administrators to execute arbi...

Aug 9, 2023
CVE-2023-36922
9.1

This vulnerability allows authenticated attackers to execute arbitrary operating system commands on SAP ECC and S/4HANA systems with IS-OIL component....

Jul 11, 2023
CVE-2021-42081
9.1

This vulnerability allows authenticated administrators to execute arbitrary shell commands through the API in OSNexus QuantaStor storage systems. Atta...

Jul 10, 2023
CVE-2022-37337
9.1

This CVE describes a command injection vulnerability in Netgear Orbi RBR750 routers running firmware version 4.6.8.5. An authenticated attacker can se...

Mar 21, 2023
CVE-2022-23662
9.1

This CVE describes an authenticated remote command injection vulnerability in Aruba ClearPass Policy Manager. An attacker with valid credentials can e...

May 16, 2022
CVE-2022-23664
9.1

This CVE describes an authenticated remote command injection vulnerability in Aruba ClearPass Policy Manager. Attackers with valid credentials can exe...

May 16, 2022
CVE-2022-23666
9.1

This CVE describes an authenticated remote command injection vulnerability in Aruba ClearPass Policy Manager. Attackers with valid credentials can exe...

May 16, 2022
CVE-2022-25017
9.1

CVE-2022-25017 is a command injection vulnerability in Hitron CHITA devices that allows attackers to execute arbitrary commands on the system by injec...

Apr 1, 2022
CVE-2022-22951
9.1

This vulnerability allows authenticated high-privileged attackers with network access to the VMware Carbon Black App Control administration interface ...

Mar 23, 2022
CVE-2022-0365
9.1

This vulnerability allows authenticated attackers to execute arbitrary operating system commands with root/admin privileges on affected systems. It af...

Feb 4, 2022
CVE-2021-21874
9.1

This vulnerability allows authenticated attackers to execute arbitrary commands on affected systems by sending specially crafted HTTP requests contain...

Dec 22, 2021
CVE-2021-21876
9.1

CVE-2021-21876 allows authenticated attackers to execute arbitrary commands via specially crafted HTTP PUT requests. This vulnerability affects system...

Dec 22, 2021
CVE-2021-41243
9.1

CVE-2021-41243 is a critical vulnerability in baserCMS that combines Zip Slip and OS command injection flaws. Authenticated users with file upload per...

Nov 26, 2021
CVE-2021-38470
9.1

This vulnerability allows remote attackers to execute arbitrary commands on InHand Networks IR615 routers by injecting commands through ping tools. At...

Oct 19, 2021
CVE-2021-38478
9.1

This vulnerability allows remote attackers to execute arbitrary commands on InHand Networks IR615 routers by injecting commands through traceroute too...

Oct 19, 2021
CVE-2021-36022
9.1

This CVE describes an XML injection vulnerability in Magento Commerce that allows authenticated attackers with admin privileges to execute arbitrary c...

Sep 1, 2021
CVE-2021-21585
9.1

CVE-2021-21585 is an OS command injection vulnerability in Dell OpenManage Enterprise's RACADM and IPMI tools. Remote authenticated users with high pr...

Aug 9, 2021
CVE-2020-5322
9.1

CVE-2020-5322 is a command injection vulnerability in Dell EMC OpenManage Enterprise-Modular (OME-M) that allows remote authenticated users with high ...

Jul 19, 2021
CVE-2021-32524
9.1

This CVE describes a command injection vulnerability in QSAN Storage Manager that allows remote privileged users to execute arbitrary commands on the ...

Jul 7, 2021
CVE-2021-21809
9.1

This vulnerability allows authenticated administrators in Moodle to execute arbitrary commands on the server through the legacy spellchecker plugin. A...

Jun 23, 2021
CVE-2020-28490
9.1

CVE-2020-28490 is a command injection vulnerability in async-git npm package versions before 1.13.2. Attackers can execute arbitrary shell commands by...

Feb 18, 2021
CVE-2021-21018
9.1

CVE-2021-21018 is an OS command injection vulnerability in Magento's scheduled operation module that allows authenticated attackers with admin console...

Feb 11, 2021
CVE-2021-21016
9.1

This vulnerability allows authenticated attackers with admin console access to execute arbitrary operating system commands on Magento servers via the ...

Feb 11, 2021
CVE-2020-14324
9.1

This CVE-2020-14324 is an authenticated OS command injection vulnerability in Red Hat CloudForms that allows attackers to execute arbitrary commands o...

Aug 11, 2020
CVE-2026-23520
9.0

CVE-2026-23520 is a command injection vulnerability in Arcane's docker management platform that allows authenticated users to execute arbitrary shell ...

Jan 15, 2026

About OS Command Injection (CWE-78)

The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.

Our database tracks 1,723 CVEs classified as CWE-78, with 659 rated critical and 894 rated high severity. The average CVSS score for OS Command Injection vulnerabilities is 8.6.

External reference: View CWE-78 on MITRE CWE →

Monitor OS Command Injection Vulnerabilities

Get alerted when new OS Command Injection CVEs affect your infrastructure.

Start Monitoring Free