CWE-78: OS Command Injection

The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.

1,733
Total CVEs
664
Critical
899
High
8.6
Avg CVSS
11
In CISA KEV

Yearly Trend

2026
146
2025
465
2024
405
2023
253
2022
163

Top Affected Vendors

1 Dlink 90
2 Totolink 85
3 Fortinet 58
4 Dell 58
5 Tp Link 36
6 Zyxel 33
7 Ruijie 30
8 Cisco 28
9 Arubanetworks 27
10 Jvckenwood 26

All OS Command Injection CVEs (1,733)

CVE-2025-64124
8.8

This OS command injection vulnerability in Nuvation Energy Multi-Stack Controller allows attackers to execute arbitrary operating system commands on a...

Jan 3, 2026
CVE-2025-64120
8.8

This OS command injection vulnerability in Nuvation Energy Multi-Stack Controller allows attackers to execute arbitrary operating system commands on a...

Jan 2, 2026
CVE-2025-68700
8.8

CVE-2025-68700 is a critical remote code execution vulnerability in RAGFlow where authenticated low-privilege users can execute arbitrary system comma...

Dec 31, 2025
CVE-2021-47745
8.8

CVE-2021-47745 is an authenticated command injection vulnerability in Cypress Solutions CTM-200 firmware that allows attackers with valid credentials ...

Dec 31, 2025
CVE-2021-47747
8.8

This vulnerability allows authenticated attackers to execute arbitrary system commands with administrative privileges in meterN energy monitoring soft...

Dec 31, 2025
CVE-2025-15389
8.8

This vulnerability allows authenticated remote attackers to execute arbitrary operating system commands on QNO Technology VPN Firewall devices. Attack...

Dec 31, 2025
CVE-2025-15388
8.8

This vulnerability allows authenticated remote attackers to execute arbitrary operating system commands on QNO Technology VPN Firewall devices. Attack...

Dec 31, 2025
CVE-2022-50793
8.8

This vulnerability allows authenticated attackers to execute arbitrary system commands on SOUND4 IMPACT/FIRST/PULSE/Eco systems through command inject...

Dec 30, 2025
CVE-2025-66210
8.8

CVE-2025-66210 is an authenticated command injection vulnerability in Coolify's Database Import functionality that allows users with application/servi...

Dec 23, 2025
CVE-2025-66211
8.8

Coolify versions before 4.0.0-beta.451 contain an authenticated command injection vulnerability in PostgreSQL initialization script filename handling....

Dec 23, 2025
CVE-2025-66212
8.8

Coolify versions before 4.0.0-beta.451 contain an authenticated command injection vulnerability in Dynamic Proxy Configuration Filename handling. User...

Dec 23, 2025
CVE-2025-66213
8.8

CVE-2025-66213 is an authenticated command injection vulnerability in Coolify's File Storage Directory Mount Path functionality. It allows users with ...

Dec 23, 2025
CVE-2024-58314
8.8

This CVE describes an authenticated command injection vulnerability in Atcom 100M IP Phones firmware that allows attackers with administrative credent...

Dec 12, 2025
CVE-2024-58294
8.8

FreePBX 16 contains an authenticated remote code execution vulnerability in the API module. Attackers with valid session credentials can exploit the '...

Dec 11, 2025
CVE-2024-58287
8.8

CVE-2024-58287 is an authenticated command injection vulnerability in reNgine 2.2.0 that allows attackers to execute arbitrary commands on the server....

Dec 11, 2025
CVE-2025-13481
8.8

This vulnerability allows authenticated users of IBM Aspera Orchestrator to execute arbitrary commands with elevated system privileges due to improper...

Dec 11, 2025
CVE-2025-56129
8.8

This CVE describes an OS command injection vulnerability in Ruijie RG-BCR860 routers that allows attackers to execute arbitrary commands via crafted P...

Dec 11, 2025
CVE-2025-56130
8.8

This CVE describes an OS command injection vulnerability in Ruijie RG-S1930 switches that allows attackers to execute arbitrary commands via a crafted...

Dec 11, 2025
CVE-2025-56114
8.8

This CVE describes an OS command injection vulnerability in Ruijie M18 routers that allows attackers to execute arbitrary commands on the device via a...

Dec 11, 2025
CVE-2025-56117
8.8

This CVE describes an OS command injection vulnerability in Ruijie X30-PRO routers that allows attackers to execute arbitrary commands via a crafted P...

Dec 11, 2025
CVE-2025-56118
8.8

This CVE describes an OS command injection vulnerability in Ruijie X60 PRO routers that allows attackers to execute arbitrary commands on the device. ...

Dec 11, 2025
CVE-2025-56120
8.8

This CVE describes an OS command injection vulnerability in Ruijie X60 PRO routers that allows attackers to execute arbitrary commands on the device. ...

Dec 11, 2025
CVE-2025-56122
8.8

This CVE describes an OS command injection vulnerability in Ruijie RG-EW1800GX PRO wireless access points. Attackers can execute arbitrary commands on...

Dec 11, 2025
CVE-2025-56123
8.8

This CVE describes an OS command injection vulnerability in Ruijie RG-EW1200G PRO wireless access points. Attackers can execute arbitrary commands on ...

Dec 11, 2025
CVE-2025-56127
8.8

This CVE describes an OS command injection vulnerability in Ruijie RG-BCR600W routers that allows attackers to execute arbitrary commands via crafted ...

Dec 11, 2025
CVE-2025-56108
8.8

This CVE describes an OS command injection vulnerability in Ruijie X30-PRO routers that allows attackers to execute arbitrary commands on the device v...

Dec 11, 2025
CVE-2025-56109
8.8

This CVE describes an OS command injection vulnerability in Ruijie RG-BCR860 routers that allows attackers to execute arbitrary commands on the device...

Dec 11, 2025
CVE-2025-56110
8.8

This CVE describes an OS command injection vulnerability in Ruijie RG-BCR860 routers that allows attackers to execute arbitrary commands via a crafted...

Dec 11, 2025
CVE-2025-56111
8.8

This CVE describes an OS command injection vulnerability in Ruijie RG-BCR860 routers that allows attackers to execute arbitrary commands on the device...

Dec 11, 2025
CVE-2025-56113
8.8

This CVE describes an OS command injection vulnerability in Ruijie RG-YST EST devices that allows attackers to execute arbitrary commands via a crafte...

Dec 11, 2025
CVE-2025-56099
8.8

This CVE describes an OS command injection vulnerability in Ruijie RG-YST access points that allows attackers to execute arbitrary commands on the dev...

Dec 11, 2025
CVE-2025-56083
8.8

This CVE describes an OS command injection vulnerability in Ruijie X30-PRO routers that allows attackers to execute arbitrary commands on the device. ...

Dec 11, 2025
CVE-2025-12744
8.8

This vulnerability allows unprivileged local users to execute arbitrary commands with root privileges by exploiting improper input validation in the A...

Dec 3, 2025
CVE-2025-11787
8.8

This CVE describes a command injection vulnerability in Circutor SGE-PLC1000/SGE-PLC50 devices that allows attackers to execute arbitrary commands on ...

Dec 2, 2025
CVE-2025-34334
8.8

This vulnerability allows authenticated attackers to execute arbitrary commands with SYSTEM privileges on AudioCodes Fax Server and Auto-Attendant IVR...

Nov 19, 2025
CVE-2025-34335
8.8

This CVE describes an authenticated command injection vulnerability in AudioCodes Fax Server and Auto-Attendant IVR appliances. An authenticated user ...

Nov 19, 2025
CVE-2025-8693
8.8

A post-authentication command injection vulnerability in Zyxel DX3300-T0 firmware allows authenticated attackers to execute arbitrary operating system...

Nov 18, 2025
CVE-2025-64109
8.8

This vulnerability allows remote code execution in Cursor CLI Beta when a user clones a malicious GitHub repository containing a crafted .cursor/mcp.j...

Nov 5, 2025
CVE-2025-64106
8.8

This vulnerability in Cursor code editor allows attackers to execute arbitrary commands on a victim's system by tricking them into clicking a maliciou...

Nov 4, 2025
CVE-2025-34284
8.8

Nagios XI versions before 2024R2 contain an authenticated command injection vulnerability in the WinRM plugin. An authenticated administrator can inje...

Oct 30, 2025
CVE-2024-14005
8.8

Nagios XI versions before 2024R1.2 contain a command injection vulnerability in the Docker Wizard. Authenticated administrators can inject shell comma...

Oct 30, 2025
CVE-2020-36867
8.8

This vulnerability allows authenticated attackers in Nagios XI to execute arbitrary commands on the server by injecting shell metacharacters into PDF ...

Oct 30, 2025
CVE-2020-36856
8.8

This vulnerability allows authenticated users with Core Config Manager access in Nagios XI to execute arbitrary commands on the host system by injecti...

Oct 30, 2025
CVE-2018-25122
8.8

This vulnerability allows authenticated users of Nagios XI to execute arbitrary commands on the server through the Component Download page. Attackers ...

Oct 30, 2025
CVE-2013-10073
8.8

This vulnerability allows authenticated users with access to the Auto-Discovery tool in Nagios XI to inject and execute arbitrary shell commands, pote...

Oct 30, 2025
CVE-2025-64140
8.8

The Jenkins Azure CLI Plugin vulnerability allows attackers with Item/Configure permission to execute arbitrary shell commands on the Jenkins controll...

Oct 29, 2025
CVE-2025-34311
8.8

This CVE describes a command injection vulnerability in IPFire firewall software that allows authenticated attackers to execute arbitrary commands as ...

Oct 28, 2025
CVE-2025-10680
8.8

This vulnerability allows a malicious OpenVPN server to execute arbitrary shell commands on client systems when DNS configuration updates are enabled....

Oct 24, 2025
CVE-2025-6541
8.8

This vulnerability allows authenticated users of the web management interface to execute arbitrary operating system commands on affected Omada/Tp-Link...

Oct 21, 2025
CVE-2025-47901
8.8

This CVE describes an OS command injection vulnerability in Microchip Time Provider 4100 devices that allows attackers to execute arbitrary operating ...

Oct 20, 2025

About OS Command Injection (CWE-78)

The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.

Our database tracks 1,733 CVEs classified as CWE-78, with 664 rated critical and 899 rated high severity. The average CVSS score for OS Command Injection vulnerabilities is 8.6.

External reference: View CWE-78 on MITRE CWE →

Monitor OS Command Injection Vulnerabilities

Get alerted when new OS Command Injection CVEs affect your infrastructure.

Start Monitoring Free