CWE-78: OS Command Injection
The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.
Yearly Trend
Top Affected Vendors
All OS Command Injection CVEs (1,751)
This vulnerability allows remote attackers to execute arbitrary operating system commands on TOTOLINK X5000R routers by injecting malicious commands t...
Jan 15, 2025This vulnerability allows remote attackers to execute arbitrary operating system commands on TOTOLINK X5000R routers by injecting malicious commands t...
Jan 15, 2025This vulnerability allows remote attackers to execute arbitrary operating system commands on TOTOLINK X5000R routers by injecting malicious commands t...
Jan 15, 2025This vulnerability allows remote attackers to execute arbitrary operating system commands on TOTOLINK X5000R routers by injecting malicious commands t...
Jan 15, 2025This vulnerability allows remote attackers to execute arbitrary operating system commands on TOTOLINK X5000R routers by injecting malicious commands t...
Jan 15, 2025This vulnerability allows remote attackers to execute arbitrary operating system commands on TOTOLINK X5000R routers by injecting malicious commands i...
Jan 15, 2025This CVE-2024-27778 is an OS command injection vulnerability in Fortinet FortiSandbox that allows authenticated attackers with read-only permissions t...
Jan 14, 2025Authenticated command injection in Iocharger AC charging station firmware allows attackers with low-privilege accounts to execute arbitrary commands a...
Jan 9, 2025This vulnerability allows authenticated remote attackers to execute arbitrary commands as root on vulnerable Webmin installations. Attackers can injec...
Dec 30, 2024This vulnerability allows remote authenticated users to execute arbitrary commands on CyberPanel servers via shell injection in the phpSelection field...
Dec 16, 2024This vulnerability allows remote authenticated attackers to execute arbitrary commands on IBM App Connect Enterprise Certified Container systems by se...
Dec 4, 2024This vulnerability allows remote attackers to execute arbitrary commands with root privileges on Victure RX1800 WiFi 6 Router devices. Attackers can e...
Dec 2, 2024This vulnerability allows remote attackers to execute arbitrary commands with root privileges on Victure RX1800 WiFi 6 Router devices. Attackers can e...
Dec 2, 2024This vulnerability allows authenticated remote attackers to execute arbitrary system commands with root privileges on Cohesive Networks VNS3 installat...
Nov 22, 2024This vulnerability allows authenticated remote attackers to execute arbitrary system commands with root privileges on Logsign Unified SecOps Platform ...
Nov 22, 2024This OS command injection vulnerability in Rakuten Turbo 5G firmware allows remote authenticated attackers to execute arbitrary operating system comma...
Nov 20, 2024StepSecurity's Harden-Runner versions before 2.10.2 contain command injection vulnerabilities via environment variables that could allow attackers to ...
Nov 18, 2024This vulnerability allows an authenticated local attacker to execute arbitrary commands with root privileges on devices running ConfD CLI due to insuf...
Nov 15, 2024This vulnerability allows remote attackers to execute arbitrary operating system commands on D-Link DIR_823G routers via command injection in the Addr...
Nov 5, 2024This vulnerability allows remote attackers to execute arbitrary commands on Draytek Vigor3900 routers by injecting malicious commands into the mainfun...
Nov 1, 2024This vulnerability allows remote attackers to execute arbitrary commands on Draytek Vigor3900 routers by injecting malicious commands into the mainfun...
Nov 1, 2024CVE-2024-36060 allows remote attackers to execute arbitrary operating system commands on EnGenius EnStation5-AC devices by injecting shell metacharact...
Oct 30, 2024This vulnerability allows remote attackers to execute arbitrary commands on Tenda AC7 routers without authentication. Attackers can inject malicious c...
Oct 28, 2024This vulnerability allows remote attackers to execute arbitrary operating system commands on Microchip TimeProvider 4100 devices through improper inpu...
Oct 4, 2024This vulnerability in Cisco IOS XR Software allows authenticated local attackers with low-privileged accounts to gain root-level file system access th...
Sep 11, 2024This vulnerability allows low-privileged remote attackers to execute arbitrary operating system commands with root privileges by exploiting improper i...
Sep 10, 2024This vulnerability allows low-privileged remote attackers to execute arbitrary operating system commands as root on affected mGuard devices. Attackers...
Sep 10, 2024A low-privileged remote attacker can read and write files as root on mGuard devices due to improper input sanitization of the EMAIL_RELAY_PASSWORD var...
Sep 10, 2024This vulnerability allows remote attackers to execute arbitrary commands on affected D-Link routers by sending malicious input to the usb_paswd.asp CG...
Sep 9, 2024This CVE describes an OS command injection vulnerability in QNAP operating systems that allows authenticated users to execute arbitrary commands via n...
Sep 6, 2024This CVE describes a command injection vulnerability in the Linksys E1500 router's httpd service. An authenticated attacker can execute arbitrary oper...
Aug 19, 2024This vulnerability allows authenticated attackers to execute arbitrary operating system commands on TOTOLINK X5000r routers through command injection ...
Aug 13, 2024This CVE describes an authenticated OS command injection vulnerability in TOTOLINK X5000r routers. Attackers with valid credentials can execute arbitr...
Aug 13, 2024This CVE describes an OS command injection vulnerability in TOTOLINK X5000r routers that allows authenticated attackers to execute arbitrary commands ...
Aug 12, 2024This CVE describes an authenticated OS command injection vulnerability in TOTOLINK X5000r routers. Attackers with valid credentials can send specially...
Aug 12, 2024This vulnerability allows authenticated attackers to execute arbitrary operating system commands on TOTOLINK X5000r routers through command injection ...
Aug 12, 2024This vulnerability allows authenticated attackers to execute arbitrary operating system commands on TOTOLINK X5000r routers by sending malicious packe...
Aug 12, 2024Softaculous Webuzo contains a command injection vulnerability in FTP management functionality that allows authenticated attackers to execute arbitrary...
Jul 25, 2024This vulnerability allows remote attackers to execute arbitrary operating system commands on Adtran 834-5 devices by injecting shell metacharacters in...
Jul 24, 2024This vulnerability in Century Systems' FutureNet NXR, VXR, and WXR series allows authenticated users with debug function knowledge to execute arbitrar...
Jul 17, 2024CVE-2024-39935 is an OS command injection vulnerability in jc21 NGINX Proxy Manager that allows authenticated users with certificate management privil...
Jul 4, 2024Dell PowerProtect DD versions before 8.0 contain an OS command injection vulnerability in an admin operation. A remote attacker with low privileges ca...
Jun 26, 2024CVE-2024-4748 is a command injection vulnerability in the CRUDDIY project that allows remote attackers to execute arbitrary shell commands on affected...
Jun 24, 2024This CVE describes a command injection vulnerability in TOTOLINK A6000R routers that allows remote attackers to execute arbitrary code via the iface p...
Jun 20, 2024This vulnerability allows authenticated remote attackers to execute arbitrary system commands on A10 Thunder ADC devices. Attackers can achieve remote...
Jun 6, 2024This vulnerability allows authenticated attackers to execute arbitrary operating system commands on ORing IAP-420 devices through the web interface. A...
May 28, 2024This vulnerability allows network-adjacent attackers to execute arbitrary commands as root on D-Link G416 wireless routers without authentication. Att...
May 23, 2024This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK X5000R routers via the disconnectVPN function. Attackers can gain...
May 14, 2024CVE-2023-37407 is an OS command injection vulnerability in IBM Aspera Orchestrator that allows authenticated remote attackers to execute arbitrary com...
May 3, 2024This vulnerability allows remote attackers to execute arbitrary code on Voltronic Power ViewPower Pro systems by injecting malicious commands into the...
May 3, 2024About OS Command Injection (CWE-78)
The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.
Our database tracks 1,751 CVEs classified as CWE-78, with 675 rated critical and 906 rated high severity. The average CVSS score for OS Command Injection vulnerabilities is 8.6.
External reference: View CWE-78 on MITRE CWE →
Monitor OS Command Injection Vulnerabilities
Get alerted when new OS Command Injection CVEs affect your infrastructure.
Start Monitoring Free