CWE-78: OS Command Injection
The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.
Yearly Trend
Top Affected Vendors
All OS Command Injection CVEs (1,755)
This vulnerability allows network-adjacent attackers to execute arbitrary commands as root on D-Link G416 routers without authentication. Attackers ca...
May 3, 2024This vulnerability allows network-adjacent attackers to execute arbitrary commands as root on D-Link G416 routers without authentication. The flaw exi...
May 3, 2024This vulnerability allows network-adjacent attackers to execute arbitrary commands as root on D-Link G416 routers without authentication. Attackers ca...
May 3, 2024This vulnerability allows attackers on the same network to execute arbitrary commands with root privileges on D-Link G416 routers without authenticati...
May 3, 2024This vulnerability allows attackers on the same network to execute arbitrary commands as root on D-Link G416 routers without authentication. The flaw ...
May 3, 2024This vulnerability allows attackers on the same network to execute arbitrary commands as root on D-Link G416 routers without authentication. The flaw ...
May 3, 2024This vulnerability allows attackers on the same network to execute arbitrary commands as root on D-Link G416 routers without authentication. The flaw ...
May 3, 2024This vulnerability allows network-adjacent attackers to execute arbitrary code as root on D-Link G416 routers without authentication. Attackers can ex...
May 3, 2024This vulnerability allows network-adjacent attackers to execute arbitrary code as root on D-Link DAP-1325 routers without authentication. Attackers ca...
May 3, 2024This vulnerability allows authenticated remote attackers to execute arbitrary commands with root privileges on Control Web Panel installations. Attack...
May 3, 2024This vulnerability allows authenticated remote attackers to execute arbitrary commands with root privileges on Control Web Panel installations. The fl...
May 3, 2024This vulnerability allows network-adjacent attackers to execute arbitrary code as root on D-Link DAP-1325 routers without authentication. Attackers ca...
May 3, 2024This vulnerability allows network-adjacent attackers to execute arbitrary commands as root on D-Link DAP-1325 routers without authentication. Attacker...
May 3, 2024This vulnerability allows network-adjacent attackers to execute arbitrary code as root on D-Link DAP-1325 routers without authentication. The flaw exi...
May 3, 2024This vulnerability allows network-adjacent attackers to execute arbitrary commands as root on D-Link DAP-1325 routers without authentication. The flaw...
May 3, 2024This vulnerability allows network-adjacent attackers to execute arbitrary commands as root on D-Link DAP-1325 routers without authentication. Attacker...
May 3, 2024This vulnerability allows network-adjacent attackers to execute arbitrary commands as root on D-Link DAP-1325 routers without authentication. Attacker...
May 3, 2024This vulnerability allows network-adjacent attackers to execute arbitrary commands as root on D-Link DAP-1325 routers without authentication. Attacker...
May 3, 2024This vulnerability allows attackers on the same local network to execute arbitrary commands with root privileges on NETGEAR RAX30 routers without auth...
May 3, 2024This vulnerability allows network-adjacent attackers to execute arbitrary commands as root on TP-Link TL-WR841N routers without authentication. The fl...
May 3, 2024This vulnerability allows network-adjacent attackers to execute arbitrary code as root on D-Link DIR-X3260 routers without authentication. Attackers c...
May 3, 2024This vulnerability allows network-adjacent attackers to execute arbitrary code as root on D-Link DIR-2150 routers without authentication. The flaw exi...
May 3, 2024This critical vulnerability in MailCleaner allows remote attackers to execute arbitrary operating system commands through admin endpoints. It affects ...
Apr 29, 2024This vulnerability allows authenticated local attackers with read-only or higher privileges on Cisco Integrated Management Controller (IMC) devices to...
Apr 24, 2024This format string vulnerability in Lenovo's SMM/SMM2 and FPC software allows authenticated users to execute arbitrary commands on a specific API endp...
Apr 15, 2024CVE-2024-1655 is an OS command injection vulnerability in certain ASUS WiFi routers that allows authenticated remote attackers to execute arbitrary sy...
Apr 15, 2024This CVE describes an OS command injection vulnerability in Fortinet FortiSandbox that allows attackers to execute arbitrary commands on affected syst...
Apr 9, 2024CVE-2023-1082 is a command injection vulnerability that allows remote attackers with low-privileged access to execute arbitrary commands on affected s...
Apr 9, 2024This CVE describes an OS command injection vulnerability in specific ELECOM wireless LAN routers that allows an unauthenticated attacker on the same n...
Apr 4, 2024This CVE describes a command injection vulnerability in the diagnostics interface of Bosch Network Synchronizer devices. Unauthenticated attackers can...
Mar 25, 2024This vulnerability allows remote command injection in PaddlePaddle's download utility. Attackers can execute arbitrary commands on systems using vulne...
Mar 7, 2024This CVE describes an OS command injection vulnerability in multiple QNAP operating system versions that allows authenticated users to execute arbitra...
Feb 2, 2024This CVE describes an OS command injection vulnerability in BIOVIA Materials Studio products that allows attackers to execute arbitrary commands on af...
Feb 1, 2024This vulnerability allows remote attackers to execute arbitrary code on TenghuTOS TWS-200 devices by sending specially crafted commands to the ping pa...
Jan 18, 2024This vulnerability allows authenticated users to execute arbitrary commands as root by injecting payloads into the 'destination' field of network test...
Jan 12, 2024This vulnerability allows a network-adjacent attacker on the same LAN or Wi-Fi network to execute arbitrary operating system commands on affected TP-L...
Jan 11, 2024This vulnerability allows an attacker on the same local network to execute arbitrary operating system commands on affected TP-LINK devices without aut...
Jan 11, 2024This vulnerability in OX App Suite's OXMF template parser allows attackers to execute arbitrary system commands with the privileges of the non-privile...
Jan 8, 2024This CVE describes an OS command injection vulnerability in QNAP Video Station that allows authenticated users to execute arbitrary commands on the sy...
Jan 5, 2024CVE-2023-50094 is an OS command injection vulnerability in reNgine web application security scanner versions before 2.1.2. An authenticated attacker c...
Jan 1, 2024This CVE describes an authenticated command injection vulnerability in Weintek cMT2078X HMI devices running easyWeb v2.1.3 and OS v20220215. Attackers...
Dec 19, 2023This CVE describes an OS command injection vulnerability in Fortinet FortiWLM that allows attackers to execute arbitrary commands on affected systems....
Dec 13, 2023This vulnerability allows the lowest privilege user in MGT CloudPanel's File-Manager to execute arbitrary operating system commands through file owner...
Dec 8, 2023This CVE describes an OS command injection vulnerability in AE1021PE and AE1021 firmware versions 2.0.9 and earlier. Attackers who can authenticate to...
Dec 6, 2023This vulnerability allows low-privileged remote attackers to execute arbitrary system commands through file system libraries, potentially gaining full...
Dec 5, 2023A post-authentication command injection vulnerability in Zyxel NAS devices allows authenticated attackers to execute arbitrary OS commands by sending ...
Nov 30, 2023This OS command injection vulnerability in Univera Computer System Panorama allows attackers to execute arbitrary commands on the underlying operating...
Nov 28, 2023This CVE describes an OS command injection vulnerability in QuMagie that allows authenticated users to execute arbitrary commands on the system. The v...
Nov 10, 2023This vulnerability in ASUS RT-AX55 routers allows authenticated remote attackers to inject malicious commands through insufficient filtering of specia...
Nov 3, 2023This vulnerability in ASUS RT-AX55 routers allows authenticated remote attackers to inject malicious commands through insufficient filtering of specia...
Nov 3, 2023About OS Command Injection (CWE-78)
The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.
Our database tracks 1,755 CVEs classified as CWE-78, with 675 rated critical and 910 rated high severity. The average CVSS score for OS Command Injection vulnerabilities is 8.6.
External reference: View CWE-78 on MITRE CWE →
Monitor OS Command Injection Vulnerabilities
Get alerted when new OS Command Injection CVEs affect your infrastructure.
Start Monitoring Free