CWE-78: OS Command Injection

The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.

1,655
Total CVEs
619
Critical
866
High
8.5
Avg CVSS
11
In CISA KEV

Yearly Trend

2026
146
2025
465
2024
405
2023
253
2022
163

Top Affected Vendors

1 Dlink 89
2 Totolink 85
3 Dell 58
4 Fortinet 57
5 Tp Link 35
6 Zyxel 33
7 Ruijie 30
8 Cisco 27
9 Jvckenwood 26
10 Ibm 23

All OS Command Injection CVEs (1,655)

CVE-2025-60957
9.9

This OS command injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server allows attackers to execute arbitrary operating system c...

Oct 6, 2025
CVE-2025-44961
9.9

This vulnerability allows authenticated users to execute arbitrary operating system commands by injecting malicious input into an IP address field in ...

Aug 4, 2025
CVE-2025-2605
9.9

This OS command injection vulnerability in Honeywell MB-Secure allows attackers to execute arbitrary commands on affected systems, potentially leading...

May 2, 2025
CVE-2025-1265
9.9

An OS command injection vulnerability in Vinci Protocol Analyzer allows attackers to execute arbitrary commands on affected systems, potentially leadi...

Feb 20, 2025
CVE-2023-20036
9.9

This vulnerability allows authenticated remote attackers to execute arbitrary commands with SYSTEM privileges on Cisco IND devices by exploiting impro...

Nov 15, 2024
CVE-2024-20424
9.9

This vulnerability allows authenticated attackers with at least Security Analyst (Read Only) privileges to execute arbitrary commands as root on Cisco...

Oct 23, 2024
CVE-2024-39943
9.9

This vulnerability allows remote authenticated users with upload permissions to execute arbitrary operating system commands on rejetto HFS servers. Th...

Jul 4, 2024
CVE-2023-35893
9.9

CVE-2023-35893 is a critical command injection vulnerability in IBM Security Guardium that allows authenticated remote attackers to execute arbitrary ...

Aug 16, 2023
CVE-2021-43928
9.9

This CVE allows remote authenticated users to execute arbitrary operating system commands on Synology Mail Station servers through OS command injectio...

Feb 7, 2022
CVE-2021-21881
9.9

This CVE describes an OS command injection vulnerability in Lantronix PremierWave 2050's Web Manager Wireless Network Scanner. Authenticated attackers...

Dec 22, 2021
CVE-2021-21883
9.9

This CVE allows authenticated attackers to execute arbitrary operating system commands on Lantronix PremierWave 2050 devices through the Web Manager D...

Dec 22, 2021
CVE-2021-21872
9.9

This CVE describes an OS command injection vulnerability in Lantronix PremierWave 2050's Web Manager Diagnostics Traceroute functionality. An authenti...

Dec 22, 2021
CVE-2021-23031
9.9

CVE-2021-23031 is an authenticated privilege escalation vulnerability in F5 BIG-IP Advanced WAF and ASM Configuration utility. An authenticated user c...

Sep 14, 2021
CVE-2020-17363
9.9

CVE-2020-17363 is a remote code execution vulnerability in USVN (User-friendly SVN) that allows attackers to execute arbitrary commands on the server ...

Dec 31, 2020
CVE-2026-29058
9.8

CVE-2026-29058 is a critical remote code execution vulnerability in AVideo video-sharing platform where unauthenticated attackers can execute arbitrar...

Mar 6, 2026
CVE-2025-13942
9.8

A remote command injection vulnerability in Zyxel EX3510-B0 devices allows attackers to execute arbitrary operating system commands by sending special...

Feb 24, 2026
CVE-2019-25441
9.8

CVE-2019-25441 is a critical command injection vulnerability in thesystem 1.0 that allows unauthenticated attackers to execute arbitrary system comman...

Feb 20, 2026
CVE-2025-70831
9.8

An unauthenticated remote code execution vulnerability exists in Smanga 3.2.7 where the /php/path/rescan.php interface fails to sanitize the mediaId p...

Feb 20, 2026
CVE-2026-27476
9.8

RustFly 2.0.0 contains a critical command injection vulnerability in its remote UI control mechanism that accepts hex-encoded instructions over UDP po...

Feb 19, 2026
CVE-2025-15559
9.8

CVE-2025-15559 is an unauthenticated OS command injection vulnerability in NesterSoft WorkTime server's client generation API. Attackers can execute a...

Feb 19, 2026
CVE-2025-65791
9.8

CVE-2025-65791 is a critical command injection vulnerability in ZoneMinder's image.php component that allows attackers to execute arbitrary commands o...

Feb 18, 2026
CVE-2026-1731
KEV EPSS 61.4% 9.8

BeyondTrust Remote Support and older Privileged Remote Access versions contain a critical pre-authentication remote code execution vulnerability. Unau...

Feb 6, 2026
CVE-2025-64111
9.8

This vulnerability allows attackers to modify files in the .git directory of Gogs installations, potentially leading to remote command execution. It a...

Feb 6, 2026
CVE-2020-37125
9.8

CVE-2020-37125 is a critical remote code execution vulnerability in Edimax EW-7438RPn-v3 Mini range extenders that allows unauthenticated attackers to...

Feb 5, 2026
CVE-2025-51958
9.8

CVE-2025-51958 is a critical remote code execution vulnerability in the aelsantex runcommand plugin for DokuWiki. Unauthenticated attackers can execut...

Jan 30, 2026
CVE-2026-0787
9.8

CVE-2026-0787 is a command injection vulnerability in ALGO 8180 IP Audio Alerter devices that allows unauthenticated remote attackers to execute arbit...

Jan 23, 2026
CVE-2026-0755
9.8

This vulnerability allows remote attackers to execute arbitrary commands on systems running vulnerable versions of gemini-mcp-tool without authenticat...

Jan 23, 2026
CVE-2026-0756
9.8

This is a critical command injection vulnerability in github-kanban-mcp-server that allows unauthenticated remote attackers to execute arbitrary syste...

Jan 23, 2026
CVE-2026-0759
9.8

This vulnerability allows remote attackers to execute arbitrary commands on systems running Katana Network Development Starter Kit without authenticat...

Jan 23, 2026
CVE-2025-15063
9.8

This is a critical command injection vulnerability in Ollama MCP Server that allows remote attackers to execute arbitrary system commands without auth...

Jan 23, 2026
CVE-2025-15061
9.8

This vulnerability allows remote attackers to execute arbitrary code on Framelink Figma MCP Server installations without authentication. Attackers can...

Jan 23, 2026
CVE-2025-56590
9.8

This vulnerability in Apryse HTML2PDF SDK allows attackers to execute arbitrary operating system commands on servers using the InsertFromURL() functio...

Jan 22, 2026
CVE-2021-47851
9.8

Mini Mouse 9.2.0 contains an unauthenticated remote code execution vulnerability that allows attackers to execute arbitrary commands via crafted HTTP ...

Jan 21, 2026
CVE-2021-47748
9.8

CVE-2021-47748 is a critical remote code execution vulnerability in Hasura GraphQL Engine that allows attackers to execute arbitrary shell commands on...

Jan 21, 2026
CVE-2025-62193
9.8

This vulnerability allows remote, unauthenticated attackers to execute arbitrary operating system commands on NOAA PMEL Live Access Server (LAS) insta...

Jan 15, 2026
CVE-2023-54339
9.8

CVE-2023-54339 is a remote command execution vulnerability in Webgrind 1.1 that allows unauthenticated attackers to inject and execute arbitrary OS co...

Jan 13, 2026
CVE-2022-50919
9.8

CVE-2022-50919 is an unauthenticated remote code execution vulnerability in Tdarr's Help terminal that allows attackers to inject arbitrary commands. ...

Jan 13, 2026
CVE-2025-64155
9.8

This CVE describes an OS command injection vulnerability in Fortinet FortiSIEM that allows attackers to execute arbitrary commands via crafted TCP req...

Jan 13, 2026
CVE-2026-22781
9.8

TinyWeb HTTP Server versions before 1.98 are vulnerable to unauthenticated remote command injection via CGI ISINDEX-style query parameters. Attackers ...

Jan 12, 2026
CVE-2025-69269
9.8

This OS command injection vulnerability in Broadcom DX NetOps Spectrum allows attackers to execute arbitrary operating system commands on affected sys...

Jan 12, 2026
CVE-2022-50794
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary system commands on SOUND4 IMPACT/FIRST/PULSE/Eco systems by injecting shell c...

Dec 30, 2025
CVE-2022-50691
9.8

CVE-2022-50691 is a critical remote command execution vulnerability in MiniDVBLinux 5.4 that allows unauthenticated attackers to execute arbitrary com...

Dec 30, 2025
CVE-2025-14500
9.8

This vulnerability allows unauthenticated remote attackers to execute arbitrary operating system commands on IceWarp servers by injecting malicious co...

Dec 23, 2025
CVE-2023-53963
9.8

CVE-2023-53963 is an unauthenticated remote command injection vulnerability in SOUND4 IMPACT/FIRST/PULSE/Eco v2.x systems. Attackers can execute arbit...

Dec 22, 2025
CVE-2023-53941
EPSS 57.5% 9.8

EasyPHP Webserver 14.1 contains an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary system command...

Dec 18, 2025
CVE-2024-14010
9.8

Typora 1.7.4 contains a command injection vulnerability in PDF export preferences that allows attackers to execute arbitrary system commands. Attacker...

Dec 12, 2025
CVE-2021-47728
9.8

This vulnerability allows remote attackers to execute arbitrary shell commands on Selea Targa IP OCR-ANPR cameras without authentication. Attackers ca...

Dec 9, 2025
CVE-2025-65882
9.8

This vulnerability in openmptcprouter allows attackers to write arbitrary files or execute arbitrary commands via improper neutralization of special e...

Dec 9, 2025
CVE-2025-66576
9.8

CVE-2025-66576 is a critical remote code execution vulnerability in Remote Keyboard Desktop 1.0.1 that allows unauthenticated attackers to execute arb...

Dec 4, 2025
CVE-2025-29269
9.8

This vulnerability allows remote attackers to execute arbitrary operating system commands on ALLNET ALL-RUT22GW industrial LTE cellular routers via th...

Dec 4, 2025

About OS Command Injection (CWE-78)

The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.

Our database tracks 1,655 CVEs classified as CWE-78, with 619 rated critical and 866 rated high severity. The average CVSS score for OS Command Injection vulnerabilities is 8.5.

External reference: View CWE-78 on MITRE CWE →

Monitor OS Command Injection Vulnerabilities

Get alerted when new OS Command Injection CVEs affect your infrastructure.

Start Monitoring Free