CWE-78: OS Command Injection

The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.

1,821
Total CVEs
721
Critical
930
High
8.6
Avg CVSS
11
In CISA KEV

Yearly Trend

2026
146
2025
465
2024
405
2023
253
2022
163

Top Affected Vendors

1 Dlink 92
2 Totolink 85
3 Fortinet 58
4 Dell 58
5 Tp Link 37
6 Zyxel 35
7 Cisco 32
8 Ruijie 30
9 Arubanetworks 27
10 Jvckenwood 26

All OS Command Injection CVEs (1,821)

CVE-2022-33869
8.8

This vulnerability allows authenticated attackers to execute arbitrary operating system commands on FortiWAN devices by injecting malicious arguments ...

Feb 16, 2023
CVE-2022-46649
8.8

This vulnerability allows authenticated users of Sierra Wireless ALEOS Acemanager to manipulate IP logging operations to execute arbitrary shell comma...

Feb 10, 2023
CVE-2022-46552
8.8

This vulnerability allows remote attackers to execute arbitrary commands on D-Link DIR-846 routers via a crafted POST request to the lan(0)_dhcps_stat...

Feb 2, 2023
CVE-2022-34527
8.8

This CVE describes a command injection vulnerability in D-Link DSL-3782 routers that allows attackers to execute arbitrary commands on the device. The...

Jul 29, 2022
CVE-2022-2550
8.8

This CVE describes an OS command injection vulnerability in Hestia Control Panel that allows authenticated attackers to execute arbitrary commands on ...

Jul 27, 2022
CVE-2022-34538
8.8

This CVE describes a command injection vulnerability in Digital Watchdog DW MEGApix IP cameras that allows attackers to execute arbitrary commands on ...

Jul 19, 2022
CVE-2022-34540
8.8

This CVE describes a command injection vulnerability in Digital Watchdog DW MEGApix IP cameras that allows attackers to execute arbitrary commands on ...

Jul 19, 2022
CVE-2022-26481
8.8

CVE-2022-26481 is an authenticated command injection vulnerability in Poly Studio video conferencing systems. Attackers with administrative access can...

Jul 17, 2022
CVE-2022-34753
8.8

This CVE describes an OS command injection vulnerability in Schneider Electric's SpaceLogic C-Bus Home Controller (formerly C-Bus Wiser Homer Controll...

Jul 13, 2022
CVE-2022-31138
8.8

CVE-2022-31138 is an OS command injection vulnerability in mailcow mailserver suite that allows authenticated users to execute arbitrary code by manip...

Jul 11, 2022
CVE-2022-25048
8.8

CVE-2022-25048 is a command injection vulnerability in CentOS Web Panel (CWP) that allows authenticated users to execute arbitrary commands with root ...

Jul 7, 2022
CVE-2021-41738
8.8

ZeroShell 3.9.5 contains a command injection vulnerability in the /cgi-bin/kerbynet IP parameter that allows authenticated attackers to execute arbitr...

Jun 11, 2022
CVE-2022-31486
8.8

This vulnerability allows authenticated attackers to execute arbitrary shell commands on HID Mercury Intelligent Controllers by sending specially craf...

Jun 6, 2022
CVE-2022-30425
8.8

This vulnerability allows remote attackers to execute arbitrary commands on Tenda HG6 routers by injecting malicious commands into the pingAddr and tr...

Jun 2, 2022
CVE-2021-34081
8.8

This CVE describes an OS command injection vulnerability in the gitsome npm package that allows attackers to execute arbitrary commands on the system ...

Jun 2, 2022
CVE-2022-31245
8.8

CVE-2022-31245 is an OS command injection vulnerability in mailcow email server software that allows authenticated users to execute arbitrary commands...

May 20, 2022
CVE-2022-24388
8.8

This vulnerability allows an attacker with user-level CLI access to inject root-level commands via the rconfig 'date' parameter in Fidelis Network and...

May 17, 2022
CVE-2022-24390
8.8

This vulnerability allows authenticated attackers with CLI user-level access to execute arbitrary commands on Fidelis Network and Deception components...

May 17, 2022
CVE-2022-24392
8.8

This vulnerability allows authenticated attackers to execute arbitrary system commands on Fidelis Network and Deception CommandPost through command in...

May 17, 2022
CVE-2022-24394
8.8

This vulnerability allows authenticated attackers to execute arbitrary system commands on Fidelis Network and Deception CommandPost servers through co...

May 17, 2022
CVE-2022-26518
8.8

CVE-2022-26518 is an OS command injection vulnerability in InHand Networks InRouter302's console infactory_net functionality that allows remote attack...

May 12, 2022
CVE-2022-29937
8.8

This vulnerability allows authenticated DataCollection users in USU Oracle Optimization software to execute arbitrary OS commands with root privileges...

Apr 29, 2022
CVE-2021-46441
8.8

This vulnerability allows authenticated attackers to execute arbitrary system commands on D-Link DIR-825 G1 routers through the 'webupg' binary due to...

Apr 27, 2022
CVE-2020-27373
8.8

The Dr Trust USA iCheck Connect BP Monitor version 1.2.1 accepts plain text commands over Bluetooth Low Energy (BLE) without authentication or encrypt...

Apr 7, 2022
CVE-2022-22986
8.8

This vulnerability allows an attacker on the same network segment to execute arbitrary operating system commands on Netcommunity OG410X and OG810X ser...

Mar 31, 2022
CVE-2022-27945
8.8

CVE-2022-27945 is a command injection vulnerability in NETGEAR R8500 routers that allows authenticated remote attackers to execute arbitrary commands ...

Mar 26, 2022
CVE-2022-27947
8.8

This vulnerability allows remote authenticated attackers to execute arbitrary commands on NETGEAR R8500 routers by injecting shell metacharacters into...

Mar 26, 2022
CVE-2022-1030
8.8

This vulnerability allows command injection in Okta Advanced Server Access Client for Linux and macOS. An attacker with knowledge of a valid team name...

Mar 23, 2022
CVE-2022-24237
8.8

CVE-2022-24237 is a command injection vulnerability in Snapt Aria's snaptPowered2 component that allows authenticated attackers to execute arbitrary c...

Mar 21, 2022
CVE-2021-44827
8.8

This vulnerability allows remote authenticated attackers to execute arbitrary operating system commands with root privileges on TP-Link Archer C20i ro...

Mar 4, 2022
CVE-2022-24288
8.8

This vulnerability allows authenticated users of Apache Airflow's web UI to execute arbitrary operating system commands through improperly sanitized p...

Feb 25, 2022
CVE-2022-20650
8.8

This vulnerability allows authenticated remote attackers to execute arbitrary commands with root privileges on Cisco NX-OS devices by sending crafted ...

Feb 23, 2022
CVE-2022-25173
8.8

This vulnerability in Jenkins Pipeline: Groovy Plugin allows attackers with Item/Configure permission to execute arbitrary operating system commands o...

Feb 15, 2022
CVE-2022-25175
8.8

This vulnerability in Jenkins Pipeline: Multibranch Plugin allows attackers with Item/Configure permission to execute arbitrary operating system comma...

Feb 15, 2022
CVE-2021-43073
8.8

This OS command injection vulnerability in Fortinet FortiWeb allows attackers to execute arbitrary commands on affected devices via specially crafted ...

Feb 2, 2022
CVE-2021-32849
8.8

CVE-2021-32849 is an authenticated remote code execution vulnerability in Gerapy, a distributed crawler management framework. Authenticated users can ...

Jan 26, 2022
CVE-2021-20160
8.8

This CVE describes a command injection vulnerability in Trendnet AC2600 routers that allows attackers to execute arbitrary commands as root by injecti...

Dec 30, 2021
CVE-2021-4144
8.8

This vulnerability allows attackers to execute arbitrary operating system commands on TP-Link TL-WR802N V4(JP) routers. Attackers can potentially gain...

Dec 23, 2021
CVE-2020-19316
8.8

This CVE describes an OS command injection vulnerability in Laravel's Filesystem.php link function. It allows attackers to execute arbitrary operating...

Dec 20, 2021
CVE-2021-20144
8.8

An unauthenticated command injection vulnerability in Gryphon Tower routers allows attackers on the same network to execute arbitrary commands as root...

Dec 9, 2021
CVE-2021-20138
8.8

An unauthenticated command injection vulnerability in Gryphon Tower routers allows attackers on the same network to execute arbitrary commands as root...

Dec 9, 2021
CVE-2021-20140
8.8

An unauthenticated command injection vulnerability in Gryphon Tower routers allows attackers on the same network to execute arbitrary commands as root...

Dec 9, 2021
CVE-2021-20142
8.8

An unauthenticated command injection vulnerability in Gryphon Tower routers allows attackers on the same network to execute arbitrary commands as root...

Dec 9, 2021
CVE-2021-20044
8.8

A post-authentication remote command injection vulnerability in SonicWall SMA100 appliances allows authenticated attackers to execute arbitrary operat...

Dec 8, 2021
CVE-2021-43283
8.8

This CVE describes a command injection vulnerability in Victure WR1200 routers that allows authenticated attackers to execute arbitrary shell commands...

Nov 30, 2021
CVE-2020-7879
8.8

CVE-2020-7879 is an OS command injection vulnerability in ipTIME C200 IP cameras when synchronized with ipTIME NAS devices. Attackers can execute arbi...

Nov 30, 2021
CVE-2021-36185
8.8

This vulnerability allows attackers to execute arbitrary operating system commands on Fortinet FortiWLM systems by sending specially crafted HTTP requ...

Nov 2, 2021
CVE-2021-24684
8.8

This vulnerability allows users with Author roles in WordPress to execute arbitrary operating system commands on the server via OS command injection i...

Oct 18, 2021
CVE-2021-41315
8.8

This vulnerability allows authenticated attackers with console access to execute arbitrary operating system commands through improper input sanitizati...

Sep 17, 2021
CVE-2021-23025
8.8

This vulnerability allows authenticated attackers to execute arbitrary commands on BIG-IP systems through the Configuration utility. It affects multip...

Sep 14, 2021

About OS Command Injection (CWE-78)

The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.

Our database tracks 1,821 CVEs classified as CWE-78, with 721 rated critical and 930 rated high severity. The average CVSS score for OS Command Injection vulnerabilities is 8.6.

External reference: View CWE-78 on MITRE CWE →

Monitor OS Command Injection Vulnerabilities

Get alerted when new OS Command Injection CVEs affect your infrastructure.

Start Monitoring Free