CWE-78: OS Command Injection

The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.

1,826
Total CVEs
722
Critical
934
High
8.6
Avg CVSS
11
In CISA KEV

Yearly Trend

2026
146
2025
465
2024
405
2023
253
2022
163

Top Affected Vendors

1 Dlink 92
2 Totolink 85
3 Dell 59
4 Fortinet 58
5 Tp Link 37
6 Zyxel 35
7 Cisco 32
8 Ruijie 30
9 Arubanetworks 27
10 Ibm 26

All OS Command Injection CVEs (1,826)

CVE-2021-23025
8.8

This vulnerability allows authenticated attackers to execute arbitrary commands on BIG-IP systems through the Configuration utility. It affects multip...

Sep 14, 2021
CVE-2021-37531
8.8

CVE-2021-37531 is an XSLT injection vulnerability in SAP NetWeaver Knowledge Management XML Forms that allows authenticated non-administrative users t...

Sep 14, 2021
CVE-2021-36182
8.8

This vulnerability allows attackers to execute arbitrary commands on Fortinet FortiWeb web application firewalls by sending specially crafted HTTP req...

Sep 8, 2021
CVE-2021-39279
8.8

This vulnerability allows authenticated attackers to execute arbitrary operating system commands on affected MOXA devices via the /forms/web_importTFT...

Sep 7, 2021
CVE-2021-39244
8.8

This vulnerability allows authenticated attackers to execute arbitrary commands on affected Altus networking devices via parameter injection in the ge...

Aug 23, 2021
CVE-2021-32772
8.8

This vulnerability allows attackers to inject malicious HTML/JavaScript into podcast feeds, which Poddycast renders without sanitization. As an Electr...

Aug 3, 2021
CVE-2021-20739
8.8

This vulnerability allows an unauthenticated attacker on the same network to execute arbitrary operating system commands on affected ELECOM wireless r...

Jul 7, 2021
CVE-2021-20740
8.8

This vulnerability allows remote authenticated attackers to execute arbitrary operating system commands with root privileges on affected Hitachi and N...

Jun 28, 2021
CVE-2021-33530
8.8

This vulnerability allows authenticated low-privilege users to execute arbitrary commands on Weidmueller Industrial WLAN devices by uploading a specia...

Jun 25, 2021
CVE-2021-33532
8.8

This vulnerability allows authenticated low-privilege users to execute arbitrary commands on Weidmueller Industrial WLAN devices through command injec...

Jun 25, 2021
CVE-2021-31769
8.8

CVE-2021-31769 allows unprivileged users to execute arbitrary operating system commands on MyQ X Smart servers. This occurs due to an authorization by...

Jun 21, 2021
CVE-2020-25755
8.8

This vulnerability allows authenticated remote attackers to execute arbitrary commands on Enphase Envoy solar energy monitoring devices via the force ...

Jun 16, 2021
CVE-2021-20731
8.8

This vulnerability allows remote attackers to execute arbitrary operating system commands with root privileges on affected Buffalo WSR-1166DHP3 and WS...

Jun 9, 2021
CVE-2020-26670
8.8

This vulnerability allows authenticated attackers to execute arbitrary operating system commands on BigTree CMS servers through the 'Create a New Sett...

Jun 1, 2021
CVE-2021-1487
8.8

This vulnerability allows authenticated remote attackers to execute arbitrary commands on Cisco Prime Infrastructure and EPN Manager systems via craft...

May 22, 2021
CVE-2021-33514
8.8

This vulnerability allows unauthenticated attackers to execute arbitrary operating system commands on affected NETGEAR smart switches by injecting mal...

May 21, 2021
CVE-2021-28151
8.8

This vulnerability allows remote attackers to execute arbitrary operating system commands on Hongdian H8922 devices by injecting shell metacharacters ...

May 6, 2021
CVE-2020-21999
8.8

This vulnerability allows authenticated attackers with default credentials to execute arbitrary operating system commands as root on iWT Ltd FaceSentr...

May 4, 2021
CVE-2020-21992
8.8

CVE-2020-21992 allows authenticated attackers to execute arbitrary OS commands with root privileges on Inim Electronics SmartLiving SmartLAN/G/SI devi...

Apr 29, 2021
CVE-2021-29147
8.8

CVE-2021-29147 is a remote command execution vulnerability in Aruba ClearPass Policy Manager that allows attackers to execute arbitrary commands on af...

Apr 29, 2021
CVE-2021-25167
8.8

This vulnerability allows remote attackers to execute arbitrary operating system commands on Aruba AirWave Management Platform systems without authent...

Apr 29, 2021
CVE-2020-21883
8.8

This CVE describes an OS command injection vulnerability in Unibox network devices that allows attackers to execute arbitrary commands on the system. ...

Apr 9, 2021
CVE-2021-25150
8.8

This vulnerability allows remote attackers to execute arbitrary commands on affected Aruba Instant Access Points (IAPs) by exploiting improper neutral...

Mar 30, 2021
CVE-2021-27273
8.8

This vulnerability allows authenticated remote attackers to execute arbitrary operating system commands on NETGEAR ProSAFE Network Management System i...

Mar 29, 2021
CVE-2020-28695
8.8

This vulnerability allows remote attackers to execute arbitrary code and retrieve admin credentials on Askey Fiber Router RTF3505VW-N1 devices. Attack...

Mar 26, 2021
CVE-2021-20017
8.8

This CVE describes a post-authentication command injection vulnerability in SonicWall SMA100 appliances. An authenticated attacker can execute arbitra...

Mar 13, 2021
CVE-2020-27575
8.8

CVE-2020-27575 is a command injection vulnerability in Maxum Rumpus web administration that allows authenticated administrators to execute arbitrary c...

Mar 8, 2021
CVE-2021-20074
8.8

CVE-2021-20074 allows authenticated users to escape the command line interface in Racom's MIDGE Firmware and execute arbitrary operating system comman...

Feb 16, 2021
CVE-2021-25297
8.8

This vulnerability allows authenticated attackers to execute arbitrary operating system commands on Nagios XI servers through improper input sanitizat...

Feb 15, 2021
CVE-2021-25310
8.8

This vulnerability allows remote authenticated attackers to execute arbitrary system commands with root privileges on Belkin Linksys WRT160NL routers....

Feb 2, 2021
CVE-2020-25036
8.8

This vulnerability allows authenticated remote attackers to escape the restricted administration shell CLI on UCOPIA Wi-Fi appliances and gain full ad...

Feb 2, 2021
CVE-2020-5626
8.8

CVE-2020-5626 allows remote attackers to execute arbitrary operating system commands by uploading a specially crafted log file to Logstorage or ELC An...

Jan 28, 2021
CVE-2021-3317
8.8

CVE-2021-3317 is an authenticated command injection vulnerability in KLog Server that allows attackers with valid credentials to execute arbitrary com...

Jan 26, 2021
CVE-2020-35576
8.8

This vulnerability allows authenticated users to execute arbitrary commands as root on TP-Link TL-WR841N V13 (JP) routers via the traceroute feature. ...

Jan 26, 2021
CVE-2020-23826
8.8

This vulnerability allows remote attackers to execute arbitrary commands on Yale WIPC-303W IP cameras through command injection in the HTTP API. Attac...

Jan 26, 2021
CVE-2020-29017
8.8

This CVE describes an OS command injection vulnerability in FortiDeceptor that allows remote authenticated attackers to execute arbitrary commands on ...

Jan 14, 2021
CVE-2020-35714
8.8

This vulnerability allows remote authenticated users to execute arbitrary commands on Belkin LINKSYS RE6500 devices via the web interface. Attackers c...

Dec 26, 2020
CVE-2020-35606
8.8

This vulnerability allows authenticated users with Package Updates module access in Webmin to execute arbitrary commands with root privileges by injec...

Dec 21, 2020
CVE-2019-14479
8.8

CVE-2019-14479 is a remote code execution vulnerability in AdRem NetCrunch network monitoring software. A read-only administrator account can execute ...

Dec 16, 2020
CVE-2020-5635
8.8

CVE-2020-5635 is an OS command injection vulnerability in Aterm SA3500G routers that allows attackers on the same network to execute arbitrary command...

Dec 14, 2020
CVE-2020-8270
8.8

This vulnerability allows unprivileged Windows users or SMB users to execute arbitrary commands with SYSTEM privileges on affected Citrix Virtual Apps...

Nov 16, 2020
CVE-2020-8273
8.8

This vulnerability allows authenticated users to escalate their privileges to root on Citrix SD-WAN Center appliances. Attackers with valid credential...

Nov 16, 2020
CVE-2020-25849
8.8

CVE-2020-25849 is a command injection vulnerability in MailGates and MailAudit email security products. Attackers who obtain a user's access token can...

Nov 1, 2020
CVE-2020-27887
8.8

CVE-2020-27887 is an authenticated remote code execution vulnerability in EyesOfNetwork's AutoDiscovery module. An authenticated user with sufficient ...

Oct 29, 2020
CVE-2020-26878
8.8

CVE-2020-26878 is a remote command injection vulnerability in Ruckus vRIoT software that allows authenticated attackers to execute arbitrary commands ...

Oct 26, 2020
CVE-2020-7752
8.8

CVE-2020-7752 is a command injection vulnerability in the systeminformation npm package that allows attackers to execute arbitrary operating system co...

Oct 26, 2020
CVE-2020-17406
8.8

This vulnerability allows authenticated remote attackers to execute arbitrary code as root on Microhard Bullet-LTE devices. The flaw exists in the too...

Oct 13, 2020
CVE-2020-26582
8.8

This vulnerability allows remote authenticated users to execute arbitrary commands on D-Link DAP-1360U wireless access points via command injection in...

Oct 6, 2020
CVE-2020-24365
8.8

This vulnerability allows authenticated attackers to execute arbitrary commands as root on affected Gemtek routers through the Monitor Diagnostic netw...

Sep 24, 2020
CVE-2020-2276
8.8

CVE-2020-2276 is a command injection vulnerability in Jenkins Selection tasks Plugin that allows attackers with Job/Configure permission to execute ar...

Sep 16, 2020

About OS Command Injection (CWE-78)

The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.

Our database tracks 1,826 CVEs classified as CWE-78, with 722 rated critical and 934 rated high severity. The average CVSS score for OS Command Injection vulnerabilities is 8.6.

External reference: View CWE-78 on MITRE CWE →

Monitor OS Command Injection Vulnerabilities

Get alerted when new OS Command Injection CVEs affect your infrastructure.

Start Monitoring Free