CWE-78: OS Command Injection

The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.

1,840
Total CVEs
734
Critical
936
High
8.6
Avg CVSS
11
In CISA KEV

Yearly Trend

2026
146
2025
465
2024
405
2023
253
2022
163

Top Affected Vendors

1 Dlink 95
2 Totolink 85
3 Dell 59
4 Fortinet 58
5 Tp Link 38
6 Zyxel 35
7 Cisco 32
8 Ruijie 30
9 Arubanetworks 27
10 Ibm 26

All OS Command Injection CVEs (1,840)

CVE-2019-14479
8.8

CVE-2019-14479 is a remote code execution vulnerability in AdRem NetCrunch network monitoring software. A read-only administrator account can execute ...

Dec 16, 2020
CVE-2020-5635
8.8

CVE-2020-5635 is an OS command injection vulnerability in Aterm SA3500G routers that allows attackers on the same network to execute arbitrary command...

Dec 14, 2020
CVE-2020-8270
8.8

This vulnerability allows unprivileged Windows users or SMB users to execute arbitrary commands with SYSTEM privileges on affected Citrix Virtual Apps...

Nov 16, 2020
CVE-2020-8273
8.8

This vulnerability allows authenticated users to escalate their privileges to root on Citrix SD-WAN Center appliances. Attackers with valid credential...

Nov 16, 2020
CVE-2020-25849
8.8

CVE-2020-25849 is a command injection vulnerability in MailGates and MailAudit email security products. Attackers who obtain a user's access token can...

Nov 1, 2020
CVE-2020-27887
8.8

CVE-2020-27887 is an authenticated remote code execution vulnerability in EyesOfNetwork's AutoDiscovery module. An authenticated user with sufficient ...

Oct 29, 2020
CVE-2020-26878
8.8

CVE-2020-26878 is a remote command injection vulnerability in Ruckus vRIoT software that allows authenticated attackers to execute arbitrary commands ...

Oct 26, 2020
CVE-2020-7752
8.8

CVE-2020-7752 is a command injection vulnerability in the systeminformation npm package that allows attackers to execute arbitrary operating system co...

Oct 26, 2020
CVE-2020-17406
8.8

This vulnerability allows authenticated remote attackers to execute arbitrary code as root on Microhard Bullet-LTE devices. The flaw exists in the too...

Oct 13, 2020
CVE-2020-26582
8.8

This vulnerability allows remote authenticated users to execute arbitrary commands on D-Link DAP-1360U wireless access points via command injection in...

Oct 6, 2020
CVE-2020-24365
8.8

This vulnerability allows authenticated attackers to execute arbitrary commands as root on affected Gemtek routers through the Monitor Diagnostic netw...

Sep 24, 2020
CVE-2020-2276
8.8

CVE-2020-2276 is a command injection vulnerability in Jenkins Selection tasks Plugin that allows attackers with Job/Configure permission to execute ar...

Sep 16, 2020
CVE-2020-2261
8.8

CVE-2020-2261 is an OS command injection vulnerability in Jenkins Perfecto Plugin that allows attackers with Job/Configure permission to execute arbit...

Sep 16, 2020
CVE-2020-3430
8.8

This vulnerability in Cisco Jabber for Windows allows remote attackers to execute arbitrary commands by tricking users into clicking malicious links. ...

Sep 4, 2020
CVE-2020-24354
8.8

This vulnerability allows remote attackers to execute arbitrary shell commands on affected Zyxel VMG5313-B30B routers through shell injection. Attacke...

Aug 31, 2020
CVE-2020-23934
8.8

CVE-2020-23934 is an authenticated remote code execution vulnerability in RiteCMS 2.2.1 that allows authenticated users to upload PHP web shells via t...

Aug 18, 2020
CVE-2020-13124
8.8

This CVE describes a command injection vulnerability in SABnzbd's web configuration interface that allows authenticated users to execute arbitrary Pyt...

Aug 11, 2020
CVE-2020-17352
8.8

Two OS command injection vulnerabilities in the Sophos XG Firewall User Portal allow authenticated attackers to execute arbitrary commands on the fire...

Aug 7, 2020
CVE-2020-11852
8.8

This vulnerability allows authenticated users with DKIM key management privileges to execute arbitrary system commands on Micro Focus Secure Messaging...

Aug 7, 2020
CVE-2020-13404
8.8

This vulnerability allows remote command injection in the ATOS/Sips payment module for Magento. Attackers can execute arbitrary system commands on ser...

Aug 5, 2020
CVE-2020-7825
8.8

This vulnerability allows remote command execution on MiPlatform systems by exploiting improper input validation in the ExtCommandApi.dll module. Atta...

Jul 17, 2020
CVE-2020-11953
8.8

This vulnerability allows attackers to execute arbitrary code on affected Rittal PDU and CMCIII devices through OS command injection. Organizations us...

Jul 14, 2020
CVE-2020-5352
8.8

This vulnerability allows remote authenticated attackers to execute arbitrary operating system commands on Dell EMC Data Protection Advisor systems th...

Jul 6, 2020
CVE-2025-53868
8.7

This vulnerability allows authenticated attackers with SCP/SFTP access to bypass Appliance mode restrictions on affected F5 systems using undisclosed ...

Oct 15, 2025
CVE-2021-34362
8.7

This CVE-2021-34362 is a command injection vulnerability in QNAP's Media Streaming add-on that allows remote attackers to execute arbitrary commands o...

Oct 22, 2021
CVE-2026-21267
8.6

This CVE describes an OS command injection vulnerability in Adobe Dreamweaver Desktop versions 21.6 and earlier. Attackers can execute arbitrary code ...

Jan 13, 2026
CVE-2025-64091
8.6

This vulnerability allows authenticated attackers to execute arbitrary operating system commands by manipulating NTP configuration settings on affecte...

Jan 9, 2026
CVE-2025-27614
8.6

CVE-2025-27614 is a command injection vulnerability in Gitk that allows attackers to execute arbitrary scripts on a user's system by tricking them int...

Jul 10, 2025
CVE-2023-3454
8.6

This CVE describes a remote code execution vulnerability in Brocade Fabric OS that allows attackers to execute arbitrary code and gain root access to ...

Apr 4, 2024
CVE-2023-35174
8.6

CVE-2023-35174 is a remote code execution vulnerability in Livebook Desktop on Windows. Attackers can craft malicious livebook:// links that, when cli...

Jun 22, 2023
CVE-2020-28494
8.6

This vulnerability allows remote command injection in total.js framework versions before 3.4.7. Attackers can execute arbitrary commands on the server...

Feb 2, 2021
CVE-2025-67738
8.5

This vulnerability in Webmin's Squid module allows authenticated users with Cache Manager permissions to execute arbitrary commands on the server thro...

Dec 11, 2025
CVE-2025-54135
8.5

Cursor code editor versions below 1.3.9 allow attackers to exploit indirect prompt injection to write malicious MCP configuration files without user a...

Aug 5, 2025
CVE-2025-44960
8.5

CVE-2025-44960 is an OS command injection vulnerability in RUCKUS SmartZone (SZ) network management software. Attackers can execute arbitrary commands...

Aug 4, 2025
CVE-2025-49141
8.5

CVE-2025-49141 is an OS command injection vulnerability in HAX CMS PHP's gitImportSite functionality. Authenticated attackers can execute arbitrary co...

Jun 9, 2025
CVE-2025-24022
8.5

This vulnerability allows remote code execution through iTop's web portal frontend. Attackers can execute arbitrary commands on the server by exploiti...

May 14, 2025
CVE-2023-25925
8.5

This vulnerability allows authenticated remote attackers to execute arbitrary operating system commands on IBM Security Guardium Key Lifecycle Manager...

Feb 28, 2024
CVE-2026-26280
8.4

This CVE describes a command injection vulnerability in the systeminformation Node.js library's wifiNetworks() function. Attackers can execute arbitra...

Feb 19, 2026
CVE-2026-25593
8.4

OpenClaw personal AI assistant versions before 2026.1.20 contain a command injection vulnerability. Unauthenticated local clients can exploit the Gate...

Feb 6, 2026
CVE-2025-13444
8.4

This CVE describes an OS command injection vulnerability in Progress LoadMaster's API that allows authenticated attackers with 'User Administration' p...

Jan 13, 2026
CVE-2026-0507
8.4

This CVE describes an OS command injection vulnerability in SAP Application Server for ABAP and SAP NetWeaver RFCSDK. An authenticated attacker with a...

Jan 13, 2026
CVE-2025-45379
8.4

This vulnerability allows a privileged user with known credentials to execute arbitrary commands through command injection in Dell CloudLink, potentia...

Nov 5, 2025
CVE-2025-30479
8.4

Dell CloudLink versions before 8.2 contain an OS command injection vulnerability (CWE-78) where authenticated privileged users can execute arbitrary c...

Nov 5, 2025
CVE-2025-0636
8.4

CVE-2025-0636 is an OS command injection vulnerability in EMCLI that allows attackers to execute arbitrary commands on affected systems. This high-sev...

Oct 13, 2025
CVE-2025-24938
8.4

This vulnerability allows authenticated administrators to execute arbitrary operating system commands through the web application's user management in...

Jul 21, 2025
CVE-2025-22495
8.4

An improper input validation vulnerability in the NTP server configuration field of Eaton Network-M2 cards allows authenticated high-privileged users ...

Feb 24, 2025
CVE-2024-39401
8.4

This CVE describes an OS command injection vulnerability in Adobe Commerce that allows authenticated admin users to execute arbitrary commands on the ...

Aug 14, 2024
CVE-2024-3126
8.4

This CVE describes a command injection vulnerability in the parisneo/lollms-webui application that allows remote attackers to execute arbitrary comman...

May 16, 2024
CVE-2024-1628
8.4

This CVE describes OS command injection vulnerabilities in GE HealthCare ultrasound devices that allow attackers to execute arbitrary commands on affe...

May 14, 2024
CVE-2022-48684
8.4

This CVE describes a template injection vulnerability in Logpoint's search template feature that uses Jinja templating. Any authenticated user with se...

Apr 27, 2024

About OS Command Injection (CWE-78)

The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.

Our database tracks 1,840 CVEs classified as CWE-78, with 734 rated critical and 936 rated high severity. The average CVSS score for OS Command Injection vulnerabilities is 8.6.

External reference: View CWE-78 on MITRE CWE →

Monitor OS Command Injection Vulnerabilities

Get alerted when new OS Command Injection CVEs affect your infrastructure.

Start Monitoring Free