CWE-78: OS Command Injection

The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.

1,845
Total CVEs
735
Critical
940
High
8.6
Avg CVSS
11
In CISA KEV

Yearly Trend

2026
146
2025
465
2024
405
2023
253
2022
163

Top Affected Vendors

1 Dlink 97
2 Totolink 85
3 Dell 59
4 Fortinet 58
5 Tp Link 38
6 Zyxel 35
7 Cisco 32
8 Ruijie 30
9 Arubanetworks 27
10 Ibm 26

All OS Command Injection CVEs (1,845)

CVE-2022-48684
8.4

This CVE describes a template injection vulnerability in Logpoint's search template feature that uses Jinja templating. Any authenticated user with se...

Apr 27, 2024
CVE-2024-2448
8.4

An authenticated OS command injection vulnerability in LoadMaster allows any authenticated UI user to execute arbitrary operating system commands thro...

Mar 22, 2024
CVE-2023-6926
8.4

This vulnerability allows authenticated SSH users with limited access on Crestron AM-300 devices to execute arbitrary OS commands and escalate privile...

Jan 23, 2024
CVE-2023-46306
8.4

This vulnerability allows authenticated attackers to execute arbitrary operating system commands with elevated privileges on NetModule Router Software...

Oct 22, 2023
CVE-2023-26129
8.4

CVE-2023-26129 is a command injection vulnerability in the bwm-ng npm package that allows attackers to execute arbitrary system commands on the host. ...

May 27, 2023
CVE-2021-31838
8.4

This vulnerability allows authenticated MVISION EDR administrators to execute arbitrary PowerShell commands on client systems through the 'execute rea...

Jun 29, 2021
CVE-2020-7688
8.4

CVE-2020-7688 is an OS command injection vulnerability in the mversion npm package that allows attackers to execute arbitrary commands on the host sys...

Jul 1, 2020
CVE-2013-3307
8.3

This vulnerability allows remote attackers to execute arbitrary operating system commands on affected Linksys routers by injecting shell metacharacter...

Jul 11, 2025
CVE-2024-8684
8.3

This CVE describes an OS command injection vulnerability in Revolution Pi devices that allows authenticated attackers to execute arbitrary operating s...

Feb 10, 2025
CVE-2024-42370
8.3

This CVE describes an environment variable injection vulnerability in Litestar's GitHub Actions workflow that could allow attackers to exfiltration se...

Aug 12, 2024
CVE-2024-22423
8.3

This vulnerability in yt-dlp allows remote code execution when using the --exec option with output template expansion. Attackers can exploit insuffici...

Apr 9, 2024
CVE-2023-26153
8.3

CVE-2023-26153 is a command injection vulnerability in geokit-rails Ruby gem versions before 2.5.0. Attackers can exploit unsafe YAML deserialization ...

Oct 6, 2023
CVE-2023-28102
8.3

This vulnerability in discordrb (a Ruby Discord API library) allows command injection if user-controlled input reaches a specific method. Attackers co...

Mar 27, 2023
CVE-2021-28571
8.3

CVE-2021-28571 is a command injection vulnerability in Adobe After Effects that allows arbitrary code execution when chained with JavaScript debugging...

Sep 8, 2021
CVE-2021-36011
8.3

CVE-2021-36011 is a command injection vulnerability in Adobe Illustrator that allows arbitrary code execution when chained with a JavaScript debugging...

Aug 20, 2021
CVE-2025-11774
8.2

This CVE describes an OS command injection vulnerability in Mitsubishi Electric's GENESIS64, ICONICS Suite, and MobileHMI software. A local attacker c...

Dec 19, 2025
CVE-2025-60962
8.2

This CVE describes an OS command injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server firmware. Attackers can execute arbitra...

Oct 6, 2025
CVE-2025-60963
8.2

This CVE describes an OS command injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server firmware that allows attackers to execu...

Oct 6, 2025
CVE-2025-60959
8.2

This CVE describes an OS command injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server firmware that allows attackers to execu...

Oct 6, 2025
CVE-2025-60017
8.2

This vulnerability allows remote attackers to execute arbitrary OS commands with root privileges on Unitree robotic devices by injecting malicious cod...

Sep 26, 2025
CVE-2025-30289
8.2

This CVE describes an OS command injection vulnerability in Adobe ColdFusion that allows authenticated attackers with local access to execute arbitrar...

Apr 8, 2025
CVE-2024-45720
8.2

On Windows, Subversion's command-line argument processing can misinterpret specially crafted arguments due to character encoding issues, potentially a...

Oct 9, 2024
CVE-2023-34116
8.2

An improper input validation vulnerability in Zoom Desktop Client for Windows allows unauthorized users to escalate privileges via network access. Thi...

Jul 11, 2023
CVE-2022-1360
8.2

CVE-2022-1360 is an OS command injection vulnerability in Cambium Networks cnMaestro On-Premise that allows remote attackers to execute arbitrary comm...

May 17, 2022
CVE-2021-28634
8.2

This vulnerability allows authenticated attackers to execute arbitrary code on systems running vulnerable versions of Adobe Acrobat Reader DC by trick...

Aug 20, 2021
CVE-2021-1602
8.2

This vulnerability allows unauthenticated remote attackers to execute arbitrary commands with root privileges on affected Cisco Small Business VPN rou...

Aug 4, 2021
CVE-2021-23012
8.2

This vulnerability allows authenticated users with Resource Administrator or Administrator roles on affected BIG-IP systems to execute arbitrary bash ...

May 10, 2021
CVE-2020-12774
8.2

This vulnerability in D-Link DSL-7740C routers allows authenticated LAN users to execute arbitrary commands through improper input validation. Attacke...

Jul 22, 2020
CVE-2026-27190
8.1

This CVE describes a command injection vulnerability in Deno's node:child_process implementation that allows attackers to execute arbitrary commands o...

Feb 20, 2026
CVE-2025-68154
8.1

CVE-2025-68154 is an OS command injection vulnerability in the systeminformation library for Node.js. On Windows systems, the fsSize() function improp...

Dec 16, 2025
CVE-2025-63916
8.1

MyScreenTools v2.2.1.0 contains a critical OS command injection vulnerability in its GIF compression tool. Attackers can execute arbitrary system comm...

Nov 17, 2025
CVE-2025-58370
8.1

CVE-2025-58370 is a command injection vulnerability in Roo Code's Bash parameter expansion handling that allows attackers to execute arbitrary command...

Sep 5, 2025
CVE-2025-57771
8.1

This vulnerability allows command injection in Roo Code's auto-execute feature when processing crafted prompts. Attackers with access to submit prompt...

Aug 22, 2025
CVE-2024-8926
8.1

This CVE allows command injection in PHP on Windows systems with specific non-standard codepage configurations, bypassing previous CVE-2024-4577 fixes...

Oct 8, 2024
CVE-2024-42057
8.1

This CVE describes a command injection vulnerability in Zyxel firewall devices that allows unauthenticated attackers to execute operating system comma...

Sep 3, 2024
CVE-2024-41956
8.1

This vulnerability allows authenticated users who can commit files to Soft Serve Git repositories to execute arbitrary code on the server. Attackers c...

Aug 1, 2024
CVE-2024-32937
8.1

This CVE describes an OS command injection vulnerability in Grandstream GXP2135 IP phones' CWMP SelfDefinedTimeZone functionality. Attackers can send ...

Jul 3, 2024
CVE-2024-24892
8.1

This vulnerability allows attackers to execute arbitrary operating system commands on systems running vulnerable versions of openEuler migration-tools...

Mar 25, 2024
CVE-2023-3314
8.1

This vulnerability allows attackers to execute arbitrary commands on systems by exploiting improper sanitization of zip file processing. An authorized...

Jul 3, 2023
CVE-2023-32548
8.1

This CVE describes an OS command injection vulnerability in WPS Office that allows remote attackers to execute arbitrary commands on affected systems....

Jun 13, 2023
CVE-2023-31128
8.1

This CVE describes a command injection vulnerability in NextCloud Cookbook's GitHub Actions workflow. Attackers with write access to the repository ca...

May 26, 2023
CVE-2021-36180
8.1

This vulnerability allows authenticated attackers to execute arbitrary commands on FortiWeb web application firewalls by sending specially crafted HTT...

Dec 8, 2021
CVE-2021-3059
8.1

This CVE-2021-3059 is an OS command injection vulnerability in Palo Alto Networks PAN-OS management interface that allows man-in-the-middle attackers ...

Nov 10, 2021
CVE-2021-35062
8.1

CVE-2021-35062 is a shell command injection vulnerability in the DRK Odenwaldkreis Testerfassung COVID-19 test result system. Attackers with a valid t...

Aug 30, 2021
CVE-2021-23412
8.1

CVE-2021-23412 is a command injection vulnerability in the gitlogplus npm package that allows attackers to execute arbitrary commands on the host syst...

Jul 23, 2021
CVE-2021-0265
8.1

CVE-2021-0265 is an unauthenticated remote code execution vulnerability in Juniper Networks AppFormix Agent's REST API. Attackers can execute arbitrar...

Apr 22, 2021
CVE-2021-25162
8.1

This vulnerability allows remote attackers to execute arbitrary commands on affected Aruba Instant Access Point devices without authentication. It aff...

Mar 30, 2021
CVE-2020-35851
8.1

CVE-2020-35851 is a command injection vulnerability in HGiga MailSherlock email security appliances. Attackers can exploit improper parameter validati...

Dec 31, 2020
CVE-2020-26245
8.1

This vulnerability in the systeminformation npm package allows attackers to execute arbitrary commands on affected systems through prototype pollution...

Nov 27, 2020
CVE-2026-22223
8.0

An OS command injection vulnerability in TP-Link Archer BE230 routers allows adjacent authenticated attackers to execute arbitrary commands. This coul...

Feb 2, 2026

About OS Command Injection (CWE-78)

The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.

Our database tracks 1,845 CVEs classified as CWE-78, with 735 rated critical and 940 rated high severity. The average CVSS score for OS Command Injection vulnerabilities is 8.6.

External reference: View CWE-78 on MITRE CWE →

Monitor OS Command Injection Vulnerabilities

Get alerted when new OS Command Injection CVEs affect your infrastructure.

Start Monitoring Free