CWE-78: OS Command Injection
The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.
Yearly Trend
Top Affected Vendors
All OS Command Injection CVEs (1,854)
This CVE describes a command injection vulnerability in Magnet Forensics AXIOM's Android device image acquisition functionality. Network-adjacent atta...
Aug 21, 2024This CVE describes a command injection vulnerability in Comtrend routers that allows authenticated users to execute arbitrary commands on the device b...
Jun 10, 2024This vulnerability allows network-adjacent attackers to execute arbitrary code as root on D-Link DIR-X3260 routers by exploiting a command injection f...
May 3, 2024This vulnerability allows network-adjacent attackers to execute arbitrary code as root on D-Link DIR-X3260 routers by exploiting command injection in ...
May 3, 2024This vulnerability allows network-adjacent attackers to execute arbitrary code as root on D-Link DIR-X3260 routers by exploiting a command injection f...
May 3, 2024This vulnerability allows network-adjacent attackers to execute arbitrary code as root on D-Link DIR-X3260 routers by exploiting command injection in ...
May 3, 2024This vulnerability allows network-adjacent attackers to execute arbitrary code as root on D-Link DIR-2150 routers by exploiting a command injection fl...
May 3, 2024This vulnerability allows network-adjacent attackers to execute arbitrary commands with root privileges on D-Link DIR-2150 routers by exploiting a com...
May 3, 2024This vulnerability allows network-adjacent attackers to execute arbitrary code as root on D-Link DIR-2150 routers by exploiting command injection in t...
May 3, 2024This vulnerability allows network-adjacent attackers with authentication to execute arbitrary commands as root on TP-Link Omada ER605 routers. The iss...
Apr 3, 2024This CVE describes a command injection vulnerability in Tenda AC15 routers where an attacker can execute arbitrary commands via the deviceName paramet...
Mar 29, 2024An OS command injection vulnerability in legacy QNAP VioStor NVR models allows authenticated users to execute arbitrary commands on the system via net...
Dec 8, 2023This CVE describes an OS command injection vulnerability in specific ELECOM wireless router models. An authenticated attacker on the same network can ...
Nov 16, 2023This vulnerability allows an authenticated attacker on the same network to execute arbitrary operating system commands on affected Archer AX6000 route...
Sep 6, 2023This vulnerability allows an authenticated attacker on the same network to execute arbitrary operating system commands on affected TP-Link Archer rout...
Sep 6, 2023This vulnerability allows a network-adjacent authenticated attacker to execute arbitrary operating system commands on Deco M4 mesh Wi-Fi systems. Atta...
Sep 6, 2023This CVE describes a command injection vulnerability in Zyxel firewall and WLAN controller products that allows LAN-based attackers to execute arbitra...
Jul 17, 2023This CVE describes an OS command injection vulnerability in ELECOM wireless LAN routers that allows authenticated attackers on the same network to exe...
Jul 13, 2023This vulnerability allows network-adjacent attackers to execute arbitrary code as root on TP-Link TL-WR841N routers by bypassing authentication and ex...
Mar 29, 2023This critical vulnerability allows remote attackers to execute arbitrary operating system commands on affected WAVLINK routers by manipulating the 'ke...
Jul 20, 2022This CVE-2022-2488 is a critical OS command injection vulnerability in WAVLINK WN535K2 and WN535K3 routers. Attackers can execute arbitrary commands o...
Jul 20, 2022This CVE describes an authenticated command injection vulnerability in Lenovo Personal Cloud Storage devices that allows authenticated users to execut...
May 18, 2022This vulnerability allows an authenticated attacker on the same network to execute arbitrary operating system commands on affected ELECOM LAN routers....
Dec 1, 2021This CVE describes an OS command injection vulnerability in multiple ELECOM router models that allows authenticated attackers on the same network to e...
Dec 1, 2021CVE-2020-22000 allows authenticated attackers to execute arbitrary operating system commands on HomeAutomation systems through a vulnerable plugin. Co...
Apr 27, 2021This vulnerability allows authenticated attackers to execute arbitrary commands on D-Link DIR-841 routers via the /jsonrpc endpoint. Attackers can inj...
Mar 11, 2021This vulnerability allows authenticated users to execute arbitrary operating system commands on D-Link DSL-2888A routers via a hidden execute_cmd.cgi ...
Dec 22, 2020CVE-2020-26217 is a remote code execution vulnerability in XStream that allows attackers to execute arbitrary shell commands by manipulating processed...
Nov 16, 2020This vulnerability allows network-adjacent attackers to bypass authentication and execute arbitrary code on D-Link DAP-1860 WiFi extenders via the HNA...
Jul 23, 2020This vulnerability allows attackers to execute arbitrary shell commands in melange pipelines when they can provide build input values. The issue occur...
Feb 4, 2026This CVE describes an OS command injection vulnerability in Adobe ColdFusion that allows authenticated high-privileged attackers to execute arbitrary ...
Jul 8, 2025CVE-2026-25546 is a command injection vulnerability in godot-mcp that allows remote code execution. Attackers can inject shell metacharacters through ...
Feb 4, 2026This vulnerability allows attackers to execute arbitrary shell commands on the build host by injecting shell metacharacters into melange's patch pipel...
Feb 4, 2026This vulnerability in Brocade Fabric OS allows authenticated local attackers with Bash shell access to read insecurely stored file contents, including...
Feb 3, 2026This OS command injection vulnerability in Dell UnityVSA allows low-privileged local attackers to execute arbitrary commands with root privileges. It ...
Jan 30, 2026This CVE describes an OS command injection vulnerability in Dell Unity storage systems. A low-privileged attacker with local access can execute arbitr...
Jan 30, 2026A local OS command injection vulnerability in the com.sprd.engineermode component on Doogee Note59 series devices allows attackers with ADB shell acce...
Jan 23, 2026This is a command injection vulnerability in the mcp-server-siri-shortcuts software that allows local attackers to escalate privileges. Attackers with...
Jan 23, 2026This CVE describes a command injection vulnerability in NVIDIA NSIGHT Graphics for Linux that allows attackers to execute arbitrary commands. Successf...
Jan 14, 2026This vulnerability allows attackers to execute arbitrary commands on systems running vulnerable versions of Kiro IDE by tricking users into opening ma...
Jan 9, 2026CVE-2022-50795 is a conditional command injection vulnerability in SOUND4 IMPACT/FIRST/PULSE/Eco systems up to version 2.x. Unauthenticated attackers ...
Dec 30, 2025This is a command injection vulnerability in SOUND4 IMPACT/FIRST/PULSE/Eco systems up to version 2.x. Local authenticated users can create malicious f...
Dec 30, 2025This vulnerability allows unauthenticated attackers to execute arbitrary commands on SOUND4 IMPACT/FIRST/PULSE/Eco systems by sending a single HTTP PO...
Dec 30, 2025This CVE describes an OS command injection vulnerability in Ruijie X60 PRO routers that allows attackers to execute arbitrary commands on the device. ...
Dec 11, 2025A local privilege escalation vulnerability in Windscribe VPN for Linux allows users in the windscribe group to execute arbitrary commands as root via ...
Dec 10, 2025This is a command injection vulnerability in evernote-mcp-server's openBrowser function that allows local attackers with initial low-privilege access ...
Nov 6, 2025This CVE describes an OS command injection vulnerability in Dell Unity storage systems. A low-privileged attacker with local access can execute arbitr...
Oct 30, 2025This CVE describes an OS command injection vulnerability in Dell Unity storage systems. A low-privileged attacker with local access can execute arbitr...
Oct 30, 2025CVE-2025-62801 is a command injection vulnerability in FastMCP that allows attackers to execute arbitrary operating system commands on Windows hosts b...
Oct 28, 2025This vulnerability allows local low-privileged attackers to execute arbitrary operating system commands on Dell PowerProtect Data Manager Hyper-V syst...
Sep 10, 2025About OS Command Injection (CWE-78)
The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.
Our database tracks 1,854 CVEs classified as CWE-78, with 740 rated critical and 944 rated high severity. The average CVSS score for OS Command Injection vulnerabilities is 8.6.
External reference: View CWE-78 on MITRE CWE →
Monitor OS Command Injection Vulnerabilities
Get alerted when new OS Command Injection CVEs affect your infrastructure.
Start Monitoring Free