CWE-78: OS Command Injection

The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.

1,854
Total CVEs
740
Critical
944
High
8.6
Avg CVSS
11
In CISA KEV

Yearly Trend

2026
146
2025
465
2024
405
2023
253
2022
163

Top Affected Vendors

1 Dlink 98
2 Totolink 85
3 Dell 59
4 Fortinet 58
5 Tp Link 38
6 Zyxel 35
7 Cisco 32
8 Ruijie 30
9 Arubanetworks 27
10 Ibm 26

All OS Command Injection CVEs (1,854)

CVE-2024-7448
8.0

This CVE describes a command injection vulnerability in Magnet Forensics AXIOM's Android device image acquisition functionality. Network-adjacent atta...

Aug 21, 2024
CVE-2024-5785
8.0

This CVE describes a command injection vulnerability in Comtrend routers that allows authenticated users to execute arbitrary commands on the device b...

Jun 10, 2024
CVE-2023-44427
8.0

This vulnerability allows network-adjacent attackers to execute arbitrary code as root on D-Link DIR-X3260 routers by exploiting a command injection f...

May 3, 2024
CVE-2023-44421
8.0

This vulnerability allows network-adjacent attackers to execute arbitrary code as root on D-Link DIR-X3260 routers by exploiting command injection in ...

May 3, 2024
CVE-2023-44423
8.0

This vulnerability allows network-adjacent attackers to execute arbitrary code as root on D-Link DIR-X3260 routers by exploiting a command injection f...

May 3, 2024
CVE-2023-44425
8.0

This vulnerability allows network-adjacent attackers to execute arbitrary code as root on D-Link DIR-X3260 routers by exploiting command injection in ...

May 3, 2024
CVE-2023-34281
8.0

This vulnerability allows network-adjacent attackers to execute arbitrary code as root on D-Link DIR-2150 routers by exploiting a command injection fl...

May 3, 2024
CVE-2023-34275
8.0

This vulnerability allows network-adjacent attackers to execute arbitrary commands with root privileges on D-Link DIR-2150 routers by exploiting a com...

May 3, 2024
CVE-2023-34277
8.0

This vulnerability allows network-adjacent attackers to execute arbitrary code as root on D-Link DIR-2150 routers by exploiting command injection in t...

May 3, 2024
CVE-2024-1180
8.0

This vulnerability allows network-adjacent attackers with authentication to execute arbitrary commands as root on TP-Link Omada ER605 routers. The iss...

Apr 3, 2024
CVE-2024-30645
8.0

This CVE describes a command injection vulnerability in Tenda AC15 routers where an attacker can execute arbitrary commands via the deviceName paramet...

Mar 29, 2024
CVE-2023-47565
8.0

An OS command injection vulnerability in legacy QNAP VioStor NVR models allows authenticated users to execute arbitrary commands on the system via net...

Dec 8, 2023
CVE-2023-43752
8.0

This CVE describes an OS command injection vulnerability in specific ELECOM wireless router models. An authenticated attacker on the same network can ...

Nov 16, 2023
CVE-2023-40531
8.0

This vulnerability allows an authenticated attacker on the same network to execute arbitrary operating system commands on affected Archer AX6000 route...

Sep 6, 2023
CVE-2023-39224
8.0

This vulnerability allows an authenticated attacker on the same network to execute arbitrary operating system commands on affected TP-Link Archer rout...

Sep 6, 2023
CVE-2023-40193
8.0

This vulnerability allows a network-adjacent authenticated attacker to execute arbitrary operating system commands on Deco M4 mesh Wi-Fi systems. Atta...

Sep 6, 2023
CVE-2023-34141
8.0

This CVE describes a command injection vulnerability in Zyxel firewall and WLAN controller products that allows LAN-based attackers to execute arbitra...

Jul 17, 2023
CVE-2023-37564
8.0

This CVE describes an OS command injection vulnerability in ELECOM wireless LAN routers that allows authenticated attackers on the same network to exe...

Jul 13, 2023
CVE-2022-42433
8.0

This vulnerability allows network-adjacent attackers to execute arbitrary code as root on TP-Link TL-WR841N routers by bypassing authentication and ex...

Mar 29, 2023
CVE-2022-2486
8.0

This critical vulnerability allows remote attackers to execute arbitrary operating system commands on affected WAVLINK routers by manipulating the 'ke...

Jul 20, 2022
CVE-2022-2488
8.0

This CVE-2022-2488 is a critical OS command injection vulnerability in WAVLINK WN535K2 and WN535K3 routers. Attackers can execute arbitrary commands o...

Jul 20, 2022
CVE-2021-42852
8.0

This CVE describes an authenticated command injection vulnerability in Lenovo Personal Cloud Storage devices that allows authenticated users to execut...

May 18, 2022
CVE-2021-20859
8.0

This vulnerability allows an authenticated attacker on the same network to execute arbitrary operating system commands on affected ELECOM LAN routers....

Dec 1, 2021
CVE-2021-20863
8.0

This CVE describes an OS command injection vulnerability in multiple ELECOM router models that allows authenticated attackers on the same network to e...

Dec 1, 2021
CVE-2020-22000
8.0

CVE-2020-22000 allows authenticated attackers to execute arbitrary operating system commands on HomeAutomation systems through a vulnerable plugin. Co...

Apr 27, 2021
CVE-2021-28143
8.0

This vulnerability allows authenticated attackers to execute arbitrary commands on D-Link DIR-841 routers via the /jsonrpc endpoint. Attackers can inj...

Mar 11, 2021
CVE-2020-24581
8.0

This vulnerability allows authenticated users to execute arbitrary operating system commands on D-Link DSL-2888A routers via a hidden execute_cmd.cgi ...

Dec 22, 2020
CVE-2020-26217
8.0

CVE-2020-26217 is a remote code execution vulnerability in XStream that allows attackers to execute arbitrary shell commands by manipulating processed...

Nov 16, 2020
CVE-2020-15631
8.0

This vulnerability allows network-adjacent attackers to bypass authentication and execute arbitrary code on D-Link DAP-1860 WiFi extenders via the HNA...

Jul 23, 2020
CVE-2026-24844
7.9

This vulnerability allows attackers to execute arbitrary shell commands in melange pipelines when they can provide build input values. The issue occur...

Feb 4, 2026
CVE-2025-49537
7.9

This CVE describes an OS command injection vulnerability in Adobe ColdFusion that allows authenticated high-privileged attackers to execute arbitrary ...

Jul 8, 2025
CVE-2026-25546
7.8

CVE-2026-25546 is a command injection vulnerability in godot-mcp that allows remote code execution. Attackers can inject shell metacharacters through ...

Feb 4, 2026
CVE-2026-25143
7.8

This vulnerability allows attackers to execute arbitrary shell commands on the build host by injecting shell metacharacters into melange's patch pipel...

Feb 4, 2026
CVE-2026-0383
7.8

This vulnerability in Brocade Fabric OS allows authenticated local attackers with Bash shell access to read insecurely stored file contents, including...

Feb 3, 2026
CVE-2026-22277
7.8

This OS command injection vulnerability in Dell UnityVSA allows low-privileged local attackers to execute arbitrary commands with root privileges. It ...

Jan 30, 2026
CVE-2026-21418
7.8

This CVE describes an OS command injection vulnerability in Dell Unity storage systems. A low-privileged attacker with local access can execute arbitr...

Jan 30, 2026
CVE-2025-67264
7.8

A local OS command injection vulnerability in the com.sprd.engineermode component on Doogee Note59 series devices allows attackers with ADB shell acce...

Jan 23, 2026
CVE-2026-0758
7.8

This is a command injection vulnerability in the mcp-server-siri-shortcuts software that allows local attackers to escalate privileges. Attackers with...

Jan 23, 2026
CVE-2025-33206
7.8

This CVE describes a command injection vulnerability in NVIDIA NSIGHT Graphics for Linux that allows attackers to execute arbitrary commands. Successf...

Jan 14, 2026
CVE-2026-0830
7.8

This vulnerability allows attackers to execute arbitrary commands on systems running vulnerable versions of Kiro IDE by tricking users into opening ma...

Jan 9, 2026
CVE-2022-50795
7.8

CVE-2022-50795 is a conditional command injection vulnerability in SOUND4 IMPACT/FIRST/PULSE/Eco systems up to version 2.x. Unauthenticated attackers ...

Dec 30, 2025
CVE-2022-50789
7.8

This is a command injection vulnerability in SOUND4 IMPACT/FIRST/PULSE/Eco systems up to version 2.x. Local authenticated users can create malicious f...

Dec 30, 2025
CVE-2022-50791
7.8

This vulnerability allows unauthenticated attackers to execute arbitrary commands on SOUND4 IMPACT/FIRST/PULSE/Eco systems by sending a single HTTP PO...

Dec 30, 2025
CVE-2025-56124
7.8

This CVE describes an OS command injection vulnerability in Ruijie X60 PRO routers that allows attackers to execute arbitrary commands on the device. ...

Dec 11, 2025
CVE-2025-65199
7.8

A local privilege escalation vulnerability in Windscribe VPN for Linux allows users in the windscribe group to execute arbitrary commands as root via ...

Dec 10, 2025
CVE-2025-12489
7.8

This is a command injection vulnerability in evernote-mcp-server's openBrowser function that allows local attackers with initial low-privilege access ...

Nov 6, 2025
CVE-2025-46422
7.8

This CVE describes an OS command injection vulnerability in Dell Unity storage systems. A low-privileged attacker with local access can execute arbitr...

Oct 30, 2025
CVE-2025-43939
7.8

This CVE describes an OS command injection vulnerability in Dell Unity storage systems. A low-privileged attacker with local access can execute arbitr...

Oct 30, 2025
CVE-2025-62801
7.8

CVE-2025-62801 is a command injection vulnerability in FastMCP that allows attackers to execute arbitrary operating system commands on Windows hosts b...

Oct 28, 2025
CVE-2025-43885
7.8

This vulnerability allows local low-privileged attackers to execute arbitrary operating system commands on Dell PowerProtect Data Manager Hyper-V syst...

Sep 10, 2025

About OS Command Injection (CWE-78)

The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.

Our database tracks 1,854 CVEs classified as CWE-78, with 740 rated critical and 944 rated high severity. The average CVSS score for OS Command Injection vulnerabilities is 8.6.

External reference: View CWE-78 on MITRE CWE →

Monitor OS Command Injection Vulnerabilities

Get alerted when new OS Command Injection CVEs affect your infrastructure.

Start Monitoring Free