CWE-78: OS Command Injection

The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.

1,855
Total CVEs
741
Critical
944
High
8.6
Avg CVSS
11
In CISA KEV

Yearly Trend

2026
147
2025
465
2024
405
2023
253
2022
163

Top Affected Vendors

1 Dlink 98
2 Totolink 85
3 Dell 59
4 Fortinet 58
5 Tp Link 38
6 Zyxel 35
7 Cisco 32
8 Ruijie 30
9 Arubanetworks 27
10 Ibm 26

All OS Command Injection CVEs (1,855)

CVE-2023-2091
7.8

This critical vulnerability in KylinSoft youker-assistant on KylinOS allows local attackers to execute arbitrary operating system commands through com...

Apr 15, 2023
CVE-2022-40679
7.8

This CVE-2022-40679 is an OS command injection vulnerability in multiple Fortinet products that allows authenticated attackers to execute arbitrary co...

Apr 11, 2023
CVE-2023-28617
7.8

This vulnerability allows attackers to execute arbitrary commands on systems running vulnerable versions of Org Mode for GNU Emacs. Attackers can expl...

Mar 19, 2023
CVE-2023-27985
7.8

This vulnerability in Emacs allows attackers to execute arbitrary shell commands through a malicious mailto: URI when using emacsclient-mail.desktop. ...

Mar 9, 2023
CVE-2022-27482
7.8

This CVE describes an OS command injection vulnerability in Fortinet FortiADC that allows authenticated attackers to execute arbitrary shell commands ...

Feb 16, 2023
CVE-2022-22454
7.8

CVE-2022-22454 is an OS command injection vulnerability in IBM InfoSphere Information Server that allows authenticated local attackers to execute arbi...

May 10, 2022
CVE-2022-1262
7.8

CVE-2022-1262 is a command injection vulnerability in the protest binary that allows authenticated attackers with CLI access to execute arbitrary comm...

Apr 11, 2022
CVE-2022-22301
7.8

This vulnerability allows authenticated attackers to execute arbitrary operating system commands on FortiAP-C devices by injecting malicious arguments...

Mar 2, 2022
CVE-2022-22945
7.8

CVE-2022-22945 is a CLI shell injection vulnerability in VMware NSX Edge that allows authenticated attackers with SSH access to execute arbitrary comm...

Feb 16, 2022
CVE-2021-26616
7.8

CVE-2021-26616 is an OS command injection vulnerability in SecuwaySSL that allows attackers to execute arbitrary commands on affected systems by injec...

Feb 9, 2022
CVE-2021-41016
7.8

This vulnerability allows authenticated attackers to execute arbitrary shell commands with elevated privileges on Fortinet FortiExtender devices. Atta...

Feb 2, 2022
CVE-2021-45844
7.8

CVE-2021-45844 is an OS command injection vulnerability in FreeCAD's ODA File Converter that allows attackers to execute arbitrary commands on the sys...

Jan 25, 2022
CVE-2022-23935
7.8

CVE-2022-23935 is a command injection vulnerability in ExifTool's Perl module that allows attackers to execute arbitrary commands on affected systems....

Jan 25, 2022
CVE-2021-45979
7.8

This vulnerability allows remote attackers to execute arbitrary code on macOS systems running vulnerable versions of Foxit PDF Reader and PDF Editor. ...

Jan 4, 2022
CVE-2021-34719
7.8

This vulnerability allows authenticated local users with low privileges to execute arbitrary commands with elevated privileges on Cisco IOS XR devices...

Sep 9, 2021
CVE-2021-34728
7.8

This vulnerability allows authenticated local attackers with low-privileged accounts to elevate their privileges on Cisco IOS XR devices. Attackers ca...

Sep 9, 2021
CVE-2021-3708
7.8

CVE-2021-3708 is an OS command injection vulnerability in D-Link DSL-2750U routers with firmware vME1.16 or earlier. Unauthenticated attackers on the ...

Aug 16, 2021
CVE-2021-26106
7.8

This vulnerability allows authenticated attackers to execute arbitrary operating system commands on FortiAP devices by exploiting improper input sanit...

Jul 9, 2021
CVE-2021-1421
7.8

CVE-2021-1421 is a command injection vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) that allows authenticated local attackers t...

May 6, 2021
CVE-2021-21503
7.8

CVE-2021-21503 is an improper input sanitization vulnerability in PowerScale OneFS that allows authenticated Compadmin users to execute arbitrary comm...

Mar 8, 2021
CVE-2020-36246
7.8

CVE-2020-36246 is a privilege escalation vulnerability in Amaze File Manager that allows attackers to gain root privileges by exploiting shell metacha...

Feb 19, 2021
CVE-2021-1370
7.8

This vulnerability allows authenticated local attackers on affected Cisco routers to escalate privileges to root by exploiting insufficient command li...

Feb 4, 2021
CVE-2020-3367
7.8

This vulnerability allows an authenticated local attacker on Cisco Secure Web Appliance (formerly Web Security Appliance) to execute arbitrary command...

Nov 18, 2020
CVE-2020-3459
7.8

This vulnerability in Cisco FXOS Software allows authenticated local attackers to execute arbitrary commands with root privileges by exploiting insuff...

Oct 21, 2020
CVE-2020-3403
7.8

This vulnerability allows authenticated local attackers with privileged EXEC permissions to inject commands that execute with root privileges upon dev...

Sep 24, 2020
CVE-2020-12620
7.8

CVE-2020-12620 is a command injection vulnerability in Pi-hole 4.4 that allows authenticated users with write access to /etc/pihole/dns-servers.conf t...

Jul 30, 2020
CVE-2026-27938
7.7

This CVE describes a command injection vulnerability in WPGraphQL's GitHub Actions workflow that allows arbitrary command execution when merging pull ...

Feb 26, 2026
CVE-2026-25157
7.7

OpenClaw versions before 2026.1.29 contain two command injection vulnerabilities. Attackers can execute arbitrary commands on remote SSH hosts via une...

Feb 4, 2026
CVE-2026-22035
7.7

CVE-2026-22035 is a command injection vulnerability in Greenshot screenshot utility that allows attackers to execute arbitrary operating system comman...

Jan 8, 2026
CVE-2025-30076
7.7

This vulnerability allows authenticated Koha administrators to execute arbitrary commands on the server via shell injection in the scheduler tool. Att...

Mar 16, 2025
CVE-2024-5585
7.7

This vulnerability allows remote command execution on Windows systems when using PHP's proc_open() function with array syntax. An attacker can inject ...

Jun 9, 2024
CVE-2024-32477
7.7

This vulnerability allows attackers to bypass Deno's permission prompts by injecting ANSI escape sequences into standard input during a race condition...

Apr 18, 2024
CVE-2022-24753
7.7

CVE-2022-24753 is an OS command injection vulnerability in Stripe CLI on Windows that allows arbitrary code execution when running specific commands i...

Mar 9, 2022
CVE-2021-31854
7.7

This CVE describes a local command injection vulnerability in McAfee Agent for Windows that allows authenticated local users to execute arbitrary code...

Jan 19, 2022
CVE-2021-21414
7.7

CVE-2021-21414 is an OS command injection vulnerability in Prisma's @prisma/sdk package that could allow remote code execution if the vulnerable getPa...

Apr 29, 2021
CVE-2026-27487
7.6

OpenClaw versions 2026.2.13 and below on macOS are vulnerable to OS command injection when refreshing OAuth tokens in the Keychain. This allows attack...

Feb 21, 2026
CVE-2024-2243
7.6

CVE-2024-2243 is an OS command injection vulnerability in csmock that allows authenticated users with Kerberos tickets to execute arbitrary commands o...

Apr 10, 2024
CVE-2023-34254
7.6

CVE-2023-34254 is a command injection vulnerability in GLPI Agent that allows authenticated remote administrators to execute arbitrary commands on Uni...

Jun 23, 2023
CVE-2021-22123
7.6

This CVE describes an OS command injection vulnerability in FortiWeb's management interface that allows remote authenticated attackers to execute arbi...

Jun 1, 2021
CVE-2026-27635
7.5

This vulnerability allows authenticated users to achieve remote code execution by uploading a ZIP file containing a file with shell metacharacters in ...

Feb 26, 2026
CVE-2026-26029
7.5

CVE-2026-26029 is a command injection vulnerability in sf-mcp-server that allows attackers to execute arbitrary shell commands by injecting malicious ...

Feb 11, 2026
CVE-2026-22265
7.5

CVE-2026-22265 is a command injection vulnerability in Roxy-WI web interface versions prior to 8.2.8.2 that allows authenticated users to execute arbi...

Jan 15, 2026
CVE-2025-69262
7.5

This CVE describes a command injection vulnerability in pnpm package manager versions 6.25.0 through 10.26.2. Attackers who can control environment va...

Jan 7, 2026
CVE-2025-64756
7.5

CVE-2025-64756 is a command injection vulnerability in the glob CLI tool that allows arbitrary command execution when processing files with malicious ...

Nov 17, 2025
CVE-2025-55284
7.5

CVE-2025-55284 allows attackers to bypass Claude Code's confirmation prompts to read local files and exfiltrate their contents over the network withou...

Aug 16, 2025
CVE-2025-54072
7.5

This vulnerability allows remote code execution on Windows systems when using yt-dlp with the --exec option and default placeholder. Attackers can cra...

Jul 22, 2025
CVE-2025-24366
7.5

This vulnerability allows authenticated SFTPGo users to exploit unsanitized rsync command arguments to read or write files with server process permiss...

Feb 7, 2025
CVE-2024-44759
7.5

This vulnerability allows attackers to download arbitrary files from NUS-M9 ERP Management Software v3.0.0 servers by exploiting an insecure file down...

Nov 15, 2024
CVE-2024-24426
7.5

This vulnerability allows attackers to cause denial of service in OpenAirInterface Magma and OAI EPC Federation by sending specially crafted NGAP pack...

Nov 15, 2024
CVE-2024-48963
7.5

Snyk CLI versions before 1.1294.0 are vulnerable to code injection when scanning untrusted PHP projects. Attackers can execute arbitrary code by trick...

Oct 23, 2024

About OS Command Injection (CWE-78)

The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.

Our database tracks 1,855 CVEs classified as CWE-78, with 741 rated critical and 944 rated high severity. The average CVSS score for OS Command Injection vulnerabilities is 8.6.

External reference: View CWE-78 on MITRE CWE →

Monitor OS Command Injection Vulnerabilities

Get alerted when new OS Command Injection CVEs affect your infrastructure.

Start Monitoring Free