CWE-78: OS Command Injection

The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.

1,855
Total CVEs
741
Critical
944
High
8.6
Avg CVSS
11
In CISA KEV

Yearly Trend

2026
147
2025
465
2024
405
2023
253
2022
163

Top Affected Vendors

1 Dlink 98
2 Totolink 85
3 Dell 59
4 Fortinet 58
5 Tp Link 38
6 Zyxel 35
7 Cisco 32
8 Ruijie 30
9 Arubanetworks 27
10 Ibm 26

All OS Command Injection CVEs (1,855)

CVE-2024-8234
7.5

An unauthenticated command injection vulnerability in Zyxel NWA1100-N firmware allows attackers to execute arbitrary OS commands and access system fil...

Aug 30, 2024
CVE-2024-5227
7.5

This vulnerability allows network-adjacent attackers to execute arbitrary commands as root on TP-Link Omada ER605 routers by injecting malicious comma...

May 23, 2024
CVE-2024-33112
7.5

This CVE describes a command injection vulnerability in D-Link DIR-845L routers that allows attackers to execute arbitrary commands on the device. The...

May 6, 2024
CVE-2024-27124
7.5

This CVE describes an OS command injection vulnerability in multiple QNAP operating system versions that allows authenticated users to execute arbitra...

Apr 26, 2024
CVE-2023-47415
7.5

CVE-2023-47415 is an OS command injection vulnerability in Cypress Solutions CTM-200 devices that allows attackers to execute arbitrary commands on th...

Mar 7, 2024
CVE-2023-28726
7.5

This vulnerability allows remote attackers to execute arbitrary operating system commands on Panasonic AiSEG2 home energy management systems. Attacker...

Mar 31, 2023
CVE-2021-3725
7.5

CVE-2021-3725 is a command injection vulnerability in the dirhistory plugin for Oh My Zsh. It allows attackers to execute arbitrary commands by tricki...

Nov 30, 2021
CVE-2021-3727
7.5

This CVE-2021-3727 is a command injection vulnerability in Oh My Zsh's rand-quote and hitokoto plugins. When these plugins fetch quotes from external ...

Nov 30, 2021
CVE-2021-41228
7.5

TensorFlow's saved_model_cli tool is vulnerable to code injection via unsafe eval() calls on user-supplied strings, allowing attackers to execute arbi...

Nov 5, 2021
CVE-2020-26301
7.5

CVE-2020-26301 is a command injection vulnerability in the ssh2 npm package that allows remote code execution on Windows systems. Attackers can execut...

Sep 20, 2021
CVE-2021-32751
7.5

CVE-2021-32751 allows arbitrary code execution when attackers can manipulate environment variables for users running vulnerable Gradle start scripts o...

Jul 20, 2021
CVE-2021-23359
7.5

CVE-2021-23359 is a command injection vulnerability in the port-killer npm package that allows attackers to execute arbitrary commands on the system. ...

Mar 18, 2021
CVE-2020-12513
7.5

This vulnerability allows authenticated attackers to execute arbitrary operating system commands on Pepperl+Fuchs Comtrol IO-Link Master devices. Atta...

Jan 22, 2021
CVE-2020-14293
7.5

CVE-2020-14293 is an OS command injection vulnerability in Secudos DOMOS 5.8 that allows remote attackers to execute arbitrary commands as root via sh...

Oct 2, 2020
CVE-2025-68922
7.4

CVE-2025-68922 is a remote code execution vulnerability in OpenOps that allows attackers to execute arbitrary commands via the Terraform block. This a...

Dec 25, 2025
CVE-2025-30370
7.4

This vulnerability in jupyterlab-git allows command injection when users open maliciously-named Git repositories via the 'Open Git Repository in Termi...

Apr 3, 2025
CVE-2024-46330
7.4

This CVE describes a command injection vulnerability in VONETS VAP11G-300 devices that allows attackers to execute arbitrary commands on the system. T...

Sep 26, 2024
CVE-2024-43405
7.4

This vulnerability allows attackers to bypass Nuclei's template signature verification by exploiting a discrepancy in how newline characters are handl...

Sep 4, 2024
CVE-2024-40641
7.4

This vulnerability in Nuclei allows attackers to execute arbitrary commands without requiring the -code option, bypassing intended security controls. ...

Jul 17, 2024
CVE-2024-27920
7.4

This vulnerability in Nuclei v3 allows execution of unsigned code templates through workflows, potentially enabling attackers to run malicious code on...

Mar 15, 2024
CVE-2023-48380
7.4

Softnext Mail SQR Expert has a command injection vulnerability (CWE-78) where authenticated localhost users can execute arbitrary system commands due ...

Dec 15, 2023
CVE-2022-25853
7.4

CVE-2022-25853 is a command injection vulnerability in the semver-tags npm package that allows attackers to execute arbitrary commands on the host sys...

Feb 6, 2023
CVE-2022-25906
7.4

CVE-2022-25906 is a command injection vulnerability in the is-http2 npm package that allows attackers to execute arbitrary commands on affected system...

Feb 1, 2023
CVE-2021-42324
7.4

This vulnerability allows authenticated low-privileged attackers with physical access to DCN S4600-10P-SI switches to escape the sandbox environment a...

Apr 5, 2022
CVE-2021-21289
7.4

CVE-2021-21289 is a command injection vulnerability in the Mechanize Ruby library that allows attackers to execute arbitrary operating system commands...

Feb 2, 2021
CVE-2020-15778
7.4

CVE-2020-15778 is a command injection vulnerability in the scp client of OpenSSH, allowing attackers to execute arbitrary commands on a remote server ...

Jul 24, 2020
CVE-2020-15121
7.4

CVE-2020-15121 is a shell injection vulnerability in radare2 reverse engineering framework where malformed PDB file names in the PDB server path allow...

Jul 20, 2020
CVE-2025-33228
7.3

NVIDIA Nsight Systems contains an OS command injection vulnerability in the gfx_hotspot recipe. Attackers can execute arbitrary commands by supplying ...

Jan 20, 2026
CVE-2025-33230
7.3

This vulnerability allows attackers to execute arbitrary operating system commands by injecting malicious strings into the installation path parameter...

Jan 20, 2026
CVE-2025-12121
7.3

CVE-2025-12121 is an OS command injection vulnerability in Lite XL text editor versions 2.1.8 and earlier. Attackers can execute arbitrary commands wi...

Nov 20, 2025
CVE-2025-63932
7.3

The D-Link DIR-868L A1 router has an unauthenticated remote code execution vulnerability in its HNAP service. Attackers can exploit this by sending sp...

Nov 19, 2025
CVE-2025-36354
7.3

This vulnerability allows unauthenticated attackers to execute arbitrary commands with limited privileges on IBM Security Verify Access systems. It af...

Oct 6, 2025
CVE-2025-35027
7.3

This CVE describes a command injection vulnerability in Unitree robotic products that allows attackers to execute arbitrary commands as root by inject...

Sep 26, 2025
CVE-2025-59534
7.3

CVE-2025-59534 is a command injection vulnerability in CryptoLib's initialize_kerberos_keytab_file_login() function that allows attackers to execute a...

Sep 23, 2025
CVE-2025-22469
7.3

This CVE describes an OS command injection vulnerability in Sato CL4/6NX Plus and CL4/6NX-J Plus label printers. Attackers with non-administrative acc...

Aug 6, 2025
CVE-2025-36604
EPSS 16.8% 7.3

This CVE describes an OS command injection vulnerability in Dell Unity storage systems. Unauthenticated remote attackers can execute arbitrary command...

Aug 4, 2025
CVE-2024-49601
7.3

CVE-2024-49601 is an OS command injection vulnerability in Dell Unity storage systems that allows unauthenticated remote attackers to execute arbitrar...

Mar 28, 2025
CVE-2024-28138
7.3

This vulnerability allows unauthenticated attackers with network access to execute arbitrary system commands on affected devices via the web interface...

Dec 10, 2024
CVE-2024-50376
7.3

This cross-site scripting (XSS) vulnerability affects Advantech industrial wireless access points. Attackers can exploit it by creating a malicious Wi...

Nov 26, 2024
CVE-2024-48459
7.3

This CVE describes a command injection vulnerability in Tenda AX2 Pro routers that allows remote attackers to execute arbitrary commands with root pri...

Oct 25, 2024
CVE-2024-9916
7.3

This critical vulnerability in HuangDou UTCMS V9 allows remote attackers to execute arbitrary operating system commands through command injection in t...

Oct 13, 2024
CVE-2024-21532
7.3

CVE-2024-21532 is a command injection vulnerability in the ggit npm package that allows attackers to execute arbitrary commands on the host system. Th...

Oct 8, 2024
CVE-2024-7066
7.3

This critical vulnerability in F-logic DataCube3 1.0 allows remote attackers to execute arbitrary operating system commands via command injection in t...

Jul 24, 2024
CVE-2024-4582
7.3

This critical vulnerability allows remote attackers to execute arbitrary operating system commands on Faraday GM8181 and GM828x DVR devices by injecti...

May 7, 2024
CVE-2024-28033
7.3

This CVE describes an OS command injection vulnerability in WebProxy versions 1.7.8 and 1.7.9 that allows remote unauthenticated attackers to execute ...

Mar 26, 2024
CVE-2021-33633
7.3

This OS command injection vulnerability in openEuler's aops-ceres component allows attackers to execute arbitrary commands on affected systems. It aff...

Mar 23, 2024
CVE-2024-1115
7.3

This critical vulnerability in openBI allows remote attackers to execute arbitrary operating system commands through command injection in the dlfile f...

Jan 31, 2024
CVE-2024-0298
7.3

This critical vulnerability in Totolink N200RE routers allows remote attackers to execute arbitrary operating system commands via command injection in...

Jan 8, 2024
CVE-2024-0296
7.3

This critical vulnerability allows remote attackers to execute arbitrary operating system commands on Totolink N200RE routers by injecting malicious c...

Jan 8, 2024
CVE-2024-0294
7.3

This critical vulnerability in Totolink LR1200GB routers allows remote attackers to execute arbitrary operating system commands through command inject...

Jan 8, 2024

About OS Command Injection (CWE-78)

The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.

Our database tracks 1,855 CVEs classified as CWE-78, with 741 rated critical and 944 rated high severity. The average CVSS score for OS Command Injection vulnerabilities is 8.6.

External reference: View CWE-78 on MITRE CWE →

Monitor OS Command Injection Vulnerabilities

Get alerted when new OS Command Injection CVEs affect your infrastructure.

Start Monitoring Free