CWE-78: OS Command Injection

The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.

1,667
Total CVEs
620
Critical
877
High
8.5
Avg CVSS
11
In CISA KEV

Yearly Trend

2026
146
2025
465
2024
405
2023
253
2022
163

Top Affected Vendors

1 Dlink 89
2 Totolink 85
3 Dell 58
4 Fortinet 57
5 Tp Link 35
6 Zyxel 33
7 Ruijie 30
8 Cisco 28
9 Jvckenwood 26
10 Arubanetworks 24

All OS Command Injection CVEs (1,667)

CVE-2025-66208
9.8

CVE-2025-66208 is a critical OS command injection vulnerability in Collabora Online's built-in CODE server (richdocumentscode proxy). It allows remote...

Dec 3, 2025
CVE-2025-66401
9.8

MCP Watch versions 0.1.2 and earlier contain a critical command injection vulnerability in the MCPScanner class. Attackers can execute arbitrary comma...

Dec 1, 2025
CVE-2025-62354
9.8

This CVE describes a command injection vulnerability in Cursor that allows unauthorized attackers to bypass allowlist restrictions and execute arbitra...

Nov 26, 2025
CVE-2025-66261
9.8

This CVE describes an unauthenticated OS command injection vulnerability in DB Electronica Telecomunicazioni Mozart FM Transmitters. Attackers can exe...

Nov 26, 2025
CVE-2025-66253
9.8

This vulnerability allows unauthenticated attackers to execute arbitrary operating system commands on DB Electronica Telecomunicazioni Mozart FM Trans...

Nov 26, 2025
CVE-2025-64755
9.8

CVE-2025-64755 is a critical vulnerability in Claude Code versions before 2.0.31 that allows attackers to bypass read-only validation and write arbitr...

Nov 21, 2025
CVE-2025-60738
9.8

This vulnerability allows remote attackers to execute arbitrary operating system commands on Ilevia EVE X1 Server devices via the ping.php component, ...

Nov 20, 2025
CVE-2025-13284
9.8

ThinPLUS software contains an OS command injection vulnerability that allows unauthenticated remote attackers to execute arbitrary operating system co...

Nov 17, 2025
CVE-2022-50596
EPSS 11.9% 9.8

CVE-2022-50596 is a critical command injection vulnerability in D-Link DIR-1260 routers that allows unauthenticated attackers to execute arbitrary com...

Nov 6, 2025
CVE-2025-61304
9.8

This CVE describes an OS command injection vulnerability in Dynatrace ActiveGate's ping extension. Attackers can execute arbitrary commands on affecte...

Nov 5, 2025
CVE-2025-11953
KEV 9.8

CVE-2025-11953 is a critical OS command injection vulnerability in the React Native Community CLI's Metro Development Server. Unauthenticated attacker...

Nov 3, 2025
CVE-2024-14003
9.8

Nagios XI versions before 2024R1.2 contain a critical remote code execution vulnerability in the NRDP server plugins. Attackers can send specially cra...

Oct 30, 2025
CVE-2025-11202
9.8

This vulnerability allows remote attackers to execute arbitrary code on win-cli-mcp-server installations without authentication. Attackers can inject ...

Oct 29, 2025
CVE-2018-25120
9.8

This CVE describes a critical command injection vulnerability in D-Link DNS-343 ShareCenter network storage devices. Unauthenticated remote attackers ...

Oct 29, 2025
CVE-2025-60803
9.8

Antabot White-Jotter contains an unauthenticated remote code execution vulnerability that allows attackers to execute arbitrary commands on affected s...

Oct 24, 2025
CVE-2016-15048
9.8

This is an unauthenticated remote command injection vulnerability in AMTT Hotel Broadband Operation System (HiBOS). Attackers can execute arbitrary sy...

Oct 22, 2025
CVE-2025-6542
9.8

This critical vulnerability (CVE-2025-6542) allows remote unauthenticated attackers to execute arbitrary operating system commands on affected Omada a...

Oct 21, 2025
CVE-2025-11900
9.8

CVE-2025-11900 is an unauthenticated remote OS command injection vulnerability in HGiga's iSherlock software. Attackers can execute arbitrary commands...

Oct 17, 2025
CVE-2025-34513
EPSS 13.1% 9.8

Ilevia EVE X1 Server firmware contains an unauthenticated OS command injection vulnerability in mbus_build_from_csv.php that allows remote attackers t...

Oct 16, 2025
CVE-2025-10659
9.8

CVE-2025-10659 allows unauthenticated attackers to execute arbitrary operating system commands on Telenium Online web servers through a vulnerable PHP...

Sep 30, 2025
CVE-2025-9762
9.8

The Post By Email WordPress plugin allows unauthenticated attackers to upload arbitrary files due to missing file type validation. This can lead to re...

Sep 30, 2025
CVE-2025-11148
9.8

CVE-2025-11148 is a critical command injection vulnerability in the check-branches npm package that allows attackers to execute arbitrary commands on ...

Sep 30, 2025
CVE-2025-11005
9.8

This CVE describes an OS command injection vulnerability in TOTOLINK X6000R routers that allows attackers to execute arbitrary commands on the device....

Sep 25, 2025
CVE-2025-56819
EPSS 20.7% 9.8

This vulnerability allows remote attackers to execute arbitrary code on Datart servers by exploiting improper input validation in the INIT connection ...

Sep 24, 2025
CVE-2025-10568
9.8

This vulnerability in HyperX NGENUITY software allows attackers to execute arbitrary code on affected systems by exploiting improper neutralization of...

Sep 19, 2025
CVE-2025-34184
9.8

This critical vulnerability allows unauthenticated remote attackers to execute arbitrary operating system commands on Ilevia EVE X1 Server systems. At...

Sep 16, 2025
CVE-2025-34186
9.8

This vulnerability allows remote attackers to bypass authentication on Ilevia EVE X1/X5 Server by injecting special characters into the authentication...

Sep 16, 2025
CVE-2025-59359
9.8

CVE-2025-59359 is an OS command injection vulnerability in Chaos Controller Manager's cleanTcs mutation that allows unauthenticated attackers within a...

Sep 15, 2025
CVE-2025-59361
9.8

CVE-2025-59361 is an OS command injection vulnerability in Chaos Mesh's cleanIptables mutation that allows unauthenticated attackers within a Kubernet...

Sep 15, 2025
CVE-2025-55048
9.8

This CVE-2025-55048 vulnerability involves multiple instances of CWE-78 (Improper Neutralization of Special Elements used in an OS Command), allowing ...

Sep 9, 2025
CVE-2025-58371
9.8

CVE-2025-58371 is a critical vulnerability in Roo Code versions 3.26.6 and below that allows remote code execution on GitHub Actions runners. Attacker...

Sep 5, 2025
CVE-2025-54857
9.8

This vulnerability allows remote unauthenticated attackers to execute arbitrary operating system commands with root privileges on SkyBridge BASIC MB-A...

Sep 1, 2025
CVE-2024-46484
9.8

This vulnerability allows remote attackers to execute arbitrary operating system commands on TRENDnet TV-IP410 vA1.0R security cameras via the /server...

Aug 29, 2025
CVE-2025-55583
9.8

This critical vulnerability allows unauthenticated remote attackers to execute arbitrary operating system commands as root on D-Link DIR-868L B1 route...

Aug 28, 2025
CVE-2018-25115
9.8

This CVE describes an unauthenticated remote command execution vulnerability in multiple D-Link DIR-series routers. Attackers can send specially craft...

Aug 27, 2025
CVE-2025-3128
9.8

CVE-2025-3128 is a critical OS command injection vulnerability in Mitsubishi Electric smartRTU devices that allows unauthenticated remote attackers to...

Aug 21, 2025
CVE-2025-43984
9.8

This vulnerability allows remote unauthenticated attackers to execute arbitrary operating system commands with root privileges on KuWFi GC111 devices....

Aug 14, 2025
CVE-2025-54074
9.8

Cherry Studio desktop client versions 1.2.5 to 1.5.1 are vulnerable to OS command injection when connecting to malicious MCP servers in HTTP Streamabl...

Aug 13, 2025
CVE-2025-25256
EPSS 41.4% 9.8

This critical vulnerability allows unauthenticated attackers to execute arbitrary operating system commands on FortiSIEM systems via crafted CLI reque...

Aug 12, 2025
CVE-2025-51390
9.8

This CVE describes a command injection vulnerability in TOTOLINK N600R routers that allows attackers to execute arbitrary commands on the device. The ...

Aug 4, 2025
CVE-2013-10048
EPSS 59.8% 9.8

This CVE describes an unauthenticated remote command execution vulnerability in legacy D-Link routers. Attackers can send specially crafted POST reque...

Aug 1, 2025
CVE-2025-50475
9.8

An unauthenticated OS command injection vulnerability in Russound MBX-PRE-D67F firmware allows attackers to execute arbitrary commands as root by send...

Jul 31, 2025
CVE-2025-54418
9.8

This CVE describes a command injection vulnerability in CodeIgniter's ImageMagick handler that allows remote code execution. Applications using ImageM...

Jul 28, 2025
CVE-2025-29631
9.8

A critical remote code execution vulnerability in Gardyn 4 allows attackers to execute arbitrary code on affected systems. This affects all Gardyn 4 i...

Jul 25, 2025
CVE-2019-25224
EPSS 78.8% 9.8

This vulnerability allows unauthenticated attackers to execute arbitrary operating system commands on WordPress sites running vulnerable versions of t...

Jul 25, 2025
CVE-2025-36846
EPSS 56.8% 9.8

This vulnerability allows unauthenticated attackers to execute arbitrary operating system commands on servers running Eveo URVE Web Manager 27.02.2025...

Jul 21, 2025
CVE-2025-6704
9.8

This vulnerability allows unauthenticated attackers to write arbitrary files to Sophos Firewall systems, potentially leading to remote code execution....

Jul 21, 2025
CVE-2025-7451
9.8

CVE-2025-7451 is an unauthenticated remote OS command injection vulnerability in iSherlock software developed by Hgiga. Attackers can execute arbitrar...

Jul 14, 2025
CVE-2025-48501
9.8

This CVE describes an OS command injection vulnerability in Nimesa Backup and Recovery software versions 2.3 and 2.4. Attackers can execute arbitrary ...

Jul 7, 2025
CVE-2025-26074
9.8

CVE-2025-26074 is a critical remote code execution vulnerability in Orkes Conductor that allows attackers to execute arbitrary operating system comman...

Jun 30, 2025

About OS Command Injection (CWE-78)

The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.

Our database tracks 1,667 CVEs classified as CWE-78, with 620 rated critical and 877 rated high severity. The average CVSS score for OS Command Injection vulnerabilities is 8.5.

External reference: View CWE-78 on MITRE CWE →

Monitor OS Command Injection Vulnerabilities

Get alerted when new OS Command Injection CVEs affect your infrastructure.

Start Monitoring Free