CWE-78: OS Command Injection
The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.
Yearly Trend
Top Affected Vendors
All OS Command Injection CVEs (1,855)
This is a critical OS command injection vulnerability in Stupid Simple CMS that allows remote attackers to execute arbitrary commands on the server. A...
Dec 17, 2023This vulnerability in mailcow's Sync Job feature allows authenticated users with specific permissions to execute arbitrary shell commands via command ...
Mar 4, 2023CVE-2022-1292 is a command injection vulnerability in the c_rehash script distributed with OpenSSL. It allows attackers to execute arbitrary commands ...
May 3, 2022Dell VNX2 file storage systems running version 8.1.21.266 or earlier contain an unauthenticated remote code execution vulnerability. Attackers can exe...
Apr 8, 2022This vulnerability allows remote code execution in Mahara e-portfolio systems through shell command injection. Attackers can execute arbitrary command...
Nov 2, 2021CVE-2021-23399 is a command injection vulnerability in the wincred npm package that allows attackers to execute arbitrary commands on systems using vu...
Jun 28, 2021CVE-2021-23381 is a command injection vulnerability in the 'killing' npm package that allows attackers to execute arbitrary commands on affected syste...
Apr 18, 2021CVE-2021-23374 is a command injection vulnerability in the ps-visitor npm package that allows attackers to execute arbitrary commands on the host syst...
Apr 18, 2021CVE-2020-28429 is a command injection vulnerability in the geojson2kml npm package that allows attackers to execute arbitrary system commands by passi...
Feb 23, 2021CVE-2020-28426 is a command injection vulnerability in the kill-process-on-port npm package that allows attackers to execute arbitrary commands on the...
Feb 1, 2021Multiple authenticated OS command injection vulnerabilities in Cohesity TranZman 4.0 allow authenticated admin users to execute arbitrary commands wit...
Mar 3, 2026CVE-2025-63911 is an authenticated command injection vulnerability in Cohesity TranZman Migration Appliance Release 4.0 Build 14614. This allows authe...
Mar 3, 2026This CVE describes a post-authentication command injection vulnerability in Zyxel VMG3625-T50B devices. An authenticated attacker with administrator p...
Feb 24, 2026This CVE describes a post-authentication command injection vulnerability in Zyxel firewall devices. An authenticated attacker with administrator privi...
Feb 5, 2026An OS command injection vulnerability in ELECOM WRC-X1500GS-B and WRC-X1500GSA-B wireless routers allows authenticated attackers to execute arbitrary ...
Feb 3, 2026This CVE describes an authenticated command injection vulnerability in TP-Link Archer BE230 routers. Attackers with admin access can execute arbitrary...
Feb 2, 2026This CVE describes a command injection vulnerability in the Archer BE230 router's VPN Connection Service that requires admin authentication. Successfu...
Feb 2, 2026A command injection vulnerability in TP-Link Archer BE230 routers allows authenticated attackers to execute arbitrary OS commands via the configuratio...
Feb 2, 2026This CVE describes a command injection vulnerability in TP-Link Archer BE230 routers that allows authenticated attackers to execute arbitrary commands...
Feb 2, 2026This CVE describes a command injection vulnerability in TP-Link Archer BE230 routers that allows authenticated attackers to execute arbitrary commands...
Feb 2, 2026This vulnerability allows attackers with valid credentials to execute arbitrary commands on affected Hikvision Wireless Access Points by sending speci...
Jan 30, 2026This CVE describes an OS command injection vulnerability in Ruijie AP180 series access points running vulnerable firmware versions. Attackers can exec...
Jan 22, 2026Authenticated command injection vulnerabilities in Aruba mobility conductors running AOS-8 allow attackers with valid credentials to execute arbitrary...
Jan 13, 2026Authenticated command injection vulnerabilities in Aruba mobility conductors running AOS-8 allow authenticated attackers to execute arbitrary commands...
Jan 13, 2026Authenticated command injection vulnerabilities in Aruba mobility conductors running AOS-8 allow attackers with valid credentials to execute arbitrary...
Jan 13, 2026Vivotek IP7137 cameras with vulnerable firmware allow authenticated attackers to execute arbitrary system commands via command injection in the system...
Jan 9, 2026This vulnerability allows authenticated users with high privileges to inject arbitrary operating system commands through backup configuration paramete...
Jan 5, 2026This vulnerability allows authenticated remote attackers to execute arbitrary operating system commands on DreamFactory instances. Attackers can achie...
Dec 23, 2025PhotoShow 3.0 contains a remote code execution vulnerability where authenticated administrators can inject malicious commands through the exiftran pat...
Dec 22, 2025This vulnerability allows authenticated attackers to execute arbitrary operating system commands on Ruijie Networks AP180 series wireless access point...
Dec 18, 2025RiteCMS v3.1.0 contains an authenticated remote code execution vulnerability in the parse_special_tags() function that allows authenticated users to e...
Dec 17, 2025This CVE describes an OS command injection vulnerability in Fortinet FortiExtender devices that allows authenticated attackers to execute arbitrary co...
Dec 9, 2025This OS command injection vulnerability in Fortinet FortiSandbox allows authenticated attackers to execute arbitrary commands on the underlying system...
Dec 9, 2025This OS command injection vulnerability in Fortinet FortiSandbox allows remote privileged attackers to execute arbitrary commands via crafted HTTP/HTT...
Dec 9, 2025This CVE describes a command injection vulnerability in Array Networks ArrayOS AG VPN appliances. Attackers can execute arbitrary commands on affected...
Dec 5, 2025This OS command injection vulnerability in Fortinet FortiWeb web application firewalls allows authenticated attackers to execute arbitrary commands on...
Nov 18, 2025Nagios Log Server versions before 2026R1.0.1 contain an authenticated command injection vulnerability in the experimental 'Natural Language Queries' f...
Nov 17, 2025This OS command injection vulnerability in NCP-HG100 network devices allows authenticated attackers to execute arbitrary commands with root privileges...
Nov 14, 2025FreePBX Endpoint Manager's filestore module contains a post-authentication command injection vulnerability in the SSH test connection function. Authen...
Nov 7, 2025This vulnerability allows authenticated system administrators in Advantech WebAccess/VPN to execute arbitrary commands on the server by uploading spec...
Nov 6, 2025This CVE describes an OS command injection vulnerability in FutureNet MA and IP-K series devices from Century Systems. Authenticated users can execute...
Oct 31, 2025This vulnerability allows authenticated administrators in Nagios Network Analyzer to execute arbitrary commands on the underlying host through imprope...
Oct 30, 2025Nagios XI versions before 2024R1.3.2 contain a remote command execution vulnerability in the WinRM Configuration Wizard. Authenticated administrators ...
Oct 30, 2025This OS command injection vulnerability in Dell Unity storage systems allows low-privileged local attackers to execute arbitrary commands with root pr...
Oct 30, 2025This CVE describes a command injection vulnerability in diagnostics functionality that allows attackers to execute arbitrary commands on affected syst...
Oct 23, 2025This OS command injection vulnerability in Centreon Infra Monitoring allows authenticated high-privilege users to inject arbitrary commands into polle...
Oct 14, 2025This vulnerability allows authenticated administrators in Ivanti EPMM to execute arbitrary operating system commands through the admin panel, leading ...
Oct 14, 2025This CVE describes an OS command injection vulnerability in Ivanti EPMM admin panel that allows authenticated administrators to execute arbitrary comm...
Oct 14, 2025Two OS command injection vulnerabilities in Fortinet FortiVoice allow privileged attackers to execute arbitrary commands via crafted HTTP/HTTPS or CLI...
Oct 14, 2025A privilege escalation vulnerability in Flowmon versions before 12.5.5 allows administrators with management interface access to execute unintended co...
Oct 9, 2025About OS Command Injection (CWE-78)
The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.
Our database tracks 1,855 CVEs classified as CWE-78, with 741 rated critical and 944 rated high severity. The average CVSS score for OS Command Injection vulnerabilities is 8.6.
External reference: View CWE-78 on MITRE CWE →
Monitor OS Command Injection Vulnerabilities
Get alerted when new OS Command Injection CVEs affect your infrastructure.
Start Monitoring Free