CWE-78: OS Command Injection

The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.

1,860
Total CVEs
746
Critical
944
High
8.6
Avg CVSS
11
In CISA KEV

Yearly Trend

2026
147
2025
465
2024
405
2023
253
2022
163

Top Affected Vendors

1 Dlink 99
2 Totolink 85
3 Dell 59
4 Fortinet 58
5 Tp Link 38
6 Zyxel 35
7 Cisco 32
8 Ruijie 30
9 Arubanetworks 27
10 Ibm 26

All OS Command Injection CVEs (1,860)

CVE-2025-5946
EPSS 24.1% 7.2

This OS command injection vulnerability in Centreon Infra Monitoring allows authenticated high-privilege users to inject arbitrary commands into polle...

Oct 14, 2025
CVE-2025-10242
7.2

This vulnerability allows authenticated administrators in Ivanti EPMM to execute arbitrary operating system commands through the admin panel, leading ...

Oct 14, 2025
CVE-2025-10985
7.2

This CVE describes an OS command injection vulnerability in Ivanti EPMM admin panel that allows authenticated administrators to execute arbitrary comm...

Oct 14, 2025
CVE-2025-47856
7.2

Two OS command injection vulnerabilities in Fortinet FortiVoice allow privileged attackers to execute arbitrary commands via crafted HTTP/HTTPS or CLI...

Oct 14, 2025
CVE-2025-10239
7.2

A privilege escalation vulnerability in Flowmon versions before 12.5.5 allows administrators with management interface access to execute unintended co...

Oct 9, 2025
CVE-2025-47212
7.2

A command injection vulnerability in QNAP operating systems allows authenticated attackers with administrator privileges to execute arbitrary commands...

Oct 3, 2025
CVE-2025-58116
7.2

This CVE describes an OS command injection vulnerability in I-O DATA WN-7D36QR and WN-7D36QR/UE wireless LAN routers. Remote authenticated attackers c...

Sep 17, 2025
CVE-2025-8613
7.2

This vulnerability allows authenticated remote attackers to execute arbitrary system commands on Vacron Camera devices via command injection in the we...

Sep 2, 2025
CVE-2025-53508
7.2

This CVE describes an OS command injection vulnerability in multiple products from iND Co.,Ltd. Attackers can execute arbitrary operating system comma...

Aug 29, 2025
CVE-2025-49813
7.2

This CVE describes an OS command injection vulnerability in Fortinet FortiADC that allows authenticated attackers with low privileges to execute arbit...

Aug 12, 2025
CVE-2013-10059
EPSS 50.8% 7.2

This CVE describes an authenticated OS command injection vulnerability in D-Link DIR-615H1 routers running firmware version 8.04. Attackers with defau...

Aug 1, 2025
CVE-2013-10061
EPSS 73.1% 7.2

This CVE describes an authenticated OS command injection vulnerability in Netgear DGN1000B routers that allows authenticated attackers to execute arbi...

Aug 1, 2025
CVE-2024-53286
7.2

This CVE describes an OS command injection vulnerability in Synology Router Manager's DDNS functionality. Authenticated administrators can execute arb...

Jul 23, 2025
CVE-2025-53472
7.2

This CVE describes an OS command injection vulnerability in ELECOM WRC-BE36QS-B and WRC-W701-B wireless routers. Remote attackers who can authenticate...

Jul 22, 2025
CVE-2025-41675
7.2

This vulnerability allows a high-privileged remote attacker to execute arbitrary operating system commands via GET requests to a cloud server communic...

Jul 21, 2025
CVE-2025-41673
7.2

This vulnerability allows authenticated high-privileged remote attackers to execute arbitrary operating system commands via POST requests to the send_...

Jul 21, 2025
CVE-2025-6771
EPSS 16.4% 7.2

This vulnerability allows authenticated attackers with high privileges in Ivanti Endpoint Manager Mobile (EPMM) to execute arbitrary operating system ...

Jul 8, 2025
CVE-2025-6770
7.2

CVE-2025-6770 is an OS command injection vulnerability in Ivanti Endpoint Manager Mobile (EPMM) that allows authenticated attackers with high privileg...

Jul 8, 2025
CVE-2025-7145
7.2

CVE-2025-7145 is an OS command injection vulnerability in ThreatSonar Anti-Ransomware that allows remote attackers with intermediate platform privileg...

Jul 7, 2025
CVE-2025-36529
7.2

This CVE describes an OS command injection vulnerability in TB-eye network recorders and AHD recorders that allows authenticated attackers to execute ...

Jun 27, 2025
CVE-2025-31104
7.2

This OS command injection vulnerability in FortiADC allows authenticated attackers to execute arbitrary operating system commands via specially crafte...

Jun 10, 2025
CVE-2025-41385
7.2

This CVE describes an OS command injection vulnerability in wivia 5 that allows authenticated administrative users to execute arbitrary operating syst...

May 30, 2025
CVE-2024-6486
7.2

This vulnerability allows authenticated WordPress administrators to execute arbitrary operating system commands on the server via the 'cli_path' param...

May 15, 2025
CVE-2025-32821
7.2

A command injection vulnerability in SMA100 SSL-VPN appliances allows authenticated administrators to execute arbitrary shell commands by manipulating...

May 7, 2025
CVE-2025-2773
7.2

This vulnerability allows authenticated remote attackers to execute arbitrary commands on BEC Technologies routers by injecting malicious input into t...

Apr 23, 2025
CVE-2024-54024
7.2

This OS command injection vulnerability in Fortinet FortiIsolator allows attackers with super-admin privileges and CLI access to execute arbitrary com...

Apr 8, 2025
CVE-2025-2257
7.2

This vulnerability allows authenticated attackers with administrator-level WordPress access to execute arbitrary code on the server via the compressio...

Mar 26, 2025
CVE-2025-0255
7.2

CVE-2025-0255 is an OS command injection vulnerability in HCL DevOps Deploy/Launch that allows authenticated privileged attackers to execute arbitrary...

Mar 24, 2025
CVE-2025-24306
7.2

This CVE describes an OS command injection vulnerability in +F FS010M devices that allows authenticated administrators to execute arbitrary operating ...

Mar 18, 2025
CVE-2024-54018
7.2

This vulnerability allows privileged attackers to execute arbitrary operating system commands on FortiSandbox appliances through crafted requests. It ...

Mar 11, 2025
CVE-2025-27393
7.2

This vulnerability in Siemens SCALANCE LPE9403 industrial network devices allows authenticated high-privileged attackers to execute arbitrary code due...

Mar 11, 2025
CVE-2025-27394
7.2

This vulnerability allows an authenticated, highly-privileged remote attacker to execute arbitrary code on affected SCALANCE LPE9403 devices by exploi...

Mar 11, 2025
CVE-2025-27392
7.2

A vulnerability in SCALANCE LPE9403 industrial network devices allows authenticated high-privileged remote attackers to execute arbitrary code due to ...

Mar 11, 2025
CVE-2024-11253
7.2

This CVE describes a post-authentication command injection vulnerability in Zyxel VMG8825-T50K devices. An authenticated attacker with administrator p...

Mar 11, 2025
CVE-2024-12009
7.2

This vulnerability allows authenticated attackers with administrator privileges to execute arbitrary operating system commands on Zyxel networking dev...

Mar 11, 2025
CVE-2024-12010
7.2

This vulnerability allows authenticated attackers with administrator privileges to execute arbitrary operating system commands on affected Zyxel devic...

Mar 11, 2025
CVE-2025-26856
7.2

This CVE describes an OS command injection vulnerability in UD-LT2 firmware that allows authenticated attackers with administrative privileges to exec...

Feb 20, 2025
CVE-2024-55904
7.2

This vulnerability allows authenticated privileged attackers to execute arbitrary commands on IBM DevOps Deploy and UrbanCode Deploy systems by sendin...

Feb 14, 2025
CVE-2024-40584
7.2

This OS command injection vulnerability in Fortinet FortiAnalyzer and FortiManager products allows authenticated privileged attackers to execute arbit...

Feb 11, 2025
CVE-2024-50567
7.2

This CVE describes an OS command injection vulnerability in Fortinet FortiWeb web application firewalls. Attackers can execute arbitrary commands on a...

Feb 11, 2025
CVE-2025-20617
7.2

This vulnerability allows authenticated attackers with administrative access to execute arbitrary operating system commands on UD-LT2 devices. Attacke...

Jan 22, 2025
CVE-2025-0356
7.2

This vulnerability allows remote attackers to execute arbitrary operating system commands on affected NEC Aterm routers via network access. Attackers ...

Jan 15, 2025
CVE-2024-50566
7.2

This CVE describes an OS command injection vulnerability in Fortinet FortiManager and FortiManager Cloud products. Authenticated remote attackers can ...

Jan 14, 2025
CVE-2024-54082
7.2

This vulnerability allows administrative users of Sharp Home 5G HR02 and Wi-Fi STATION SH-54C devices to execute arbitrary operating system commands w...

Dec 23, 2024
CVE-2024-53688
7.2

This CVE describes an OS command injection vulnerability in AE1021 and AE1021PE firmware that allows authenticated users to execute arbitrary operatin...

Dec 18, 2024
CVE-2024-54008
7.2

An authenticated Remote Code Execution vulnerability in AirWave CLI allows authenticated attackers to execute arbitrary commands with privileged user ...

Dec 10, 2024
CVE-2024-47133
7.2

This vulnerability allows remote authenticated attackers with administrative privileges to execute arbitrary operating system commands on affected IO-...

Dec 5, 2024
CVE-2024-9200
7.2

This vulnerability allows authenticated attackers with administrator privileges to execute arbitrary operating system commands on Zyxel VMG4005-B50A d...

Dec 3, 2024
CVE-2024-11983
7.2

This vulnerability allows remote attackers with administrator credentials to execute arbitrary system commands on affected Billion Electric routers vi...

Nov 29, 2024
CVE-2024-9461
7.2

This vulnerability allows authenticated attackers with Administrator-level WordPress access to execute arbitrary code on the server via the cron_inter...

Nov 26, 2024

About OS Command Injection (CWE-78)

The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.

Our database tracks 1,860 CVEs classified as CWE-78, with 746 rated critical and 944 rated high severity. The average CVSS score for OS Command Injection vulnerabilities is 8.6.

External reference: View CWE-78 on MITRE CWE →

Monitor OS Command Injection Vulnerabilities

Get alerted when new OS Command Injection CVEs affect your infrastructure.

Start Monitoring Free