CWE-78: OS Command Injection

The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.

1,867
Total CVEs
751
Critical
946
High
8.6
Avg CVSS
11
In CISA KEV

Yearly Trend

2026
147
2025
465
2024
405
2023
253
2022
163

Top Affected Vendors

1 Dlink 99
2 Totolink 85
3 Dell 59
4 Fortinet 58
5 Tp Link 38
6 Zyxel 36
7 Cisco 32
8 Ruijie 30
9 Arubanetworks 27
10 Ibm 26

All OS Command Injection CVEs (1,867)

CVE-2024-53688
7.2

This CVE describes an OS command injection vulnerability in AE1021 and AE1021PE firmware that allows authenticated users to execute arbitrary operatin...

Dec 18, 2024
CVE-2024-54008
7.2

An authenticated Remote Code Execution vulnerability in AirWave CLI allows authenticated attackers to execute arbitrary commands with privileged user ...

Dec 10, 2024
CVE-2024-47133
7.2

This vulnerability allows remote authenticated attackers with administrative privileges to execute arbitrary operating system commands on affected IO-...

Dec 5, 2024
CVE-2024-9200
7.2

This vulnerability allows authenticated attackers with administrator privileges to execute arbitrary operating system commands on Zyxel VMG4005-B50A d...

Dec 3, 2024
CVE-2024-11983
7.2

This vulnerability allows remote attackers with administrator credentials to execute arbitrary system commands on affected Billion Electric routers vi...

Nov 29, 2024
CVE-2024-9461
7.2

This vulnerability allows authenticated attackers with Administrator-level WordPress access to execute arbitrary code on the server via the cron_inter...

Nov 26, 2024
CVE-2024-50369
7.2

This OS command injection vulnerability in Advantech EKI-6333 series industrial wireless access points allows attackers to execute arbitrary commands ...

Nov 26, 2024
CVE-2024-50367
7.2

This OS command injection vulnerability in Advantech EKI-6333 series industrial switches allows attackers to execute arbitrary commands on affected de...

Nov 26, 2024
CVE-2024-50365
7.2

This OS command injection vulnerability in Advantech EKI-6333 series industrial switches allows attackers to execute arbitrary commands on affected de...

Nov 26, 2024
CVE-2024-50363
7.2

This OS command injection vulnerability in Advantech EKI-6333 series industrial switches allows attackers to execute arbitrary commands on affected de...

Nov 26, 2024
CVE-2024-50361
7.2

This OS command injection vulnerability in Advantech EKI-6333 series industrial switches allows attackers to execute arbitrary commands on affected de...

Nov 26, 2024
CVE-2024-50359
7.2

This OS command injection vulnerability in Advantech EKI series industrial switches allows attackers to execute arbitrary commands on affected devices...

Nov 26, 2024
CVE-2024-28026
7.2

This CVE describes three authenticated OS command injection vulnerabilities in MC Technologies MC LR Router's web interface. An attacker with valid cr...

Nov 21, 2024
CVE-2024-9474
7.2

This CVE describes a privilege escalation vulnerability in Palo Alto Networks PAN-OS software where an authenticated administrator with access to the ...

Nov 18, 2024
CVE-2024-11066
7.2

This CVE describes an OS command injection vulnerability in D-Link DSL6740C modems that allows authenticated attackers with administrator privileges t...

Nov 11, 2024
CVE-2024-11064
7.2

The D-Link DSL6740C modem has an OS command injection vulnerability that allows authenticated attackers with administrator privileges to execute arbit...

Nov 11, 2024
CVE-2024-11062
7.2

The D-Link DSL6740C modem has an OS command injection vulnerability that allows authenticated attackers with administrator privileges to execute arbit...

Nov 11, 2024
CVE-2024-10653
7.2

CVE-2024-10653 is an OS command injection vulnerability in IDExpert software from CHANGING Information Technology. Attackers with administrative acces...

Nov 1, 2024
CVE-2024-41153
7.2

A command injection vulnerability in the Edge Computing UI for TRO600 series radios allows attackers with write access to execute arbitrary system com...

Oct 29, 2024
CVE-2024-37845
7.2

MangoOS versions before 5.2.0 contain an authenticated remote code execution vulnerability in the Active Process Command feature. This allows authenti...

Oct 25, 2024
CVE-2024-8957
7.2

CVE-2024-8957 is an OS command injection vulnerability in PTZOptics PT30X-SDI/NDI cameras that allows arbitrary command execution via insufficient val...

Sep 17, 2024
CVE-2024-42503
7.2

This CVE describes an authenticated command injection vulnerability in ArubaOS CLI that allows authenticated attackers to execute arbitrary commands w...

Sep 17, 2024
CVE-2024-8280
7.2

This vulnerability in Lenovo XClarity Controller (XCC) allows authenticated users with elevated privileges to execute arbitrary commands or cause a re...

Sep 13, 2024
CVE-2024-8278
7.2

This privilege escalation vulnerability in Lenovo XClarity Controller (XCC) allows authenticated users with elevated privileges to execute arbitrary c...

Sep 13, 2024
CVE-2024-8686
7.2

This CVE describes a command injection vulnerability in Palo Alto Networks PAN-OS software that allows authenticated administrators to bypass system r...

Sep 11, 2024
CVE-2024-20483
7.2

This vulnerability allows authenticated attackers with Administrator privileges on Cisco Routed PON Manager or direct MongoDB access to execute arbitr...

Sep 11, 2024
CVE-2024-8190
7.2

An OS command injection vulnerability in Ivanti Cloud Services Appliance allows authenticated attackers with admin privileges to execute arbitrary com...

Sep 10, 2024
CVE-2024-7203
7.2

This vulnerability allows authenticated administrators on affected Zyxel firewalls to execute arbitrary operating system commands through command inje...

Sep 3, 2024
CVE-2024-42059
7.2

This is a post-authentication command injection vulnerability in multiple Zyxel firewall series. An authenticated attacker with administrator privileg...

Sep 3, 2024
CVE-2024-7728
7.2

This vulnerability allows remote attackers with administrator privileges to execute arbitrary operating system commands on CAYIN Technology CMS server...

Aug 14, 2024
CVE-2024-3659
7.2

This vulnerability allows authenticated attackers with administrative access to KAON AR2140 routers to execute arbitrary shell commands via crafted re...

Aug 8, 2024
CVE-2024-33896
7.2

CVE-2024-33896 is a code injection vulnerability in Cosy+ industrial remote access gateways that allows attackers to execute arbitrary commands on aff...

Aug 2, 2024
CVE-2024-38510
7.2

This CVE describes a privilege escalation vulnerability in Lenovo XClarity Controller (XCC) SSH captive command shell interface. Authenticated XCC use...

Jul 26, 2024
CVE-2024-38512
7.2

This privilege escalation vulnerability in Lenovo XClarity Controller (XCC) allows authenticated users with elevated privileges to execute arbitrary c...

Jul 26, 2024
CVE-2024-38508
7.2

This CVE describes a privilege escalation vulnerability in Lenovo XCC (XClarity Controller) interfaces that allows authenticated users with elevated p...

Jul 26, 2024
CVE-2024-28749
7.2

This vulnerability allows remote attackers with administrative privileges to execute arbitrary operating system commands through a file writing functi...

Jul 9, 2024
CVE-2023-50382
7.2

This CVE describes three OS command injection vulnerabilities in Realtek rtl819x Jungle SDK's boa formWsc functionality. Attackers can execute arbitra...

Jul 8, 2024
CVE-2024-5672
7.2

This vulnerability allows a high-privileged remote attacker to execute arbitrary operating system commands via GET requests due to improper input sani...

Jul 3, 2024
CVE-2024-5403
7.2

This vulnerability allows remote attackers with administrator privileges to execute arbitrary system commands on ASKEY 5G NR Small Cell devices due to...

May 27, 2024
CVE-2024-5399
7.2

Openfind Mail2000 contains an OS command injection vulnerability in a specific API endpoint. Attackers with administrative access can exploit this to ...

May 27, 2024
CVE-2024-33529
7.2

This vulnerability allows authenticated administrators in ILIAS e-learning platforms to execute arbitrary operating system commands by uploading files...

May 21, 2024
CVE-2023-6321
7.2

This CVE describes a command injection vulnerability in the IOCTL interface handling OTA updates. An authenticated attacker can execute arbitrary comm...

May 15, 2024
CVE-2024-31477
7.2

This CVE describes authenticated command injection vulnerabilities in HPE Aruba Networking products that allow attackers with CLI access to execute ar...

May 14, 2024
CVE-2024-2662
7.2

This vulnerability allows authenticated WordPress administrators to execute arbitrary commands on the server through the Unlimited Elements For Elemen...

May 14, 2024
CVE-2024-4299
7.2

This CVE allows remote attackers with administrative privileges to execute arbitrary system commands on HGiga iSherlock products through command injec...

Apr 29, 2024
CVE-2024-4298
7.2

This CVE describes a command injection vulnerability in HGiga iSherlock email security products (MailSherlock, SpamSherlock, AuditSherlock). Remote at...

Apr 29, 2024
CVE-2024-29167
7.2

This vulnerability allows remote authenticated attackers with administrative privileges to execute arbitrary operating system commands on SVR-116 devi...

Apr 4, 2024
CVE-2024-25946
7.2

Dell vApp Manager versions prior to 9.2.4.9 contain a command injection vulnerability (CWE-78) that allows authorized attackers to execute arbitrary c...

Mar 28, 2024
CVE-2024-24899
7.2

This OS command injection vulnerability in openEuler's aops-zeus component allows attackers to execute arbitrary commands on affected Linux systems. T...

Mar 25, 2024
CVE-2024-28187
7.2

SOY CMS versions before 3.14.2 contain an OS command injection vulnerability in the file upload feature. Administrators can exploit this by uploading ...

Mar 11, 2024

About OS Command Injection (CWE-78)

The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.

Our database tracks 1,867 CVEs classified as CWE-78, with 751 rated critical and 946 rated high severity. The average CVSS score for OS Command Injection vulnerabilities is 8.6.

External reference: View CWE-78 on MITRE CWE →

Monitor OS Command Injection Vulnerabilities

Get alerted when new OS Command Injection CVEs affect your infrastructure.

Start Monitoring Free