CWE-78: OS Command Injection

The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.

1,873
Total CVEs
755
Critical
948
High
8.6
Avg CVSS
11
In CISA KEV

Yearly Trend

2026
147
2025
465
2024
405
2023
253
2022
163

Top Affected Vendors

1 Dlink 99
2 Totolink 85
3 Dell 59
4 Fortinet 58
5 Tp Link 38
6 Zyxel 36
7 Cisco 32
8 Ruijie 30
9 Arubanetworks 27
10 Ibm 26

All OS Command Injection CVEs (1,873)

CVE-2024-4298
7.2

This CVE describes a command injection vulnerability in HGiga iSherlock email security products (MailSherlock, SpamSherlock, AuditSherlock). Remote at...

Apr 29, 2024
CVE-2024-29167
7.2

This vulnerability allows remote authenticated attackers with administrative privileges to execute arbitrary operating system commands on SVR-116 devi...

Apr 4, 2024
CVE-2024-25946
7.2

Dell vApp Manager versions prior to 9.2.4.9 contain a command injection vulnerability (CWE-78) that allows authorized attackers to execute arbitrary c...

Mar 28, 2024
CVE-2024-24899
7.2

This OS command injection vulnerability in openEuler's aops-zeus component allows attackers to execute arbitrary commands on affected Linux systems. T...

Mar 25, 2024
CVE-2024-28187
7.2

SOY CMS versions before 3.14.2 contain an OS command injection vulnerability in the file upload feature. Administrators can exploit this by uploading ...

Mar 11, 2024
CVE-2023-6398
7.2

This CVE describes a post-authentication command injection vulnerability in Zyxel firewall and access point firmware. An authenticated attacker with a...

Feb 20, 2024
CVE-2024-1367
7.2

This CVE describes a command injection vulnerability in Security Center that allows authenticated administrators to execute arbitrary code on the host...

Feb 14, 2024
CVE-2024-22445
7.2

Dell PowerProtect Data Manager versions 19.15 and earlier contain an OS command injection vulnerability that allows remote authenticated high-privileg...

Feb 13, 2024
CVE-2023-47167
7.2

This CVE describes an authenticated command injection vulnerability in TP-Link ER7206 Omada VPN routers. An attacker with valid credentials can execut...

Feb 6, 2024
CVE-2023-47617
7.2

This vulnerability allows authenticated attackers to execute arbitrary commands on TP-Link ER7206 Omada Gigabit VPN Router by sending specially crafte...

Feb 6, 2024
CVE-2023-36498
7.2

This vulnerability allows authenticated attackers to execute arbitrary commands on the TP-Link ER7206 Omada Gigabit VPN Router via a post-authenticati...

Feb 6, 2024
CVE-2023-43482
7.2

This vulnerability allows authenticated attackers to execute arbitrary commands on TP-Link ER7206 Omada Gigabit VPN Router devices by sending speciall...

Feb 6, 2024
CVE-2024-0918
7.2

This critical vulnerability in TRENDnet TEW-800MB routers allows remote attackers to execute arbitrary operating system commands by manipulating the D...

Jan 26, 2024
CVE-2023-4464
7.2

This critical vulnerability in Poly VoIP devices allows remote attackers to execute arbitrary operating system commands via the Diagnostic Telnet Mode...

Dec 29, 2023
CVE-2023-48667
7.2

This CVE describes an OS command injection vulnerability in Dell PowerProtect DD's administrator CLI. A remote attacker with high privileges can execu...

Dec 14, 2023
CVE-2023-48662
7.2

Dell vApp Manager versions prior to 9.2.4.x contain a command injection vulnerability (CWE-78) that allows remote authenticated users with high privil...

Dec 14, 2023
CVE-2023-48664
7.2

Dell vApp Manager versions prior to 9.2.4.x contain a command injection vulnerability (CWE-78) that allows remote attackers with high privileges to ex...

Dec 14, 2023
CVE-2023-49691
7.2

This vulnerability allows malicious local administrators to execute arbitrary operating system commands with root privileges by exploiting improper in...

Dec 12, 2023
CVE-2023-48428
7.2

This vulnerability in SINEC INS allows malicious administrators to upload specially crafted certificates through the RADIUS configuration mechanism, b...

Dec 12, 2023
CVE-2023-44291
7.2

Dell DM5500 5.14.0.0 contains an OS command injection vulnerability that allows authenticated attackers with high privileges to execute arbitrary oper...

Dec 4, 2023
CVE-2023-4221
7.2

This vulnerability allows authenticated users with Learning Path upload permissions to execute arbitrary commands on the server through command inject...

Nov 28, 2023
CVE-2023-6304
7.2

This critical vulnerability allows remote attackers to execute arbitrary operating system commands on Tecno 4G Portable WiFi devices via command injec...

Nov 27, 2023
CVE-2023-47675
7.2

CVE-2023-47675 is an OS command injection vulnerability in CubeCart e-commerce software that allows authenticated administrators to execute arbitrary ...

Nov 17, 2023
CVE-2023-5037
7.2

This vulnerability allows authenticated attackers to execute arbitrary commands on affected Hanwha Vision cameras through command injection in request...

Nov 13, 2023
CVE-2023-41352
7.2

This vulnerability allows remote attackers with administrator privileges to execute arbitrary commands on Chunghwa Telecom NOKIA G-040W-Q routers thro...

Nov 3, 2023
CVE-2023-20219
7.2

This vulnerability allows authenticated remote attackers with valid device credentials (no admin privileges required) to execute arbitrary commands on...

Nov 1, 2023
CVE-2023-20273
7.2

This vulnerability in Cisco IOS XE Software allows authenticated remote attackers to execute arbitrary commands with root privileges via the web UI. A...

Oct 25, 2023
CVE-2023-33839
7.2

CVE-2023-33839 is an OS command injection vulnerability in IBM Security Verify Governance 10.0 that allows authenticated remote attackers to execute a...

Oct 23, 2023
CVE-2023-34356
7.2

An authenticated OS command injection vulnerability in Peplink Surf SOHO HW1 routers allows attackers to execute arbitrary commands via specially craf...

Oct 11, 2023
CVE-2023-35193
7.2

This CVE describes an OS command injection vulnerability in Peplink Surf SOHO HW1 routers that allows authenticated attackers to execute arbitrary com...

Oct 11, 2023
CVE-2023-28381
7.2

This vulnerability allows authenticated attackers to execute arbitrary operating system commands on Peplink Surf SOHO HW1 devices via command injectio...

Oct 11, 2023
CVE-2023-38886
7.2

This vulnerability allows remote authenticated attackers with privileged access to execute arbitrary commands on Dolibarr ERP CRM systems. Attackers c...

Sep 20, 2023
CVE-2023-35850
7.2

This vulnerability allows authenticated attackers with administrator or privileged accounts in SUNNET WMPro portal to execute arbitrary system command...

Sep 18, 2023
CVE-2023-39362
7.2

This vulnerability allows authenticated privileged users in Cacti 1.2.24 to perform command injection through SNMP device configuration, leading to re...

Sep 5, 2023
CVE-2022-43907
7.2

CVE-2022-43907 is an OS command injection vulnerability in IBM Security Guardium that allows authenticated remote attackers to execute arbitrary comma...

Aug 27, 2023
CVE-2023-34215
7.2

This vulnerability allows remote attackers to execute arbitrary commands on TN-5900 Series devices due to insufficient input validation in the certifi...

Aug 17, 2023
CVE-2023-33238
7.2

This CVE describes a command injection vulnerability in Moxa TN-4900 and TN-5900 series industrial routers. Insufficient input validation in certifica...

Aug 17, 2023
CVE-2023-37863
7.2

This vulnerability allows remote attackers with SNMPv2 write privileges to gain full administrative access to PHOENIX CONTACT WP 6xxx series web panel...

Aug 9, 2023
CVE-2023-21411
7.2

CVE-2023-21411 is an OS command injection vulnerability in Axis camera access control settings that allows authenticated attackers to execute arbitrar...

Aug 3, 2023
CVE-2023-35019
7.2

CVE-2023-35019 is an OS command injection vulnerability in IBM Security Verify Governance, Identity Manager 10.0 that allows authenticated remote atta...

Jul 31, 2023
CVE-2023-38056
7.2

This vulnerability allows authenticated OTRS administrators to execute arbitrary commands on the server through improper input sanitization in the Sys...

Jul 24, 2023
CVE-2023-23777
7.2

This vulnerability allows privileged attackers to execute arbitrary bash commands on FortiWeb web application firewalls through crafted CLI backup par...

Jul 11, 2023
CVE-2023-25583
7.2

Two OS command injection vulnerabilities in the zebra vlan_name functionality of Milesight UR32L routers allow remote attackers to execute arbitrary c...

Jul 6, 2023
CVE-2023-24595
7.2

This CVE describes an OS command injection vulnerability in the ys_thirdparty system_user_script functionality of Milesight UR32L routers. Attackers c...

Jul 6, 2023
CVE-2023-3333
7.2

This CVE describes an OS command injection vulnerability in multiple NEC Aterm router models that allows authenticated attackers with high privileges ...

Jun 28, 2023
CVE-2023-34420
7.2

This vulnerability allows authenticated users with elevated privileges in Lenovo XClarity Administrator (LXCA) to execute arbitrary commands through c...

Jun 26, 2023
CVE-2023-33381
7.2

This CVE describes a command injection vulnerability in the MitraStar GPT-2741GNAC router's ping functionality. Authenticated users can execute arbitr...

Jun 6, 2023
CVE-2023-27988
7.2

This vulnerability allows authenticated attackers with administrator privileges to execute arbitrary operating system commands on affected Zyxel NAS32...

May 30, 2023
CVE-2023-33617
7.2

This CVE describes an OS command injection vulnerability in Parks Fiberlink 210 routers that allows attackers to execute arbitrary commands on the dev...

May 23, 2023
CVE-2023-28392
7.2

This vulnerability allows authenticated users with administrative privileges to execute arbitrary operating system commands on affected Wi-Fi AP UNIT ...

May 23, 2023

About OS Command Injection (CWE-78)

The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.

Our database tracks 1,873 CVEs classified as CWE-78, with 755 rated critical and 948 rated high severity. The average CVSS score for OS Command Injection vulnerabilities is 8.6.

External reference: View CWE-78 on MITRE CWE →

Monitor OS Command Injection Vulnerabilities

Get alerted when new OS Command Injection CVEs affect your infrastructure.

Start Monitoring Free