CWE-78: OS Command Injection
The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.
Yearly Trend
Top Affected Vendors
All OS Command Injection CVEs (1,878)
This CVE describes a command injection vulnerability in the MitraStar GPT-2741GNAC router's ping functionality. Authenticated users can execute arbitr...
Jun 6, 2023This vulnerability allows authenticated attackers with administrator privileges to execute arbitrary operating system commands on affected Zyxel NAS32...
May 30, 2023This CVE describes an OS command injection vulnerability in Parks Fiberlink 210 routers that allows attackers to execute arbitrary commands on the dev...
May 23, 2023This vulnerability allows authenticated users with administrative privileges to execute arbitrary operating system commands on affected Wi-Fi AP UNIT ...
May 23, 2023This vulnerability allows authenticated attackers with root/administrator privileges to execute arbitrary OS commands through improper input validatio...
May 10, 2023CVE-2023-28742 is an authenticated remote command execution vulnerability in F5 BIG-IP DNS iQuery mesh functionality. An authenticated attacker with n...
May 3, 2023This CVE describes an OS command injection vulnerability in Fortinet FortiWeb web application firewalls. Attackers can execute arbitrary commands on a...
Mar 7, 2023This CVE describes an OS command injection vulnerability in Barracuda CloudGen WAN Private Edge Gateway devices. Authenticated attackers can execute a...
Mar 3, 2023This is a post-authentication command injection vulnerability in Zyxel firewall devices that allows authenticated administrators to execute arbitrary ...
Feb 7, 2023This vulnerability allows authenticated administrators on SerComm h500s devices to execute arbitrary operating system commands as root via command inj...
Jun 2, 2022This CVE describes an authenticated remote command injection vulnerability in Aruba ClearPass Policy Manager. Attackers with valid credentials can exe...
May 17, 2022This vulnerability allows authenticated attackers to execute arbitrary operating system commands on FortiWAN devices through the web GUI. Attackers ca...
Apr 6, 2022This CVE describes an OS command injection vulnerability in Reolink RLC-410W IP cameras. Attackers can execute arbitrary commands on the device by inj...
Jan 28, 2022This CVE describes an OS command injection vulnerability in Reolink RLC-410W cameras where an attacker can execute arbitrary commands by manipulating ...
Jan 28, 2022CVE-2020-28884 is an OS command injection vulnerability in Liferay Portal Server that allows authenticated administrators to execute arbitrary operati...
Jan 28, 2022Dell VNX2 OE for File versions 8.1.21.266 and earlier contain an authenticated remote code execution vulnerability. A malicious user with valid creden...
Jan 25, 2022CVE-2021-3584 is a server-side remote code execution vulnerability in Foreman that allows authenticated attackers to inject malicious commands through...
Dec 23, 2021This CVE allows remote attackers to execute arbitrary commands on affected HPE Aruba Instant Access Points (IAPs) without authentication. The vulnerab...
Oct 12, 2021This CVE allows remote attackers to execute arbitrary commands on affected HPE Aruba Instant Access Points (IAPs) without authentication. The vulnerab...
Oct 12, 2021This vulnerability allows authenticated attackers on the Telus Wi-Fi Hub's local network to execute arbitrary commands with root privileges. Attackers...
Oct 11, 2021This CVE describes a command injection vulnerability in multiple IP camera devices from UDP Technology, Geutebrück, and other vendors. Attackers can ...
Sep 13, 2021This CVE describes a command injection vulnerability in multiple IP camera devices from UDP Technology, Geutebrück, and other vendors. Attackers can ...
Sep 13, 2021This vulnerability allows authenticated users in Redaxo CMS to execute arbitrary PHP code on the server by uploading malicious modules. It affects Red...
Sep 9, 2021This CVE describes an authenticated command injection vulnerability in Siemens SINEC NMS that allows administrative users to execute arbitrary system ...
Aug 10, 2021This CVE allows remote attackers to execute arbitrary commands on affected Aruba switches by exploiting improper neutralization of special elements in...
Jul 22, 2021This vulnerability allows authenticated attackers to execute arbitrary operating system commands on Mimosa wireless devices through command injection ...
Jul 20, 2021This vulnerability allows remote attackers to execute arbitrary commands on D-LINK DIR-3040 routers by sending specially crafted network requests to t...
Jul 16, 2021CVE-2021-34610 is a remote command execution vulnerability in Aruba ClearPass Policy Manager that allows attackers to execute arbitrary commands on af...
Jul 8, 2021This vulnerability allows authenticated high-privilege attackers to execute arbitrary system commands on Weidmueller Industrial WLAN devices by inject...
Jun 25, 2021This vulnerability allows remote authenticated attackers to execute arbitrary operating system commands on IBM Security Guardium systems by sending sp...
May 24, 2021This CVE describes a command injection vulnerability in Avaya Session Border Controller for Enterprise that allows authenticated remote attackers to e...
Apr 23, 2021This vulnerability allows remote attackers with administrator access to ASUS BMC firmware to execute arbitrary commands via command injection in the W...
Apr 6, 2021This vulnerability allows remote attackers with administrative privileges in baserCMS to execute arbitrary operating system commands. It affects baser...
Mar 26, 2021CVE-2021-26962 is a remote authenticated command injection vulnerability in Aruba AirWave Management Platform that allows authenticated attackers to e...
Mar 5, 2021This CVE describes a remote authenticated command injection vulnerability in Aruba ClearPass Policy Manager that allows authenticated attackers to exe...
Feb 23, 2021This CVE describes a remote authenticated command injection vulnerability in Aruba ClearPass Policy Manager. Authenticated attackers can execute arbit...
Feb 23, 2021This CVE describes a remote authenticated command injection vulnerability in Aruba ClearPass Policy Manager. Authenticated attackers can execute arbit...
Feb 23, 2021This vulnerability allows remote attackers with administrator privileges in FileZen to execute arbitrary operating system commands. It affects FileZen...
Feb 17, 2021CVE-2020-35578 is an OS command injection vulnerability in Nagios XI's Manage Plugins page that allows authenticated admin users to execute arbitrary ...
Jan 13, 2021This vulnerability allows authenticated management users on SonicWall SMA100 appliances to execute arbitrary operating system commands via HTTP POST p...
Jan 9, 2021This vulnerability allows authenticated remote attackers to execute arbitrary operating system commands with elevated privileges on Trend Micro InterS...
Nov 18, 2020This vulnerability allows remote authenticated admin users in Nagios XI 5.7.3 to execute arbitrary operating system commands with apache user privileg...
Oct 20, 2020CVE-2020-2038 is an OS command injection vulnerability in PAN-OS management interfaces that allows authenticated administrators to execute arbitrary o...
Sep 9, 2020This vulnerability allows attackers with administrator cookies to inject malicious commands through improperly validated URLs in Cellopoint CelloOS. I...
Aug 25, 2020CVE-2020-16205 is an OS command injection vulnerability in Geutebruck G-Cam and G-Code devices that allows remote authenticated attackers to execute a...
Aug 14, 2020This CVE allows remote attackers to execute arbitrary operating system commands on affected GPON ONU devices by injecting shell metacharacters into th...
Jul 15, 2020CVE-2020-4512 is an OS command injection vulnerability in IBM QRadar SIEM that allows authenticated privileged users to execute arbitrary commands on ...
Jul 14, 2020This CVE describes an OS command injection vulnerability in PAN-OS management interfaces that allows authenticated administrators to execute arbitrary...
Jul 8, 2020This vulnerability allows authenticated remote attackers with administrative privileges to execute arbitrary commands on Cisco TelePresence and RoomOS...
Jun 18, 2020An OS command injection vulnerability in PAN-OS management server allows authenticated administrators to execute arbitrary OS commands with root privi...
Jun 10, 2020About OS Command Injection (CWE-78)
The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.
Our database tracks 1,878 CVEs classified as CWE-78, with 759 rated critical and 949 rated high severity. The average CVSS score for OS Command Injection vulnerabilities is 8.6.
External reference: View CWE-78 on MITRE CWE →
Monitor OS Command Injection Vulnerabilities
Get alerted when new OS Command Injection CVEs affect your infrastructure.
Start Monitoring Free