CWE-78: OS Command Injection

The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.

1,878
Total CVEs
759
Critical
949
High
8.6
Avg CVSS
11
In CISA KEV

Yearly Trend

2026
147
2025
465
2024
405
2023
253
2022
163

Top Affected Vendors

1 Dlink 101
2 Totolink 85
3 Dell 59
4 Fortinet 58
5 Tp Link 38
6 Zyxel 36
7 Cisco 33
8 Ruijie 30
9 Arubanetworks 27
10 Ibm 26

All OS Command Injection CVEs (1,878)

CVE-2023-33381
7.2

This CVE describes a command injection vulnerability in the MitraStar GPT-2741GNAC router's ping functionality. Authenticated users can execute arbitr...

Jun 6, 2023
CVE-2023-27988
7.2

This vulnerability allows authenticated attackers with administrator privileges to execute arbitrary operating system commands on affected Zyxel NAS32...

May 30, 2023
CVE-2023-33617
7.2

This CVE describes an OS command injection vulnerability in Parks Fiberlink 210 routers that allows attackers to execute arbitrary commands on the dev...

May 23, 2023
CVE-2023-28392
7.2

This vulnerability allows authenticated users with administrative privileges to execute arbitrary operating system commands on affected Wi-Fi AP UNIT ...

May 23, 2023
CVE-2023-32568
7.2

This vulnerability allows authenticated attackers with root/administrator privileges to execute arbitrary OS commands through improper input validatio...

May 10, 2023
CVE-2023-28742
7.2

CVE-2023-28742 is an authenticated remote command execution vulnerability in F5 BIG-IP DNS iQuery mesh functionality. An authenticated attacker with n...

May 3, 2023
CVE-2022-39951
7.2

This CVE describes an OS command injection vulnerability in Fortinet FortiWeb web application firewalls. Attackers can execute arbitrary commands on a...

Mar 7, 2023
CVE-2023-26213
7.2

This CVE describes an OS command injection vulnerability in Barracuda CloudGen WAN Private Edge Gateway devices. Authenticated attackers can execute a...

Mar 3, 2023
CVE-2022-38547
7.2

This is a post-authentication command injection vulnerability in Zyxel firewall devices that allows authenticated administrators to execute arbitrary ...

Feb 7, 2023
CVE-2021-44080
7.2

This vulnerability allows authenticated administrators on SerComm h500s devices to execute arbitrary operating system commands as root via command inj...

Jun 2, 2022
CVE-2022-23672
7.2

This CVE describes an authenticated remote command injection vulnerability in Aruba ClearPass Policy Manager. Attackers with valid credentials can exe...

May 17, 2022
CVE-2021-24009
7.2

This vulnerability allows authenticated attackers to execute arbitrary operating system commands on FortiWAN devices through the web GUI. Attackers ca...

Apr 6, 2022
CVE-2021-40410
7.2

This CVE describes an OS command injection vulnerability in Reolink RLC-410W IP cameras. Attackers can execute arbitrary commands on the device by inj...

Jan 28, 2022
CVE-2021-40412
7.2

This CVE describes an OS command injection vulnerability in Reolink RLC-410W cameras where an attacker can execute arbitrary commands by manipulating ...

Jan 28, 2022
CVE-2020-28884
7.2

CVE-2020-28884 is an OS command injection vulnerability in Liferay Portal Server that allows authenticated administrators to execute arbitrary operati...

Jan 28, 2022
CVE-2021-36296
7.2

Dell VNX2 OE for File versions 8.1.21.266 and earlier contain an authenticated remote code execution vulnerability. A malicious user with valid creden...

Jan 25, 2022
CVE-2021-3584
7.2

CVE-2021-3584 is a server-side remote code execution vulnerability in Foreman that allows authenticated attackers to inject malicious commands through...

Dec 23, 2021
CVE-2021-37732
7.2

This CVE allows remote attackers to execute arbitrary commands on affected HPE Aruba Instant Access Points (IAPs) without authentication. The vulnerab...

Oct 12, 2021
CVE-2021-37730
7.2

This CVE allows remote attackers to execute arbitrary commands on affected HPE Aruba Instant Access Points (IAPs) without authentication. The vulnerab...

Oct 12, 2021
CVE-2021-20122
7.2

This vulnerability allows authenticated attackers on the Telus Wi-Fi Hub's local network to execute arbitrary commands with root privileges. Attackers...

Oct 11, 2021
CVE-2021-33551
7.2

This CVE describes a command injection vulnerability in multiple IP camera devices from UDP Technology, Geutebrück, and other vendors. Attackers can ...

Sep 13, 2021
CVE-2021-33553
7.2

This CVE describes a command injection vulnerability in multiple IP camera devices from UDP Technology, Geutebrück, and other vendors. Attackers can ...

Sep 13, 2021
CVE-2021-39459
7.2

This vulnerability allows authenticated users in Redaxo CMS to execute arbitrary PHP code on the server by uploading malicious modules. It affects Red...

Sep 9, 2021
CVE-2021-33721
7.2

This CVE describes an authenticated command injection vulnerability in Siemens SINEC NMS that allows administrative users to execute arbitrary system ...

Aug 10, 2021
CVE-2021-29143
7.2

This CVE allows remote attackers to execute arbitrary commands on affected Aruba switches by exploiting improper neutralization of special elements in...

Jul 22, 2021
CVE-2020-25206
7.2

This vulnerability allows authenticated attackers to execute arbitrary operating system commands on Mimosa wireless devices through command injection ...

Jul 20, 2021
CVE-2021-21819
7.2

This vulnerability allows remote attackers to execute arbitrary commands on D-LINK DIR-3040 routers by sending specially crafted network requests to t...

Jul 16, 2021
CVE-2021-34610
7.2

CVE-2021-34610 is a remote command execution vulnerability in Aruba ClearPass Policy Manager that allows attackers to execute arbitrary commands on af...

Jul 8, 2021
CVE-2021-33534
7.2

This vulnerability allows authenticated high-privilege attackers to execute arbitrary system commands on Weidmueller Industrial WLAN devices by inject...

Jun 25, 2021
CVE-2021-20557
7.2

This vulnerability allows remote authenticated attackers to execute arbitrary operating system commands on IBM Security Guardium systems by sending sp...

May 24, 2021
CVE-2020-7034
7.2

This CVE describes a command injection vulnerability in Avaya Session Border Controller for Enterprise that allows authenticated remote attackers to e...

Apr 23, 2021
CVE-2021-28203
7.2

This vulnerability allows remote attackers with administrator access to ASUS BMC firmware to execute arbitrary commands via command injection in the W...

Apr 6, 2021
CVE-2021-20682
7.2

This vulnerability allows remote attackers with administrative privileges in baserCMS to execute arbitrary operating system commands. It affects baser...

Mar 26, 2021
CVE-2021-26962
7.2

CVE-2021-26962 is a remote authenticated command injection vulnerability in Aruba AirWave Management Platform that allows authenticated attackers to e...

Mar 5, 2021
CVE-2021-26680
7.2

This CVE describes a remote authenticated command injection vulnerability in Aruba ClearPass Policy Manager that allows authenticated attackers to exe...

Feb 23, 2021
CVE-2021-26681
7.2

This CVE describes a remote authenticated command injection vulnerability in Aruba ClearPass Policy Manager. Authenticated attackers can execute arbit...

Feb 23, 2021
CVE-2021-26683
7.2

This CVE describes a remote authenticated command injection vulnerability in Aruba ClearPass Policy Manager. Authenticated attackers can execute arbit...

Feb 23, 2021
CVE-2021-20655
7.2

This vulnerability allows remote attackers with administrator privileges in FileZen to execute arbitrary operating system commands. It affects FileZen...

Feb 17, 2021
CVE-2020-35578
7.2

CVE-2020-35578 is an OS command injection vulnerability in Nagios XI's Manage Plugins page that allows authenticated admin users to execute arbitrary ...

Jan 13, 2021
CVE-2020-5146
7.2

This vulnerability allows authenticated management users on SonicWall SMA100 appliances to execute arbitrary operating system commands via HTTP POST p...

Jan 9, 2021
CVE-2020-28580
7.2

This vulnerability allows authenticated remote attackers to execute arbitrary operating system commands with elevated privileges on Trend Micro InterS...

Nov 18, 2020
CVE-2020-5791
7.2

This vulnerability allows remote authenticated admin users in Nagios XI 5.7.3 to execute arbitrary operating system commands with apache user privileg...

Oct 20, 2020
CVE-2020-2038
7.2

CVE-2020-2038 is an OS command injection vulnerability in PAN-OS management interfaces that allows authenticated administrators to execute arbitrary o...

Sep 9, 2020
CVE-2020-17384
7.2

This vulnerability allows attackers with administrator cookies to inject malicious commands through improperly validated URLs in Cellopoint CelloOS. I...

Aug 25, 2020
CVE-2020-16205
7.2

CVE-2020-16205 is an OS command injection vulnerability in Geutebruck G-Cam and G-Code devices that allows remote authenticated attackers to execute a...

Aug 14, 2020
CVE-2020-8958
7.2

This CVE allows remote attackers to execute arbitrary operating system commands on affected GPON ONU devices by injecting shell metacharacters into th...

Jul 15, 2020
CVE-2020-4512
7.2

CVE-2020-4512 is an OS command injection vulnerability in IBM QRadar SIEM that allows authenticated privileged users to execute arbitrary commands on ...

Jul 14, 2020
CVE-2020-2030
7.2

This CVE describes an OS command injection vulnerability in PAN-OS management interfaces that allows authenticated administrators to execute arbitrary...

Jul 8, 2020
CVE-2020-3336
7.2

This vulnerability allows authenticated remote attackers with administrative privileges to execute arbitrary commands on Cisco TelePresence and RoomOS...

Jun 18, 2020
CVE-2020-2028
7.2

An OS command injection vulnerability in PAN-OS management server allows authenticated administrators to execute arbitrary OS commands with root privi...

Jun 10, 2020

About OS Command Injection (CWE-78)

The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.

Our database tracks 1,878 CVEs classified as CWE-78, with 759 rated critical and 949 rated high severity. The average CVSS score for OS Command Injection vulnerabilities is 8.6.

External reference: View CWE-78 on MITRE CWE →

Monitor OS Command Injection Vulnerabilities

Get alerted when new OS Command Injection CVEs affect your infrastructure.

Start Monitoring Free