CWE-78: OS Command Injection

The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.

1,885
Total CVEs
766
Critical
949
High
8.6
Avg CVSS
11
In CISA KEV

Yearly Trend

2026
147
2025
465
2024
405
2023
253
2022
163

Top Affected Vendors

1 Dlink 101
2 Totolink 85
3 Dell 59
4 Fortinet 58
5 Tp Link 40
6 Zyxel 36
7 Cisco 33
8 Ruijie 30
9 Arubanetworks 27
10 Ibm 26

All OS Command Injection CVEs (1,885)

CVE-2020-17384
7.2

This vulnerability allows attackers with administrator cookies to inject malicious commands through improperly validated URLs in Cellopoint CelloOS. I...

Aug 25, 2020
CVE-2020-16205
7.2

CVE-2020-16205 is an OS command injection vulnerability in Geutebruck G-Cam and G-Code devices that allows remote authenticated attackers to execute a...

Aug 14, 2020
CVE-2020-8958
7.2

This CVE allows remote attackers to execute arbitrary operating system commands on affected GPON ONU devices by injecting shell metacharacters into th...

Jul 15, 2020
CVE-2020-4512
7.2

CVE-2020-4512 is an OS command injection vulnerability in IBM QRadar SIEM that allows authenticated privileged users to execute arbitrary commands on ...

Jul 14, 2020
CVE-2020-2030
7.2

This CVE describes an OS command injection vulnerability in PAN-OS management interfaces that allows authenticated administrators to execute arbitrary...

Jul 8, 2020
CVE-2020-3336
7.2

This vulnerability allows authenticated remote attackers with administrative privileges to execute arbitrary commands on Cisco TelePresence and RoomOS...

Jun 18, 2020
CVE-2020-2028
7.2

An OS command injection vulnerability in PAN-OS management server allows authenticated administrators to execute arbitrary OS commands with root privi...

Jun 10, 2020
CVE-2020-13978
7.2

Monstra CMS 3.0.4 allows authenticated administrators to execute arbitrary operating system commands through the Theme Module's Edit Chunk feature. Th...

Jun 9, 2020
CVE-2025-11142
7.1

CVE-2025-11142 is an OS command injection vulnerability in Axis camera VAPIX API's mediaclip.cgi endpoint that allows authenticated attackers with ope...

Feb 10, 2026
CVE-2023-26039
7.1

CVE-2023-26039 is an OS command injection vulnerability in ZoneMinder's HostController.php that allows authenticated users to execute arbitrary shell ...

Feb 25, 2023
CVE-2021-22127
7.1

This vulnerability allows an unauthenticated attacker to execute arbitrary code as root on Linux systems running vulnerable FortiClient versions by tr...

Apr 6, 2022
CVE-2021-21315
7.1

CVE-2021-21315 is a command injection vulnerability in the systeminformation npm package that allows attackers to execute arbitrary commands on affect...

Feb 16, 2021
CVE-2024-48891
7.0

This CVE describes a local privilege escalation vulnerability in FortiSOAR where an attacker with existing low-privileged shell access can execute arb...

Oct 14, 2025
CVE-2023-26317
7.0

Xiaomi routers have a command injection vulnerability in their external interface due to insufficient input filtering. Attackers can exploit this by h...

Aug 2, 2023
CVE-2021-31799
7.0

This vulnerability in RDoc (Ruby's documentation generator) allows arbitrary code execution when processing filenames containing pipe (|) or backtick ...

Jul 30, 2021
CVE-2026-2035
6.8

This vulnerability allows authenticated attackers on the same network to execute arbitrary commands as root on Deciso OPNsense firewalls. The flaw exi...

Feb 20, 2026
CVE-2026-22718
6.8

The VSCode extension for Spring CLI contains a command injection vulnerability (CWE-78) that allows attackers to execute arbitrary commands on a user'...

Jan 14, 2026
CVE-2025-55055
6.8

CVE-2025-55055 is an OS command injection vulnerability that allows attackers to execute arbitrary commands on affected systems by injecting malicious...

Nov 17, 2025
CVE-2025-12763
6.8

pgAdmin 4 on Windows systems contains a command injection vulnerability that allows attackers to execute arbitrary system commands through specially c...

Nov 13, 2025
CVE-2025-42892
6.8

This CVE describes an OS command injection vulnerability in SAP Business Connector that allows authenticated administrators with adjacent network acce...

Nov 11, 2025
CVE-2025-8655
6.8

This vulnerability allows physically present attackers to execute arbitrary code with root privileges on Kenwood DMX958XR car multimedia receivers. At...

Aug 6, 2025
CVE-2025-8646
6.8

This vulnerability allows physically present attackers to execute arbitrary code with root privileges on Kenwood DMX958XR car multimedia receivers dur...

Aug 6, 2025
CVE-2025-8647
6.8

This vulnerability allows physically present attackers to execute arbitrary code with root privileges on Kenwood DMX958XR car multimedia systems by ex...

Aug 6, 2025
CVE-2025-8648
6.8

This vulnerability allows physically present attackers to execute arbitrary code with root privileges on Kenwood DMX958XR car multimedia receivers by ...

Aug 6, 2025
CVE-2025-8649
6.8

This vulnerability allows physically present attackers to execute arbitrary code with root privileges on Kenwood DMX958XR car multimedia systems witho...

Aug 6, 2025
CVE-2025-8650
6.8

This vulnerability allows physically present attackers to execute arbitrary code with root privileges on Kenwood DMX958XR in-car entertainment systems...

Aug 6, 2025
CVE-2025-8651
6.8

This vulnerability allows physically present attackers to execute arbitrary code with root privileges on Kenwood DMX958XR car multimedia systems. Atta...

Aug 6, 2025
CVE-2025-8652
6.8

This vulnerability allows physically present attackers to execute arbitrary code with root privileges on Kenwood DMX958XR car multimedia systems witho...

Aug 6, 2025
CVE-2025-8639
6.8

This vulnerability allows physically present attackers to execute arbitrary code with root privileges on Kenwood DMX958XR car multimedia receivers by ...

Aug 6, 2025
CVE-2025-8640
6.8

This vulnerability allows physically present attackers to execute arbitrary code with root privileges on Kenwood DMX958XR car multimedia receivers by ...

Aug 6, 2025
CVE-2025-8641
6.8

This vulnerability allows physically present attackers to execute arbitrary code with root privileges on Kenwood DMX958XR car multimedia receivers by ...

Aug 6, 2025
CVE-2025-8642
6.8

This vulnerability allows physically present attackers to execute arbitrary code with root privileges on Kenwood DMX958XR car multimedia receivers. At...

Aug 6, 2025
CVE-2025-8643
6.8

This vulnerability allows physically present attackers to execute arbitrary code with root privileges on Kenwood DMX958XR car multimedia receivers by ...

Aug 6, 2025
CVE-2025-8644
6.8

This vulnerability allows physically present attackers to execute arbitrary code with root privileges on Kenwood DMX958XR car multimedia receivers by ...

Aug 6, 2025
CVE-2025-8645
6.8

This CVE describes a command injection vulnerability in Kenwood DMX958XR firmware update process that allows physically present attackers to execute a...

Aug 6, 2025
CVE-2025-8632
6.8

This vulnerability allows physically present attackers to execute arbitrary code with root privileges on Kenwood DMX958XR car multimedia systems by ex...

Aug 6, 2025
CVE-2025-8633
6.8

This vulnerability allows physically present attackers to execute arbitrary code with root privileges on Kenwood DMX958XR car multimedia receivers dur...

Aug 6, 2025
CVE-2025-8634
6.8

This vulnerability allows physically present attackers to execute arbitrary code with root privileges on Kenwood DMX958XR car multimedia systems by ex...

Aug 6, 2025
CVE-2025-8635
6.8

This vulnerability allows physically present attackers to execute arbitrary code with root privileges on Kenwood DMX958XR car multimedia receivers by ...

Aug 6, 2025
CVE-2025-8636
6.8

This vulnerability allows physically present attackers to execute arbitrary code with root privileges on Kenwood DMX958XR car multimedia receivers by ...

Aug 6, 2025
CVE-2025-8637
6.8

This vulnerability allows physically present attackers to execute arbitrary code with root privileges on Kenwood DMX958XR car multimedia receivers. At...

Aug 6, 2025
CVE-2025-8638
6.8

This vulnerability allows physically present attackers to execute arbitrary code with root privileges on Kenwood DMX958XR car multimedia systems by ex...

Aug 6, 2025
CVE-2025-8628
6.8

This vulnerability allows physically present attackers to execute arbitrary code with root privileges on Kenwood DMX958XR car multimedia systems by ex...

Aug 6, 2025
CVE-2025-8629
6.8

This vulnerability allows physically present attackers to execute arbitrary code with root privileges on Kenwood DMX958XR car multimedia systems by ex...

Aug 6, 2025
CVE-2025-8630
6.8

This vulnerability allows physically present attackers to execute arbitrary code with root privileges on Kenwood DMX958XR car multimedia receivers by ...

Aug 6, 2025
CVE-2025-8631
6.8

This vulnerability allows physically present attackers to execute arbitrary code with root privileges on Kenwood DMX958XR car multimedia systems by ex...

Aug 6, 2025
CVE-2025-43020
6.8

A command injection vulnerability in Poly Clariti Manager versions before 10.12.2 allows privileged users to execute arbitrary commands on the system....

Jul 22, 2025
CVE-2025-48204
6.8

This vulnerability in the ns_backup TYPO3 extension allows attackers to execute arbitrary commands on the server through command injection. It affects...

May 21, 2025
CVE-2024-57023
6.8

This CVE describes an OS command injection vulnerability in TOTOLINK X5000R routers where an attacker can execute arbitrary commands via the 'week' pa...

Jan 15, 2025
CVE-2024-57025
6.8

This CVE describes an OS command injection vulnerability in TOTOLINK X5000R routers via the 'desc' parameter in the setWiFiScheduleCfg function. Attac...

Jan 15, 2025

About OS Command Injection (CWE-78)

The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.

Our database tracks 1,885 CVEs classified as CWE-78, with 766 rated critical and 949 rated high severity. The average CVSS score for OS Command Injection vulnerabilities is 8.6.

External reference: View CWE-78 on MITRE CWE →

Monitor OS Command Injection Vulnerabilities

Get alerted when new OS Command Injection CVEs affect your infrastructure.

Start Monitoring Free