CWE-78: OS Command Injection
The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.
Yearly Trend
Top Affected Vendors
All OS Command Injection CVEs (1,885)
This vulnerability allows attackers with administrator cookies to inject malicious commands through improperly validated URLs in Cellopoint CelloOS. I...
Aug 25, 2020CVE-2020-16205 is an OS command injection vulnerability in Geutebruck G-Cam and G-Code devices that allows remote authenticated attackers to execute a...
Aug 14, 2020This CVE allows remote attackers to execute arbitrary operating system commands on affected GPON ONU devices by injecting shell metacharacters into th...
Jul 15, 2020CVE-2020-4512 is an OS command injection vulnerability in IBM QRadar SIEM that allows authenticated privileged users to execute arbitrary commands on ...
Jul 14, 2020This CVE describes an OS command injection vulnerability in PAN-OS management interfaces that allows authenticated administrators to execute arbitrary...
Jul 8, 2020This vulnerability allows authenticated remote attackers with administrative privileges to execute arbitrary commands on Cisco TelePresence and RoomOS...
Jun 18, 2020An OS command injection vulnerability in PAN-OS management server allows authenticated administrators to execute arbitrary OS commands with root privi...
Jun 10, 2020Monstra CMS 3.0.4 allows authenticated administrators to execute arbitrary operating system commands through the Theme Module's Edit Chunk feature. Th...
Jun 9, 2020CVE-2025-11142 is an OS command injection vulnerability in Axis camera VAPIX API's mediaclip.cgi endpoint that allows authenticated attackers with ope...
Feb 10, 2026CVE-2023-26039 is an OS command injection vulnerability in ZoneMinder's HostController.php that allows authenticated users to execute arbitrary shell ...
Feb 25, 2023This vulnerability allows an unauthenticated attacker to execute arbitrary code as root on Linux systems running vulnerable FortiClient versions by tr...
Apr 6, 2022CVE-2021-21315 is a command injection vulnerability in the systeminformation npm package that allows attackers to execute arbitrary commands on affect...
Feb 16, 2021This CVE describes a local privilege escalation vulnerability in FortiSOAR where an attacker with existing low-privileged shell access can execute arb...
Oct 14, 2025Xiaomi routers have a command injection vulnerability in their external interface due to insufficient input filtering. Attackers can exploit this by h...
Aug 2, 2023This vulnerability in RDoc (Ruby's documentation generator) allows arbitrary code execution when processing filenames containing pipe (|) or backtick ...
Jul 30, 2021This vulnerability allows authenticated attackers on the same network to execute arbitrary commands as root on Deciso OPNsense firewalls. The flaw exi...
Feb 20, 2026The VSCode extension for Spring CLI contains a command injection vulnerability (CWE-78) that allows attackers to execute arbitrary commands on a user'...
Jan 14, 2026CVE-2025-55055 is an OS command injection vulnerability that allows attackers to execute arbitrary commands on affected systems by injecting malicious...
Nov 17, 2025pgAdmin 4 on Windows systems contains a command injection vulnerability that allows attackers to execute arbitrary system commands through specially c...
Nov 13, 2025This CVE describes an OS command injection vulnerability in SAP Business Connector that allows authenticated administrators with adjacent network acce...
Nov 11, 2025This vulnerability allows physically present attackers to execute arbitrary code with root privileges on Kenwood DMX958XR car multimedia receivers. At...
Aug 6, 2025This vulnerability allows physically present attackers to execute arbitrary code with root privileges on Kenwood DMX958XR car multimedia receivers dur...
Aug 6, 2025This vulnerability allows physically present attackers to execute arbitrary code with root privileges on Kenwood DMX958XR car multimedia systems by ex...
Aug 6, 2025This vulnerability allows physically present attackers to execute arbitrary code with root privileges on Kenwood DMX958XR car multimedia receivers by ...
Aug 6, 2025This vulnerability allows physically present attackers to execute arbitrary code with root privileges on Kenwood DMX958XR car multimedia systems witho...
Aug 6, 2025This vulnerability allows physically present attackers to execute arbitrary code with root privileges on Kenwood DMX958XR in-car entertainment systems...
Aug 6, 2025This vulnerability allows physically present attackers to execute arbitrary code with root privileges on Kenwood DMX958XR car multimedia systems. Atta...
Aug 6, 2025This vulnerability allows physically present attackers to execute arbitrary code with root privileges on Kenwood DMX958XR car multimedia systems witho...
Aug 6, 2025This vulnerability allows physically present attackers to execute arbitrary code with root privileges on Kenwood DMX958XR car multimedia receivers by ...
Aug 6, 2025This vulnerability allows physically present attackers to execute arbitrary code with root privileges on Kenwood DMX958XR car multimedia receivers by ...
Aug 6, 2025This vulnerability allows physically present attackers to execute arbitrary code with root privileges on Kenwood DMX958XR car multimedia receivers by ...
Aug 6, 2025This vulnerability allows physically present attackers to execute arbitrary code with root privileges on Kenwood DMX958XR car multimedia receivers. At...
Aug 6, 2025This vulnerability allows physically present attackers to execute arbitrary code with root privileges on Kenwood DMX958XR car multimedia receivers by ...
Aug 6, 2025This vulnerability allows physically present attackers to execute arbitrary code with root privileges on Kenwood DMX958XR car multimedia receivers by ...
Aug 6, 2025This CVE describes a command injection vulnerability in Kenwood DMX958XR firmware update process that allows physically present attackers to execute a...
Aug 6, 2025This vulnerability allows physically present attackers to execute arbitrary code with root privileges on Kenwood DMX958XR car multimedia systems by ex...
Aug 6, 2025This vulnerability allows physically present attackers to execute arbitrary code with root privileges on Kenwood DMX958XR car multimedia receivers dur...
Aug 6, 2025This vulnerability allows physically present attackers to execute arbitrary code with root privileges on Kenwood DMX958XR car multimedia systems by ex...
Aug 6, 2025This vulnerability allows physically present attackers to execute arbitrary code with root privileges on Kenwood DMX958XR car multimedia receivers by ...
Aug 6, 2025This vulnerability allows physically present attackers to execute arbitrary code with root privileges on Kenwood DMX958XR car multimedia receivers by ...
Aug 6, 2025This vulnerability allows physically present attackers to execute arbitrary code with root privileges on Kenwood DMX958XR car multimedia receivers. At...
Aug 6, 2025This vulnerability allows physically present attackers to execute arbitrary code with root privileges on Kenwood DMX958XR car multimedia systems by ex...
Aug 6, 2025This vulnerability allows physically present attackers to execute arbitrary code with root privileges on Kenwood DMX958XR car multimedia systems by ex...
Aug 6, 2025This vulnerability allows physically present attackers to execute arbitrary code with root privileges on Kenwood DMX958XR car multimedia systems by ex...
Aug 6, 2025This vulnerability allows physically present attackers to execute arbitrary code with root privileges on Kenwood DMX958XR car multimedia receivers by ...
Aug 6, 2025This vulnerability allows physically present attackers to execute arbitrary code with root privileges on Kenwood DMX958XR car multimedia systems by ex...
Aug 6, 2025A command injection vulnerability in Poly Clariti Manager versions before 10.12.2 allows privileged users to execute arbitrary commands on the system....
Jul 22, 2025This vulnerability in the ns_backup TYPO3 extension allows attackers to execute arbitrary commands on the server through command injection. It affects...
May 21, 2025This CVE describes an OS command injection vulnerability in TOTOLINK X5000R routers where an attacker can execute arbitrary commands via the 'week' pa...
Jan 15, 2025This CVE describes an OS command injection vulnerability in TOTOLINK X5000R routers via the 'desc' parameter in the setWiFiScheduleCfg function. Attac...
Jan 15, 2025About OS Command Injection (CWE-78)
The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.
Our database tracks 1,885 CVEs classified as CWE-78, with 766 rated critical and 949 rated high severity. The average CVSS score for OS Command Injection vulnerabilities is 8.6.
External reference: View CWE-78 on MITRE CWE →
Monitor OS Command Injection Vulnerabilities
Get alerted when new OS Command Injection CVEs affect your infrastructure.
Start Monitoring Free