CWE-78: OS Command Injection
The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.
Yearly Trend
Top Affected Vendors
All OS Command Injection CVEs (1,893)
This vulnerability allows physically present attackers to execute arbitrary code with root privileges on Kenwood DMX958XR car multimedia systems by ex...
Aug 6, 2025This vulnerability allows physically present attackers to execute arbitrary code with root privileges on Kenwood DMX958XR car multimedia receivers by ...
Aug 6, 2025This vulnerability allows physically present attackers to execute arbitrary code with root privileges on Kenwood DMX958XR car multimedia systems by ex...
Aug 6, 2025A command injection vulnerability in Poly Clariti Manager versions before 10.12.2 allows privileged users to execute arbitrary commands on the system....
Jul 22, 2025This vulnerability in the ns_backup TYPO3 extension allows attackers to execute arbitrary commands on the server through command injection. It affects...
May 21, 2025This CVE describes an OS command injection vulnerability in TOTOLINK X5000R routers where an attacker can execute arbitrary commands via the 'week' pa...
Jan 15, 2025This CVE describes an OS command injection vulnerability in TOTOLINK X5000R routers via the 'desc' parameter in the setWiFiScheduleCfg function. Attac...
Jan 15, 2025This vulnerability allows a malicious or compromised MacPorts mirror to execute arbitrary commands with root privileges on client machines during the ...
Jan 7, 2025CVE-2024-56137 is a remote command execution vulnerability in MaxKB's function library module that allows privileged users to execute arbitrary operat...
Jan 2, 2025This vulnerability allows remote authenticated attackers to execute arbitrary commands on IBM Security Directory Integrator systems by sending special...
Dec 20, 2024This vulnerability allows remote attackers to execute arbitrary operating system commands on affected TOTOLINK routers via the /boafrm/formSysCmd comp...
Nov 27, 2024This vulnerability allows physically present attackers to execute arbitrary code on Visteon infotainment systems by exploiting command injection in th...
Nov 22, 2024This vulnerability allows physically present attackers to execute arbitrary code on Visteon infotainment systems by injecting commands through crafted...
Nov 22, 2024This vulnerability allows authenticated attackers with administrator privileges on the local network to execute arbitrary operating system commands on...
Nov 12, 2024This vulnerability allows physically present attackers to execute arbitrary code with root privileges on Alpine Halo9 infotainment systems without aut...
Sep 28, 2024CVE-2024-39607 is an OS command injection vulnerability in ELECOM wireless LAN routers that allows authenticated administrators to execute arbitrary o...
Aug 1, 2024An authenticated command injection vulnerability in HPE Aruba EdgeConnect SD-WAN gateways allows attackers with CLI access to execute arbitrary comman...
Jul 24, 2024This CVE describes a command injection vulnerability in TOTOLINK A6000R routers that allows attackers to execute arbitrary commands on the device. The...
Jul 22, 2024This vulnerability allows network-adjacent attackers with Telnet credentials to execute arbitrary commands as root on D-Link DAP-2622 access points. T...
May 3, 2024This vulnerability allows network-adjacent attackers to execute arbitrary code with root privileges on D-Link DIR-1935 routers by bypassing authentica...
Mar 29, 2023This vulnerability allows network-adjacent attackers to execute arbitrary code as root on D-Link DIR-1935 routers by bypassing authentication and expl...
Mar 29, 2023This vulnerability allows authenticated attackers on the same network to bypass authentication and execute arbitrary code with root privileges on D-Li...
Mar 29, 2023This vulnerability allows authenticated attackers on the same network to execute arbitrary code with root privileges on D-Link DIR-1935 routers by exp...
Mar 29, 2023A command injection vulnerability in the AOS-CX Operating System allows authenticated remote attackers to execute arbitrary commands on affected syste...
Nov 18, 2025This CVE describes an OS command injection vulnerability in Dell PowerProtect Data Domain systems. A high-privileged attacker with local access can ex...
Oct 7, 2025This CVE describes an OS command injection vulnerability in Dell PowerProtect Data Domain systems running affected DD OS versions. A high-privileged a...
Oct 7, 2025This CVE describes an OS command injection vulnerability in Dell PowerProtect Data Domain systems running affected DD OS versions. A high-privileged a...
Oct 7, 2025This CVE describes an OS command injection vulnerability in Dell PowerProtect Data Domain systems running affected DD OS versions. A high-privileged a...
Oct 7, 2025This CVE describes an OS command injection vulnerability in Dell PowerProtect Data Domain systems running affected DD OS versions. A high-privileged a...
Oct 7, 2025Dell Cloud Disaster Recovery versions before 19.20 contain an OS command injection vulnerability that allows high-privileged local attackers to execut...
Sep 25, 2025This vulnerability in EdgeConnect SD-WAN's command line interface allows authenticated attackers to execute arbitrary operating system commands throug...
Sep 16, 2025This CVE describes an OS command injection vulnerability in Fortinet FortiWeb's command-line interface that allows privileged attackers to execute arb...
Aug 12, 2025This CVE describes an OS command injection vulnerability in Dell PowerProtect Data Domain's DDSH CLI. A high-privileged attacker with local access can...
Aug 4, 2025This CVE describes an OS command injection vulnerability in Dell PowerProtect Data Domain's DDSH CLI. A high-privileged attacker with local access can...
Aug 4, 2025This vulnerability allows a high-privileged attacker with local access to execute arbitrary OS commands with root privileges on Dell PowerProtect Data...
Aug 4, 2025A local privilege escalation vulnerability in Juniper Junos OS and Junos OS Evolved allows high-privileged local attackers to execute arbitrary comman...
Jul 11, 2025This CVE describes an OS command injection vulnerability in Fortinet FortiManager and FortiAnalyzer products. Attackers can execute arbitrary commands...
Mar 11, 2025This CVE describes an OS command injection vulnerability in Fortinet FortiMail and FortiRecorder products. Attackers with CLI access can execute arbit...
Jan 14, 2025This CVE describes an OS command injection vulnerability in Fortinet FortiVoice phone systems. Authenticated privileged attackers can execute arbitrar...
Jan 14, 2025This CVE describes an OS command injection vulnerability in Fortinet FortiAP devices that allows local authenticated attackers to execute arbitrary co...
Jan 14, 2025This CVE describes OS command injection vulnerabilities in Fortinet FortiManager and FortiAnalyzer products. Authenticated privileged attackers can ex...
Nov 12, 2024CVE-2025-48069 is a command injection vulnerability in ejson2env versions before 2.0.8 where insufficient output sanitization allows malicious content...
May 21, 2025This OS command injection vulnerability in Drupal AI allows attackers to execute arbitrary operating system commands on the server. It affects Drupal ...
Mar 31, 2025This OS command injection vulnerability in Fortinet FortiWeb allows attackers to execute arbitrary commands on affected devices by sending specially c...
Feb 11, 2025This CVE describes an OS command injection vulnerability in UD-LT2 firmware that allows authenticated CLI users to execute arbitrary operating system ...
Jan 22, 2025This vulnerability allows attackers with administrative privileges in BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) to inject com...
Dec 18, 2024This CVE describes an OS command injection vulnerability in Fortinet FortiDDoS and FortiDDoS-F products. An authenticated attacker can execute arbitra...
Aug 13, 2024This CVE describes an OS command injection vulnerability in QNAP Media Streaming add-on that allows authenticated administrators to execute arbitrary ...
May 3, 2024This vulnerability allows authenticated administrators on Cisco UCS Manager to execute arbitrary operating system commands with root privileges due to...
Feb 25, 2026This CVE describes an OS command injection vulnerability in Dell PowerProtect Data Domain systems running affected DD OS versions. A high-privileged a...
Jan 9, 2026About OS Command Injection (CWE-78)
The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.
Our database tracks 1,893 CVEs classified as CWE-78, with 766 rated critical and 956 rated high severity. The average CVSS score for OS Command Injection vulnerabilities is 8.6.
External reference: View CWE-78 on MITRE CWE →
Monitor OS Command Injection Vulnerabilities
Get alerted when new OS Command Injection CVEs affect your infrastructure.
Start Monitoring Free