CWE-78: OS Command Injection

The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.

1,893
Total CVEs
766
Critical
956
High
8.6
Avg CVSS
11
In CISA KEV

Yearly Trend

2026
148
2025
465
2024
405
2023
253
2022
163

Top Affected Vendors

1 Dlink 101
2 Totolink 85
3 Dell 59
4 Fortinet 58
5 Tp Link 41
6 Zyxel 36
7 Cisco 33
8 Ruijie 30
9 Arubanetworks 27
10 Ibm 26

All OS Command Injection CVEs (1,893)

CVE-2025-8629
6.8

This vulnerability allows physically present attackers to execute arbitrary code with root privileges on Kenwood DMX958XR car multimedia systems by ex...

Aug 6, 2025
CVE-2025-8630
6.8

This vulnerability allows physically present attackers to execute arbitrary code with root privileges on Kenwood DMX958XR car multimedia receivers by ...

Aug 6, 2025
CVE-2025-8631
6.8

This vulnerability allows physically present attackers to execute arbitrary code with root privileges on Kenwood DMX958XR car multimedia systems by ex...

Aug 6, 2025
CVE-2025-43020
6.8

A command injection vulnerability in Poly Clariti Manager versions before 10.12.2 allows privileged users to execute arbitrary commands on the system....

Jul 22, 2025
CVE-2025-48204
6.8

This vulnerability in the ns_backup TYPO3 extension allows attackers to execute arbitrary commands on the server through command injection. It affects...

May 21, 2025
CVE-2024-57023
6.8

This CVE describes an OS command injection vulnerability in TOTOLINK X5000R routers where an attacker can execute arbitrary commands via the 'week' pa...

Jan 15, 2025
CVE-2024-57025
6.8

This CVE describes an OS command injection vulnerability in TOTOLINK X5000R routers via the 'desc' parameter in the setWiFiScheduleCfg function. Attac...

Jan 15, 2025
CVE-2024-11681
6.8

This vulnerability allows a malicious or compromised MacPorts mirror to execute arbitrary commands with root privileges on client machines during the ...

Jan 7, 2025
CVE-2024-56137
6.8

CVE-2024-56137 is a remote command execution vulnerability in MaxKB's function library module that allows privileged users to execute arbitrary operat...

Jan 2, 2025
CVE-2024-28767
6.8

This vulnerability allows remote authenticated attackers to execute arbitrary commands on IBM Security Directory Integrator systems by sending special...

Dec 20, 2024
CVE-2024-51228
6.8

This vulnerability allows remote attackers to execute arbitrary operating system commands on affected TOTOLINK routers via the /boafrm/formSysCmd comp...

Nov 27, 2024
CVE-2024-8358
6.8

This vulnerability allows physically present attackers to execute arbitrary code on Visteon infotainment systems by exploiting command injection in th...

Nov 22, 2024
CVE-2024-8360
6.8

This vulnerability allows physically present attackers to execute arbitrary code on Visteon infotainment systems by injecting commands through crafted...

Nov 22, 2024
CVE-2024-8881
6.8

This vulnerability allows authenticated attackers with administrator privileges on the local network to execute arbitrary operating system commands on...

Nov 12, 2024
CVE-2024-23961
6.8

This vulnerability allows physically present attackers to execute arbitrary code with root privileges on Alpine Halo9 infotainment systems without aut...

Sep 28, 2024
CVE-2024-39607
6.8

CVE-2024-39607 is an OS command injection vulnerability in ELECOM wireless LAN routers that allows authenticated administrators to execute arbitrary o...

Aug 1, 2024
CVE-2024-41136
6.8

An authenticated command injection vulnerability in HPE Aruba EdgeConnect SD-WAN gateways allows attackers with CLI access to execute arbitrary comman...

Jul 24, 2024
CVE-2024-41315
6.8

This CVE describes a command injection vulnerability in TOTOLINK A6000R routers that allows attackers to execute arbitrary commands on the device. The...

Jul 22, 2024
CVE-2023-44416
6.8

This vulnerability allows network-adjacent attackers with Telnet credentials to execute arbitrary commands as root on D-Link DAP-2622 access points. T...

May 3, 2024
CVE-2022-43632
6.8

This vulnerability allows network-adjacent attackers to execute arbitrary code with root privileges on D-Link DIR-1935 routers by bypassing authentica...

Mar 29, 2023
CVE-2022-43624
6.8

This vulnerability allows network-adjacent attackers to execute arbitrary code as root on D-Link DIR-1935 routers by bypassing authentication and expl...

Mar 29, 2023
CVE-2022-43626
6.8

This vulnerability allows authenticated attackers on the same network to bypass authentication and execute arbitrary code with root privileges on D-Li...

Mar 29, 2023
CVE-2022-43628
6.8

This vulnerability allows authenticated attackers on the same network to execute arbitrary code with root privileges on D-Link DIR-1935 routers by exp...

Mar 29, 2023
CVE-2025-37158
6.7

A command injection vulnerability in the AOS-CX Operating System allows authenticated remote attackers to execute arbitrary commands on affected syste...

Nov 18, 2025
CVE-2025-36567
6.7

This CVE describes an OS command injection vulnerability in Dell PowerProtect Data Domain systems. A high-privileged attacker with local access can ex...

Oct 7, 2025
CVE-2025-36569
6.7

This CVE describes an OS command injection vulnerability in Dell PowerProtect Data Domain systems running affected DD OS versions. A high-privileged a...

Oct 7, 2025
CVE-2025-36566
6.7

This CVE describes an OS command injection vulnerability in Dell PowerProtect Data Domain systems running affected DD OS versions. A high-privileged a...

Oct 7, 2025
CVE-2025-43906
6.7

This CVE describes an OS command injection vulnerability in Dell PowerProtect Data Domain systems running affected DD OS versions. A high-privileged a...

Oct 7, 2025
CVE-2025-43911
6.7

This CVE describes an OS command injection vulnerability in Dell PowerProtect Data Domain systems running affected DD OS versions. A high-privileged a...

Oct 7, 2025
CVE-2025-43943
6.7

Dell Cloud Disaster Recovery versions before 19.20 contain an OS command injection vulnerability that allows high-privileged local attackers to execut...

Sep 25, 2025
CVE-2025-37129
6.7

This vulnerability in EdgeConnect SD-WAN's command line interface allows authenticated attackers to execute arbitrary operating system commands throug...

Sep 16, 2025
CVE-2025-47857
6.7

This CVE describes an OS command injection vulnerability in Fortinet FortiWeb's command-line interface that allows privileged attackers to execute arb...

Aug 12, 2025
CVE-2025-30096
6.7

This CVE describes an OS command injection vulnerability in Dell PowerProtect Data Domain's DDSH CLI. A high-privileged attacker with local access can...

Aug 4, 2025
CVE-2025-30097
6.7

This CVE describes an OS command injection vulnerability in Dell PowerProtect Data Domain's DDSH CLI. A high-privileged attacker with local access can...

Aug 4, 2025
CVE-2025-30098
6.7

This vulnerability allows a high-privileged attacker with local access to execute arbitrary OS commands with root privileges on Dell PowerProtect Data...

Aug 4, 2025
CVE-2025-52988
6.7

A local privilege escalation vulnerability in Juniper Junos OS and Junos OS Evolved allows high-privileged local attackers to execute arbitrary comman...

Jul 11, 2025
CVE-2024-32123
6.7

This CVE describes an OS command injection vulnerability in Fortinet FortiManager and FortiAnalyzer products. Attackers can execute arbitrary commands...

Mar 11, 2025
CVE-2024-56497
6.7

This CVE describes an OS command injection vulnerability in Fortinet FortiMail and FortiRecorder products. Attackers with CLI access can execute arbit...

Jan 14, 2025
CVE-2024-40587
6.7

This CVE describes an OS command injection vulnerability in Fortinet FortiVoice phone systems. Authenticated privileged attackers can execute arbitrar...

Jan 14, 2025
CVE-2024-26012
6.7

This CVE describes an OS command injection vulnerability in Fortinet FortiAP devices that allows local authenticated attackers to execute arbitrary co...

Jan 14, 2025
CVE-2024-32118
6.7

This CVE describes OS command injection vulnerabilities in Fortinet FortiManager and FortiAnalyzer products. Authenticated privileged attackers can ex...

Nov 12, 2024
CVE-2025-48069
6.6

CVE-2025-48069 is a command injection vulnerability in ejson2env versions before 2.0.8 where insufficient output sanitization allows malicious content...

May 21, 2025
CVE-2025-31693
6.6

This OS command injection vulnerability in Drupal AI allows attackers to execute arbitrary operating system commands on the server. It affects Drupal ...

Mar 31, 2025
CVE-2024-50569
6.6

This OS command injection vulnerability in Fortinet FortiWeb allows attackers to execute arbitrary commands on affected devices by sending specially c...

Feb 11, 2025
CVE-2025-23237
6.6

This CVE describes an OS command injection vulnerability in UD-LT2 firmware that allows authenticated CLI users to execute arbitrary operating system ...

Jan 22, 2025
CVE-2024-12686
6.6

This vulnerability allows attackers with administrative privileges in BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) to inject com...

Dec 18, 2024
CVE-2022-27486
6.6

This CVE describes an OS command injection vulnerability in Fortinet FortiDDoS and FortiDDoS-F products. An authenticated attacker can execute arbitra...

Aug 13, 2024
CVE-2023-47220
6.6

This CVE describes an OS command injection vulnerability in QNAP Media Streaming add-on that allows authenticated administrators to execute arbitrary ...

May 3, 2024
CVE-2026-20036
6.5

This vulnerability allows authenticated administrators on Cisco UCS Manager to execute arbitrary operating system commands with root privileges due to...

Feb 25, 2026
CVE-2025-46645
6.5

This CVE describes an OS command injection vulnerability in Dell PowerProtect Data Domain systems running affected DD OS versions. A high-privileged a...

Jan 9, 2026

About OS Command Injection (CWE-78)

The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.

Our database tracks 1,893 CVEs classified as CWE-78, with 766 rated critical and 956 rated high severity. The average CVSS score for OS Command Injection vulnerabilities is 8.6.

External reference: View CWE-78 on MITRE CWE →

Monitor OS Command Injection Vulnerabilities

Get alerted when new OS Command Injection CVEs affect your infrastructure.

Start Monitoring Free