CWE-78: OS Command Injection
The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.
Yearly Trend
Top Affected Vendors
All OS Command Injection CVEs (1,897)
This CVE describes an OS command injection vulnerability in Fortinet FortiDDoS and FortiDDoS-F products. An authenticated attacker can execute arbitra...
Aug 13, 2024This CVE describes an OS command injection vulnerability in QNAP Media Streaming add-on that allows authenticated administrators to execute arbitrary ...
May 3, 2024This vulnerability allows authenticated administrators on Cisco UCS Manager to execute arbitrary operating system commands with root privileges due to...
Feb 25, 2026This CVE describes an OS command injection vulnerability in Dell PowerProtect Data Domain systems running affected DD OS versions. A high-privileged a...
Jan 9, 2026This CVE describes an OS command injection vulnerability in D-Link C1 routers where an attacker can execute arbitrary commands via the HTTP 'time' par...
Sep 23, 2025This CVE describes an OS command injection vulnerability in Tenda AC9 routers where an attacker can execute arbitrary commands on the device by manipu...
Sep 23, 2025This vulnerability allows authenticated administrators on Cisco UCS Manager to execute arbitrary commands with root privileges through command injecti...
Aug 27, 2025AAPanel v7.0.7 contains an OS command injection vulnerability (CWE-78) that allows attackers to execute arbitrary commands on the server. This affects...
May 21, 2025This vulnerability allows authenticated low-privileged remote attackers to perform OS command injection through Cisco IOS XE's web management interfac...
May 7, 2025This CVE describes an OS command injection vulnerability in the Infinxt iEdge 100 router's Troubleshoot module. Attackers can execute arbitrary comman...
Apr 1, 2025CVE-2025-26320 is an OS command injection vulnerability in t0mer BroadlinkManager v5.9.1 that allows attackers to execute arbitrary commands on the ho...
Mar 4, 2025This vulnerability allows authenticated remote attackers with administrative privileges to execute arbitrary commands as root on Cisco ATA 190 Multipl...
Oct 16, 2024Xiaomi AX9000 routers have a post-authentication command injection vulnerability that allows authenticated attackers to execute arbitrary commands wit...
Aug 26, 2024This vulnerability allows authenticated local attackers to cause Cisco access points to reboot by submitting specially crafted CLI commands. It affect...
Mar 23, 2023This CVE describes an OS command injection vulnerability in Dell PowerProtect Data Domain systems. A high-privileged attacker with local access can ex...
Oct 7, 2025Ghostty terminal emulator versions before 1.3.0 allow control characters like Ctrl+C in pasted/dropped text, which can execute arbitrary commands in s...
Mar 10, 2026This vulnerability allows authenticated users to execute arbitrary commands on IBM DataStage systems due to improper input validation in the wrapped c...
Mar 3, 2026This vulnerability allows authenticated users to execute arbitrary commands on IBM DataStage systems due to improper input validation in the job subro...
Mar 3, 2026This vulnerability in Liquid Prompt allows arbitrary command injection when users navigate to directories containing Git repositories with malicious b...
Feb 20, 2026This vulnerability allows authenticated attackers with at least Observer role credentials to execute arbitrary commands as root in a restricted contai...
Nov 13, 2025This CVE describes an OS command injection vulnerability in Powered BLUE 870 software versions 0.20130927 and earlier. Attackers can execute arbitrary...
Aug 8, 2025This critical vulnerability allows remote attackers to execute arbitrary operating system commands on TOTOLINK T10 routers by exploiting a command inj...
Sep 19, 2024This critical vulnerability in TOTOLINK AC1200 T8 routers allows remote attackers to execute arbitrary operating system commands via the setDiagnosisC...
Aug 22, 2024This CVE describes a critical OS command injection vulnerability in Alien Technology ALR-F800 RFID readers. Attackers can execute arbitrary commands r...
Aug 7, 2024This critical vulnerability allows remote attackers to execute arbitrary operating system commands on affected Raisecom gateway devices by manipulatin...
Aug 5, 2024This CVE describes a critical OS command injection vulnerability in Raisecom gateway devices' web interface. Attackers can execute arbitrary commands ...
Aug 5, 2024This critical vulnerability in TOTOLINK A3600R routers allows remote attackers to execute arbitrary operating system commands via command injection in...
Jul 28, 2024This vulnerability in xdg-desktop-portal-hyprland allows OS command injection due to improper escaping when passing application IDs and titles via env...
Jul 27, 2024This critical vulnerability allows remote attackers to execute arbitrary operating system commands on affected Raisecom gateway devices by manipulatin...
Jul 26, 2024This critical vulnerability in Ruijie RG-UAC 1.0 allows remote attackers to execute arbitrary operating system commands through command injection in t...
Jun 20, 2024This critical vulnerability in Ruijie RG-UAC 1.0 allows remote attackers to execute arbitrary operating system commands via command injection in the g...
Jun 20, 2024This CVE describes a critical OS command injection vulnerability in D-Link DAR-7000-40 network devices. Attackers can remotely execute arbitrary comma...
May 16, 2024This critical vulnerability in Ruijie RG-UAC Unified Internet Behavior Management Audit System allows remote attackers to execute arbitrary operating ...
May 14, 2024This critical vulnerability in Ruijie RG-UAC Unified Internet Behavior Management Audit System allows remote attackers to execute arbitrary operating ...
May 14, 2024This vulnerability allows remote attackers with administrative access to execute arbitrary commands with root privileges on Opto22 Groov Manage device...
Nov 20, 2025This vulnerability in Tiki Wiki CMS allows attackers to inject malicious scripts into web pages through improper HTML tag neutralization. It affects a...
Dec 30, 2024This vulnerability allows authenticated remote attackers with Network Administrator privileges to execute arbitrary operating system commands on Cisco...
Oct 23, 2024This vulnerability in Cisco Catalyst 9300 switches allows authenticated local attackers with level-15 privileges or unauthenticated attackers with phy...
Mar 23, 2023This vulnerability allows authenticated local attackers with Administrator credentials to execute arbitrary code as root on Cisco ASA and FTD devices ...
Mar 4, 2026This CVE describes an OS command injection vulnerability in Dell PowerProtect Data Domain systems. A high-privileged attacker with local access could ...
Jan 9, 2026This vulnerability in Cisco UCS Manager CLI allows authenticated administrators to read, create, or overwrite any file on the underlying operating sys...
Aug 27, 2025This vulnerability allows authenticated local attackers with Administrator credentials to execute arbitrary commands as root on Cisco Secure Firewall ...
Aug 14, 2025This vulnerability in Cisco ATA 190 Series Analog Telephone Adapters allows authenticated local attackers with high privileges to execute arbitrary co...
Oct 16, 2024This vulnerability allows authenticated administrators on Cisco Identity Services Engine (ISE) to execute arbitrary commands on the underlying operati...
Sep 4, 2024This vulnerability allows authenticated users with Administrator credentials to execute arbitrary commands as root on Cisco NX-OS devices through comm...
Jul 1, 2024This vulnerability allows a compadmin user on Dell PowerScale OneFS systems to escalate privileges and execute arbitrary commands as root. It affects ...
Apr 20, 2021A command injection vulnerability in aquasecurity/trivy-action GitHub Action versions 0.31.0-0.33.1 allows attackers to execute arbitrary commands on ...
Feb 19, 2026A command injection vulnerability in TrustyAI Explainability toolkit allows authenticated users with CR deployment permissions to execute arbitrary co...
Jun 20, 2025This CVE describes an OS command injection vulnerability in BUFFALO wireless LAN routers and repeaters. An authenticated attacker can execute arbitrar...
Sep 10, 2024This vulnerability allows authenticated local attackers with read-only CLI access to overwrite arbitrary files on Cisco Catalyst SD-WAN Manager device...
May 7, 2025About OS Command Injection (CWE-78)
The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.
Our database tracks 1,897 CVEs classified as CWE-78, with 766 rated critical and 960 rated high severity. The average CVSS score for OS Command Injection vulnerabilities is 8.6.
External reference: View CWE-78 on MITRE CWE →
Monitor OS Command Injection Vulnerabilities
Get alerted when new OS Command Injection CVEs affect your infrastructure.
Start Monitoring Free