CWE-78: OS Command Injection

The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.

1,901
Total CVEs
768
Critical
962
High
8.6
Avg CVSS
11
In CISA KEV

Yearly Trend

2026
148
2025
465
2024
405
2023
253
2022
163

Top Affected Vendors

1 Dlink 103
2 Totolink 85
3 Dell 60
4 Fortinet 58
5 Tp Link 41
6 Zyxel 36
7 Cisco 33
8 Ruijie 30
9 Arubanetworks 27
10 Ibm 26

All OS Command Injection CVEs (1,901)

CVE-2026-26189
5.9

A command injection vulnerability in aquasecurity/trivy-action GitHub Action versions 0.31.0-0.33.1 allows attackers to execute arbitrary commands on ...

Feb 19, 2026
CVE-2025-6193
5.9

A command injection vulnerability in TrustyAI Explainability toolkit allows authenticated users with CR deployment permissions to execute arbitrary co...

Jun 20, 2025
CVE-2024-44072
5.7

This CVE describes an OS command injection vulnerability in BUFFALO wireless LAN routers and repeaters. An authenticated attacker can execute arbitrar...

Sep 10, 2024
CVE-2025-20213
5.5

This vulnerability allows authenticated local attackers with read-only CLI access to overwrite arbitrary files on Cisco Catalyst SD-WAN Manager device...

May 7, 2025
CVE-2025-52379
5.4

This vulnerability allows authenticated attackers to execute arbitrary operating system commands on Nexxt Solutions NCM-X1800 Mesh Routers by exploiti...

Jul 15, 2025
CVE-2025-43920
5.4

This vulnerability allows unauthenticated attackers to execute arbitrary operating system commands on servers running GNU Mailman 2.1.39 in certain ex...

Apr 20, 2025
CVE-2025-56498
5.3

An authenticated OS command injection vulnerability in PLDT WiFi Router's Prolink PGN6401V allows attackers to execute arbitrary system commands with ...

Sep 3, 2025
CVE-2024-31481
5.3

Unauthenticated attackers can cause Denial of Service (DoS) by exploiting vulnerabilities in the CLI service accessed via the PAPI protocol in Aruba/H...

May 14, 2024
CVE-2024-31479
5.3

Unauthenticated attackers can cause Denial of Service (DoS) in Aruba Central Communications service via PAPI protocol, disrupting normal operations. T...

May 14, 2024
CVE-2025-20161
5.1

This vulnerability allows authenticated local administrators on affected Cisco Nexus switches to execute arbitrary commands with root privileges by in...

Feb 26, 2025
CVE-2025-67640
5.0

This vulnerability in Jenkins Git client Plugin allows attackers who can control workspace directory names to inject arbitrary operating system comman...

Dec 10, 2025
CVE-2024-8869
5.0

This critical vulnerability in TOTOLINK A720R routers allows remote attackers to execute arbitrary operating system commands through the exportOvpn fu...

Sep 15, 2024
CVE-2024-53942
4.8

This vulnerability allows remote attackers to execute arbitrary operating system commands with root privileges on affected NRadio N8-180 devices. Atta...

Feb 3, 2025
CVE-2025-36143
4.7

CVE-2025-36143 is an OS command injection vulnerability in IBM Lakehouse (watsonx.data 2.2) that allows authenticated privileged users to execute arbi...

Sep 18, 2025
CVE-2025-25039
4.7

This vulnerability in HPE Aruba ClearPass Policy Manager allows authenticated remote attackers to execute arbitrary commands on the underlying host wi...

Feb 4, 2025
CVE-2024-21906
4.7

This CVE describes an OS command injection vulnerability in QNAP operating systems that allows authenticated administrators to execute arbitrary comma...

Sep 6, 2024
CVE-2024-5338
4.7

This CVE describes a critical OS command injection vulnerability in Ruijie RG-UAC Unified Internet Behavior Management Audit System. Attackers can exe...

May 25, 2024
CVE-2024-5336
4.7

This CVE describes a critical OS command injection vulnerability in Ruijie RG-UAC Unified Internet Behavior Management Audit System. Attackers can rem...

May 25, 2024
CVE-2024-5241
4.7

This CVE describes a critical OS command injection vulnerability in Huashi Private Cloud CDN Live Streaming Acceleration Server. Attackers can remotel...

May 23, 2024
CVE-2024-4508
4.7

This CVE describes a critical OS command injection vulnerability in Ruijie RG-UAC Unified Internet Behavior Management Audit System. Attackers can rem...

May 6, 2024
CVE-2024-4510
4.7

This critical vulnerability in Ruijie RG-UAC Unified Internet Behavior Management Audit System allows remote attackers to execute arbitrary operating ...

May 6, 2024
CVE-2024-4504
4.7

This critical vulnerability in Ruijie RG-UAC Unified Internet Behavior Management Audit System allows remote attackers to execute arbitrary operating ...

May 5, 2024
CVE-2024-4506
4.7

This CVE describes a critical OS command injection vulnerability in Ruijie RG-UAC Unified Internet Behavior Management Audit System. Attackers can exe...

May 5, 2024
CVE-2024-4502
4.7

This critical vulnerability in Ruijie RG-UAC Unified Internet Behavior Management Audit System allows remote attackers to execute arbitrary operating ...

May 5, 2024
CVE-2024-4501
4.7

This CVE describes a critical OS command injection vulnerability in Ruijie RG-UAC Unified Internet Behavior Management Audit System. Attackers can exe...

May 5, 2024
CVE-2025-54941
4.6

This CVE describes an OS command injection vulnerability in Apache Airflow's example_dag_decorator where unvalidated parameters could allow UI users t...

Oct 30, 2025
CVE-2025-60013
4.6

This vulnerability allows authenticated attackers with high privileges to execute arbitrary system commands when initializing the rSeries FIPS module ...

Oct 15, 2025
CVE-2025-52626
4.5

A command injection vulnerability in HCL AION 2.0 allows attackers to execute arbitrary commands on the underlying system by injecting malicious input...

Feb 3, 2026
CVE-2025-20292
4.4

This vulnerability allows authenticated local attackers on Cisco NX-OS devices to execute command injection attacks on the underlying operating system...

Aug 27, 2025
CVE-2023-53158
4.1

This vulnerability in the gix-transport Rust crate allows remote command execution via specially crafted SSH URLs containing ProxyCommand injection. I...

Jul 28, 2025
CVE-2025-53637
4.1

This CVE describes a command injection vulnerability in Meshtastic's GitHub Actions workflow that allows attackers to execute arbitrary code in the CI...

Jul 10, 2025
CVE-2026-1723
N/A

This CVE describes an OS command injection vulnerability in TOTOLINK X6000R routers that allows attackers to execute arbitrary commands on the device....

Jan 30, 2026
CVE-2026-1665
N/A

This CVE describes a command injection vulnerability in nvm (Node Version Manager) where the NVM_AUTH_HEADER environment variable is not properly sani...

Jan 29, 2026
CVE-2026-25063
N/A

A command injection vulnerability in gradle-completion up to version 9.3.0 allows arbitrary code execution when users trigger Bash tab completion in p...

Jan 29, 2026
CVE-2025-6225
N/A

CVE-2025-6225 is a shell command injection vulnerability in Kieback&Peter Neutrino-GLT building management system's SM70 PHWEB web component. Attacker...

Jan 7, 2026
CVE-2025-43875
N/A

This CVE describes an OS command injection vulnerability (CWE-78) in Johnson Controls building automation systems. Successful exploitation could allow...

Dec 24, 2025
CVE-2025-43876
N/A

This CVE describes an OS command injection vulnerability (CWE-78) in Johnson Controls building automation systems. Attackers could execute arbitrary c...

Dec 24, 2025
CVE-2025-65008
N/A

This vulnerability allows remote attackers to execute arbitrary system commands on affected WODESYS routers via the langGet parameter in the adm.cgi e...

Dec 18, 2025
CVE-2025-43873
N/A

This CVE describes an OS command injection vulnerability (CWE-78) in Johnson Controls Metasys products that allows attackers to execute arbitrary comm...

Dec 17, 2025
CVE-2023-53872
N/A

CVE-2023-53872 is an OS command injection vulnerability in Wp2Fac 1.0 that allows remote attackers to execute arbitrary system commands on the server....

Dec 15, 2025
CVE-2024-58286
N/A

CVE-2024-58286 is a remote code execution vulnerability in dizqueTV 1.5.3 that allows attackers to inject arbitrary shell commands through the FFMPEG ...

Dec 11, 2025
CVE-2025-66572
N/A

Loaded Commerce 6.6 contains a client-side template injection vulnerability that allows unauthenticated attackers to execute arbitrary code on the ser...

Dec 4, 2025
CVE-2024-58278
N/A

Perl2exe versions up to V30.10C contain an arbitrary code execution vulnerability that allows local authenticated attackers to execute malicious scrip...

Dec 4, 2025
CVE-2025-34319
N/A

This CVE describes an unauthenticated OS command injection vulnerability in TOTOLINK N300RT wireless router firmware, allowing remote attackers to exe...

Dec 3, 2025
CVE-2025-8890
N/A

CVE-2025-8890 is a shell command injection vulnerability in the network diagnostics tool of SDMC NE6037 routers. Attackers with administrative access ...

Nov 27, 2025
CVE-2025-59370
N/A

A command injection vulnerability in bwdpi allows authenticated remote attackers to execute arbitrary commands on affected ASUS routers. This could le...

Nov 25, 2025
CVE-2025-12742
N/A

A Looker user with Developer role can execute arbitrary commands on the server due to insecure processing of Teradata driver parameters. This affects ...

Nov 25, 2025
CVE-2021-4470
N/A

CVE-2021-4470 is a critical pre-authentication remote code execution vulnerability in TG8 Firewall's runphpcmd.php endpoint. Unauthenticated attackers...

Nov 14, 2025
CVE-2021-4466
N/A

CVE-2021-4466 is an authenticated remote code execution vulnerability in IPCop firewall software. Authenticated attackers can inject shell commands th...

Nov 14, 2025
CVE-2025-11546
N/A

This vulnerability allows unauthenticated remote attackers to execute arbitrary operating system commands on affected NEC cluster management software ...

Nov 7, 2025

About OS Command Injection (CWE-78)

The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.

Our database tracks 1,901 CVEs classified as CWE-78, with 768 rated critical and 962 rated high severity. The average CVSS score for OS Command Injection vulnerabilities is 8.6.

External reference: View CWE-78 on MITRE CWE →

Monitor OS Command Injection Vulnerabilities

Get alerted when new OS Command Injection CVEs affect your infrastructure.

Start Monitoring Free