CWE-78: OS Command Injection

The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.

1,911
Total CVEs
770
Critical
970
High
8.6
Avg CVSS
11
In CISA KEV

Yearly Trend

2026
148
2025
465
2024
405
2023
253
2022
163

Top Affected Vendors

1 Dlink 104
2 Totolink 85
3 Dell 60
4 Fortinet 58
5 Tp Link 41
6 Zyxel 36
7 Cisco 33
8 Ruijie 30
9 Arubanetworks 27
10 Ibm 26

All OS Command Injection CVEs (1,911)

CVE-2024-58286
N/A

CVE-2024-58286 is a remote code execution vulnerability in dizqueTV 1.5.3 that allows attackers to inject arbitrary shell commands through the FFMPEG ...

Dec 11, 2025
CVE-2025-66572
N/A

Loaded Commerce 6.6 contains a client-side template injection vulnerability that allows unauthenticated attackers to execute arbitrary code on the ser...

Dec 4, 2025
CVE-2024-58278
N/A

Perl2exe versions up to V30.10C contain an arbitrary code execution vulnerability that allows local authenticated attackers to execute malicious scrip...

Dec 4, 2025
CVE-2025-34319
N/A

This CVE describes an unauthenticated OS command injection vulnerability in TOTOLINK N300RT wireless router firmware, allowing remote attackers to exe...

Dec 3, 2025
CVE-2025-8890
N/A

CVE-2025-8890 is a shell command injection vulnerability in the network diagnostics tool of SDMC NE6037 routers. Attackers with administrative access ...

Nov 27, 2025
CVE-2025-59370
N/A

A command injection vulnerability in bwdpi allows authenticated remote attackers to execute arbitrary commands on affected ASUS routers. This could le...

Nov 25, 2025
CVE-2025-12742
N/A

A Looker user with Developer role can execute arbitrary commands on the server due to insecure processing of Teradata driver parameters. This affects ...

Nov 25, 2025
CVE-2021-4470
N/A

CVE-2021-4470 is a critical pre-authentication remote code execution vulnerability in TG8 Firewall's runphpcmd.php endpoint. Unauthenticated attackers...

Nov 14, 2025
CVE-2021-4466
N/A

CVE-2021-4466 is an authenticated remote code execution vulnerability in IPCop firewall software. Authenticated attackers can inject shell commands th...

Nov 14, 2025
CVE-2025-11546
N/A

This vulnerability allows unauthenticated remote attackers to execute arbitrary operating system commands on affected NEC cluster management software ...

Nov 7, 2025
CVE-2025-27234
N/A

The Zabbix Agent 2 smartctl plugin fails to properly sanitize smart.disk.get parameters, allowing attackers to inject malicious arguments into smartct...

Sep 12, 2025

About OS Command Injection (CWE-78)

The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.

Our database tracks 1,911 CVEs classified as CWE-78, with 770 rated critical and 970 rated high severity. The average CVSS score for OS Command Injection vulnerabilities is 8.6.

External reference: View CWE-78 on MITRE CWE →

Monitor OS Command Injection Vulnerabilities

Get alerted when new OS Command Injection CVEs affect your infrastructure.

Start Monitoring Free