CWE-78: OS Command Injection
The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.
Yearly Trend
Top Affected Vendors
All OS Command Injection CVEs (1,681)
This vulnerability allows unauthenticated remote attackers to execute arbitrary system commands on SECOM WRTR-304GN-304TW-UPSC devices due to improper...
Oct 18, 2024This CVE describes an OS command injection vulnerability in Elsight products that allows attackers to execute arbitrary commands on the underlying ope...
Oct 6, 2024CVE-2024-9441 is a critical OS command injection vulnerability in Linear eMerge e3-Series access control systems. Remote unauthenticated attackers can...
Oct 2, 2024CVE-2024-47608 is an OS command injection vulnerability (CWE-78) in Logicytics forensic data collection software that allows attackers to execute arbi...
Oct 1, 2024This vulnerability allows remote attackers to execute arbitrary code on Tenda G3 routers by exploiting improper input sanitization in the USB partitio...
Sep 26, 2024This is an unauthenticated command injection vulnerability in Zyxel NAS devices that allows remote attackers to execute arbitrary operating system com...
Sep 10, 2024This is an unauthenticated OS command injection vulnerability in Zyxel networking devices that allows remote attackers to execute arbitrary commands o...
Sep 3, 2024This vulnerability allows unauthenticated remote attackers to execute arbitrary commands on D-Link DIR-846W routers via the tomography_ping_address pa...
Aug 27, 2024This vulnerability allows remote attackers to execute arbitrary commands on D-Link DIR-846W routers by sending a specially crafted POST request to the...
Aug 27, 2024A command injection vulnerability in Asus RT-N15U routers allows remote attackers to execute arbitrary system commands through the netstat function pa...
Aug 15, 2024This vulnerability allows remote attackers to execute arbitrary commands on Tenda FH1206 routers via a crafted HTTP request to the /goform/telnet endp...
Aug 15, 2024This CVE describes an OS command injection vulnerability in Veribilim Software's Veribase Order Management system. Attackers can execute arbitrary ope...
Aug 12, 2024This CVE describes a shell injection vulnerability in GL-iNet router firmware that allows remote attackers to execute arbitrary commands with root pri...
Aug 6, 2024This vulnerability allows remote attackers to execute arbitrary operating system commands through the Caterease software database layer due to imprope...
Aug 2, 2024This vulnerability allows remote attackers to execute arbitrary operating system commands through SQL injection in Caterease software. Attackers can g...
Aug 2, 2024This CVE describes a command injection vulnerability in Tenda FH1201 routers that allows attackers to execute arbitrary commands on the device. The vu...
Jul 25, 2024CVE-2024-39685 is a critical command injection vulnerability in Bert-VITS2 that allows attackers to execute arbitrary commands on the system by manipu...
Jul 22, 2024This vulnerability allows administrative users on FutureNet NXR, VXR, and WXR series devices from Century Systems to execute arbitrary operating syste...
Jul 17, 2024This vulnerability allows attackers with web interface access to execute arbitrary TELNET commands and view admin passwords on Ruijie EG-2000 series g...
Jul 16, 2024A command injection vulnerability in mudler/localai version 2.14.0 allows attackers to execute arbitrary system commands by manipulating the backend p...
Jun 26, 2024CVE-2024-6048 is a critical OS command injection vulnerability in Openfind's MailGates and MailAudit email security products. Unauthenticated remote a...
Jun 17, 2024This vulnerability allows unauthenticated remote attackers to execute arbitrary system commands on affected GeoVision devices due to improper input fi...
Jun 17, 2024This vulnerability allows remote attackers to execute arbitrary commands on affected Toshiba multifunction printers through improper neutralization of...
Jun 14, 2024CVE-2024-36360 is an unauthenticated remote command injection vulnerability in awkblog v0.0.1 and earlier that allows attackers to execute arbitrary o...
Jun 11, 2024This vulnerability allows remote attackers to execute arbitrary system commands on Pandora FMS servers through improper input validation in the Netflo...
Jun 10, 2024This vulnerability allows remote attackers to execute arbitrary operating system commands on Pandora FMS servers by injecting malicious commands throu...
Jun 10, 2024This is a critical PHP CGI argument injection vulnerability affecting Windows servers running Apache with PHP-CGI. It allows attackers to bypass prote...
Jun 9, 2024This vulnerability in parisneo/lollms-webui version 9.3 allows attackers to bypass access restrictions and execute arbitrary code remotely. Attackers ...
Jun 6, 2024AutoGPT versions v0.5.0 through v5.0.x contain an OS command injection vulnerability due to improper shell command validation. Attackers can bypass al...
Jun 6, 2024This is a critical command injection vulnerability in Zyxel NAS devices that allows unauthenticated attackers to execute arbitrary operating system co...
Jun 4, 2024This critical vulnerability in Aruba access points allows unauthenticated attackers to execute arbitrary commands with root privileges by sending mali...
May 14, 2024CVE-2024-31471 is a critical command injection vulnerability in Aruba's Central Communications service that allows unauthenticated attackers to execut...
May 14, 2024This vulnerability allows remote attackers to execute arbitrary code on systems running vulnerable versions of tiagorlampert CHAOS. The issue stems fr...
May 7, 2024This vulnerability allows attackers to execute arbitrary operating system commands on netis-systems MEX605 routers through the tracert page. Attackers...
May 3, 2024This vulnerability allows remote attackers to execute arbitrary code on LG Simple Editor installations without authentication. Attackers can inject ma...
May 3, 2024This critical vulnerability in Infotel Conseil GLPI allows remote attackers to execute arbitrary code on affected systems due to insufficient input va...
Apr 29, 2024This critical vulnerability in MailCleaner allows remote attackers to execute arbitrary operating system commands through email handling components. A...
Apr 29, 2024This vulnerability allows unauthenticated remote attackers to execute arbitrary code on systems running vulnerable versions of Eclipse Target Manageme...
Apr 26, 2024This CVE describes a command injection vulnerability in mudler/localai's TranscriptEndpoint that allows attackers to execute arbitrary commands on the...
Apr 10, 2024This CVE describes a critical OS command injection vulnerability in the lollms-webui application's '/open_code_folder' endpoint. Attackers can execute...
Apr 10, 2024This vulnerability allows unauthenticated remote attackers to execute arbitrary system commands on Voltronic Power ViewPower Pro installations. Attack...
Apr 1, 2024A remote code execution vulnerability in aliyundrive-webdav versions 2.3.3 and earlier allows attackers to execute arbitrary commands on affected syst...
Mar 29, 2024CVE-2024-28048 is a critical OS command injection vulnerability in ffBull version 4.11 that allows remote unauthenticated attackers to execute arbitra...
Mar 26, 2024CVE-2024-28125 is an OS command injection vulnerability in FitNesse that allows authenticated remote attackers to execute arbitrary commands on the un...
Mar 18, 2024This CVE describes a Server-Side Template Injection (SSTI) vulnerability in Live Helper Chat that allows remote attackers to execute arbitrary code an...
Feb 29, 2024This vulnerability allows remote attackers to execute arbitrary operating system commands on HGiga OAKlouds servers by injecting malicious commands in...
Feb 15, 2024This CVE describes an OS command injection vulnerability in Akaunting v3.1.3 and earlier that allows attackers to execute arbitrary system commands on...
Feb 8, 2024This vulnerability allows remote attackers to execute arbitrary operating system commands on Yealink Meeting Servers through the file upload interface...
Feb 8, 2024This CVE describes a command injection vulnerability in TOTOLINK A3300R routers that allows attackers to execute arbitrary commands on the device. The...
Jan 30, 2024This CVE describes a command injection vulnerability in TOTOLINK A3300R routers that allows attackers to execute arbitrary commands on the device. The...
Jan 30, 2024About OS Command Injection (CWE-78)
The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.
Our database tracks 1,681 CVEs classified as CWE-78, with 625 rated critical and 886 rated high severity. The average CVSS score for OS Command Injection vulnerabilities is 8.5.
External reference: View CWE-78 on MITRE CWE →
Monitor OS Command Injection Vulnerabilities
Get alerted when new OS Command Injection CVEs affect your infrastructure.
Start Monitoring Free