CWE-78: OS Command Injection
The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.
Yearly Trend
Top Affected Vendors
All OS Command Injection CVEs (1,692)
CVE-2023-35861 is a shell injection vulnerability in Supermicro motherboard BMC email notifications that allows remote attackers to execute arbitrary ...
Jul 31, 2023CVE-2023-37903 is a critical sandbox escape vulnerability in vm2, a Node.js sandboxing library. Attackers with code execution inside the vm2 sandbox c...
Jul 21, 2023This CVE describes an OS command injection vulnerability in HGiga iSherlock user modules. Attackers can execute arbitrary operating system commands on...
Jul 21, 2023A critical command injection vulnerability in Kratos NGC-IDU 9.1.0.4 allows remote attackers to execute arbitrary Linux commands as root via crafted T...
Jul 18, 2023This vulnerability allows remote attackers to execute arbitrary code on RIGOL MSO5000 digital oscilloscopes by injecting shell metacharacters into pas...
Jul 16, 2023This vulnerability allows unauthenticated attackers to execute arbitrary commands on TOTOLINK A3300R routers by manipulating the lang parameter in the...
Jul 7, 2023This CVE describes a command injection vulnerability in TOTOLINK A3300R routers that allows attackers to execute arbitrary commands on the device. Att...
Jul 7, 2023CVE-2022-44720 is an OS command injection vulnerability in Weblib Ucopia web filtering appliances that allows attackers to execute arbitrary commands ...
Jun 29, 2023CVE-2023-26134 is a command injection vulnerability in the git-commit-info npm package where the gitCommitInfo() method fails to sanitize user-control...
Jun 28, 2023CVE-2023-30261 is a critical command injection vulnerability in OpenWB charging station management software that allows remote attackers to execute ar...
Jun 26, 2023CVE-2023-30258 is a critical command injection vulnerability in MagnusBilling that allows unauthenticated remote attackers to execute arbitrary comman...
Jun 23, 2023This is a critical pre-authentication command injection vulnerability in Zyxel NAS devices that allows unauthenticated remote attackers to execute arb...
Jun 19, 2023This CVE describes a system command injection vulnerability in Huawei BiSheng-WNM printer firmware that allows attackers to execute arbitrary commands...
Jun 16, 2023This CVE describes a command injection vulnerability in D-Link Go-RT-AC750 routers where an attacker can execute arbitrary commands via the service pa...
Jun 15, 2023This critical vulnerability in WAGO products allows unauthenticated remote attackers to create new user accounts and modify device configurations. Thi...
May 15, 2023Metersphere v1.20.20-lts-79d354a6 contains a remote command execution vulnerability in the custom code snippet function of the system workbench. Attac...
May 8, 2023This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK A7100RU routers. Attackers can inject malicious commands through ...
May 5, 2023This CVE describes a command injection vulnerability in TOTOLINK X5000R routers that allows remote attackers to execute arbitrary commands via the 'co...
May 5, 2023CVE-2023-25826 is an unauthenticated remote command injection vulnerability in OpenTSDB's legacy HTTP query API. Attackers can execute arbitrary opera...
May 3, 2023CVE-2023-29778 allows remote attackers to execute arbitrary operating system commands on GL.iNET MT3000 routers via command injection in the logread R...
May 2, 2023This vulnerability allows unauthenticated remote attackers to execute arbitrary operating system commands on affected Zyxel firewall devices by sendin...
Apr 25, 2023CVE-2023-30621 is a critical command injection vulnerability in the Gipsy Discord bot that allows unauthenticated users to execute arbitrary commands ...
Apr 21, 2023CVE-2023-29805 is a command injection vulnerability in WFS-SR03 v1.0.3 that allows attackers to execute arbitrary commands on affected systems via the...
Apr 14, 2023This critical command injection vulnerability in Tenda G103 routers allows attackers to execute arbitrary system commands by manipulating the language...
Apr 10, 2023This CVE describes an OS command injection vulnerability in Quectel AG550QCN devices through the ql_atfwd component. Attackers can execute arbitrary c...
Apr 4, 2023CVE-2023-27394 is an unauthenticated OS command injection vulnerability in Osprey Pump Controller version 1.01 that allows attackers to execute arbitr...
Mar 28, 2023This vulnerability in the pullit Node.js package allows attackers to execute arbitrary operating system commands by injecting malicious code into Git ...
Mar 27, 2023This is a critical command injection vulnerability in TOTOLink CP900 outdoor CPE devices that allows unauthenticated attackers to execute arbitrary sy...
Mar 23, 2023This CVE describes a command injection vulnerability in TOTOLink CP900 outdoor CPE devices that allows attackers to execute arbitrary commands via the...
Mar 23, 2023This vulnerability allows attackers to execute arbitrary operating system commands with root privileges on D-Link DIR-820L routers by injecting malici...
Mar 16, 2023This vulnerability allows remote attackers to execute arbitrary operating system commands on Altenergy Power Control Software systems by injecting she...
Mar 14, 2023This CVE describes an OS command injection vulnerability in D-Link DIR-820LA1 routers that allows attackers to execute arbitrary commands with root pr...
Mar 13, 2023This CVE describes an OS command injection vulnerability in D-Link DIR-867 routers that allows attackers to execute arbitrary commands via a crafted L...
Mar 13, 2023This vulnerability allows remote attackers to execute arbitrary commands on TOTOlink A7100RU routers via command injection in the 'ou' parameter. Atta...
Mar 8, 2023This CVE describes an OS command injection vulnerability in Gogs (a self-hosted Git service) that allows attackers to execute arbitrary commands on th...
Feb 25, 2023CVE-2022-48337 is a command injection vulnerability in GNU Emacs' etags utility that allows attackers to execute arbitrary commands via shell metachar...
Feb 20, 2023This vulnerability allows remote unauthenticated attackers to execute arbitrary commands as root on APSystems ECU-R version 5203 devices by injecting ...
Feb 10, 2023A command injection vulnerability in Jitsi on Windows allows attackers to execute arbitrary commands by injecting malicious URLs when launching browse...
Feb 9, 2023CVE-2023-23076 is a critical OS command injection vulnerability in ManageEngine Support Center Plus that allows attackers to execute arbitrary command...
Feb 1, 2023This critical vulnerability in Brocade Fabric OS allows remote unauthenticated attackers to execute arbitrary commands on affected switches. Attackers...
Dec 8, 2022CVE-2022-23100 is a critical OS command injection vulnerability in OX App Suite's Documentconverter component that allows attackers to execute arbitra...
Jul 27, 2022CVE-2022-24405 is a critical OS command injection vulnerability in OX App Suite's Documentconverter API that allows attackers to execute arbitrary com...
Jul 27, 2022This vulnerability allows remote attackers on the local network to execute arbitrary commands as root on Verizon 5G Home LVSKIHP InDoorUnit devices. T...
Jul 14, 2022This vulnerability allows remote attackers on the local network to execute arbitrary commands as root on Verizon 5G Home LVSKIHP outdoor units. The is...
Jul 14, 2022CVE-2022-28888 is a critical remote command execution vulnerability in Spryker Commerce OS that allows attackers to execute arbitrary commands on affe...
Jul 13, 2022This vulnerability allows remote attackers to execute arbitrary code on Tenda AC10 routers by exploiting improper input validation in the lanIp parame...
Jul 7, 2022CVE-2014-0156 is an OS command injection vulnerability in the Awesome Spawn Ruby gem that allows attackers to execute arbitrary commands by passing ma...
Jun 30, 2022This CVE describes command injection vulnerabilities in Robustel R1510 routers that allow remote attackers to execute arbitrary commands via specially...
Jun 30, 2022CVE-2022-33314 is a critical command injection vulnerability in Robustel R1510 routers that allows remote attackers to execute arbitrary commands on a...
Jun 30, 2022CVE-2022-33326 allows remote attackers to execute arbitrary commands on Robustel R1510 routers through command injection in the /ajax/config_rollback/...
Jun 30, 2022About OS Command Injection (CWE-78)
The product constructs all or part of an OS command using externally-influenced input, but does not neutralize special elements that could modify the intended OS command.
Our database tracks 1,692 CVEs classified as CWE-78, with 632 rated critical and 890 rated high severity. The average CVSS score for OS Command Injection vulnerabilities is 8.5.
External reference: View CWE-78 on MITRE CWE →
Monitor OS Command Injection Vulnerabilities
Get alerted when new OS Command Injection CVEs affect your infrastructure.
Start Monitoring Free