CWE-78— OS Command Injection
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.— MITRE CWE catalog
7,002 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-78page 1 of 141
- CVE-2026-16812CRITICALCVSS 10.0EG 10.0⚠ KEV2026-07-27
VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integri…
- CVE-2026-49869CRITICALCVSS 10.0EG 10.0⚠ KEV2026-06-26
Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().endsWith("/configs") to whitelist the public configuration endpoint from Basic Auth. Becau…
- CVE-2026-10520CRITICALCVSS 10.0EG 10.0⚠ KEV2026-06-09
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution
- CVE-2024-50603CRITICALCVSS 10.0EG 10.0⚠ KEV2025-01-08
An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutralization of special elements used in an OS command, an unauthenticated attacker is able to execute arbitrary code. Shell me…
- CVE-2024-45519CRITICALCVSS 10.0EG 10.0⚠ KEV2024-10-02
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.1.1 sometimes allows unauthenticated users to execute commands.
- CVE-2022-20708CRITICALCVSS 10.0EG 10.0⚠ KEV2022-02-10
Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication a…
- CVE-2024-51378CRITICALCVSS 9.8EG 10.0⚠ KEV2024-10-29
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or /ftp/getresetstatus by bypassing secM…
- CVE-2024-1212CRITICALCVSS 9.8EG 10.0⚠ KEV2024-02-21
Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.
- CVE-2019-7256CRITICALCVSS 9.8EG 10.0⚠ KEV2019-07-02
Linear eMerge E3-Series devices allow Command Injections.
- CVE-2021-38163CRITICALCVSS 9.9EG 9.9⚠ KEV2021-09-14
SAP NetWeaver (Visual Composer 7.0 RT) versions - 7.30, 7.31, 7.40, 7.50, without restriction, an attacker authenticated as a non-administrative user can upload a malicious file over a network and trigger its processing, which is capable o…
- CVE-2026-25089CRITICALCVSS 9.8EG 9.8⚠ KEV2026-06-09
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.…
- CVE-2026-39808CRITICALCVSS 9.8EG 9.8⚠ KEV2026-04-14
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector h…
- CVE-2025-67038CRITICALCVSS 9.8EG 9.8⚠ KEV2026-03-11
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authentication fails. The username is directly concatenated with the command without any sanitization. This allo…
- CVE-2026-1731CRITICALCVSS 9.8EG 9.8⚠ KEV2026-02-06
BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attack…
- CVE-2025-66644CRITICALCVSS 9.8EG 9.8⚠ KEV2025-12-05
Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2025.
- CVE-2025-11953CRITICALCVSS 9.8EG 9.8⚠ KEV2025-11-03
The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default. The server exposes an endpoint that is vulnerable to OS command injection. This allows unauthenticated network attack…
- CVE-2025-1316CRITICALCVSS 9.8EG 9.8⚠ KEV2025-03-05
Edimax IC-7100 does not properly neutralize requests. An attacker can create specially crafted requests to achieve remote code execution on the device
- CVE-2024-11120CRITICALCVSS 9.8EG 9.8⚠ KEV2024-11-15
Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device. Moreover, this vulnerability has alrea…
- CVE-2024-6047CRITICALCVSS 9.8EG 9.8⚠ KEV2024-06-17
Certain EOL GeoVision devices fail to properly filter user input for the specific functionality. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device.
- CVE-2024-4577CRITICALCVSS 9.8EG 9.8⚠ KEV2024-06-09
In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use "Best-Fit" behavior to replace characters in comman…
- CVE-2023-43208CRITICALCVSS 9.8EG 9.8⚠ KEV2023-10-26
NextGen Healthcare Mirth Connect before version 4.4.1 is vulnerable to unauthenticated remote code execution. Note that this vulnerability is caused by the incomplete patch of CVE-2023-37679.
- CVE-2023-27992CRITICALCVSS 9.8EG 9.8⚠ KEV2023-06-19
The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, NAS540 firmware versions prior to V5.21(AATB.11)C0, and NAS542 firmware versions prior to V5.21(ABAG.11)C0 could all…
- CVE-2023-28771CRITICALCVSS 9.8EG 9.8⚠ KEV2023-04-25
Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.35, USG FLEX series firmware versions 4.60 through 5.35, and ATP series firmware versions 4.60 thro…
- CVE-2023-25280CRITICALCVSS 9.8EG 9.8⚠ KEV2023-03-16
OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp.
- CVE-2022-44877CRITICALCVSS 9.8EG 9.8⚠ KEV2023-01-05
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the login parameter.
- CVE-2022-46169CRITICALCVSS 9.8EG 9.8⚠ KEV2022-12-05
Cacti is an open source platform which provides a robust and extensible operational monitoring and fault management framework for users. In affected versions a command injection vulnerability allows an unauthenticated user to execute arbit…
- CVE-2022-29303CRITICALCVSS 9.8EG 9.8⚠ KEV2022-05-12
SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php.
- CVE-2022-30525CRITICALCVSS 9.8EG 9.8⚠ KEV2022-05-12
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 firmware versions 5.00 through 5.21 Patch 1, USG FLEX 500 firmware versions 5.00 through 5.21 Patch …
- CVE-2022-26258CRITICALCVSS 9.8EG 9.8⚠ KEV2022-03-28
D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp.
- CVE-2021-45382CRITICALCVSS 9.8EG 9.8⚠ KEV2022-02-17
A Remote Command Execution (RCE) vulnerability exists in all series H/W revisions D-link DIR-810L, DIR-820L/LW, DIR-826L, DIR-830L, and DIR-836L routers via the DDNS function in ncc2 binary file. Note: DIR-810L, DIR-820L, DIR-830L, DIR-826…
- CVE-2021-27561CRITICALCVSS 9.8EG 9.8⚠ KEV2021-10-15
Yealink Device Management (DM) 3.6.0.20 allows command injection as root via the /sm/api/v1/firewall/zone/services URI, without authentication.
- CVE-2021-36260CRITICALCVSS 9.8EG 9.8⚠ KEV2021-09-22
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vulnerability to launch a command injection attack by sending some messages with malicious co…
- CVE-2021-35394CRITICALCVSS 9.8EG 9.8⚠ KEV2021-08-16
Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as 'UDPServer' binary. The binary is affected by multiple memory corruption vulnerabilities and an arbitrary command inje…
- CVE-2021-36380CRITICALCVSS 9.8EG 9.8⚠ KEV2021-08-13
Sunhillo SureLine before 8.7.0.1.1 allows Unauthenticated OS Command Injection via shell metacharacters in ipAddr or dnsAddr /cgi/networkDiag.cgi.
- CVE-2021-1498CRITICALCVSS 9.8EG 9.8⚠ KEV2021-05-06
Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerab…
- CVE-2021-1497CRITICALCVSS 9.8EG 9.8⚠ KEV2021-05-06
Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, remote attacker to perform command injection attacks against an affected device. For more information about these vulnerab…
- CVE-2020-2509CRITICALCVSS 9.8EG 9.8⚠ KEV2021-04-17
A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. We have already fixed this vulnerability in the …
- CVE-2021-27104CRITICALCVSS 9.8EG 9.8⚠ KEV2021-02-16
Accellion FTA 9_12_370 and earlier is affected by OS command execution via a crafted POST request to various admin endpoints. The fixed version is FTA_9_12_380 and later.
- CVE-2021-22502CRITICALCVSS 9.8EG 9.8⚠ KEV2021-02-08
Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40. The vulnerability could be exploited to allow Remote Code Execution on the OBR server.
- CVE-2020-25506CRITICALCVSS 9.8EG 9.8⚠ KEV2021-02-02
D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead to remote arbitrary code execution.
- CVE-2020-16846CRITICALCVSS 9.8EG 9.8⚠ KEV2020-11-06
An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH client enabled, can result in shell injection.
- CVE-2018-19949CRITICALCVSS 9.8EG 9.8⚠ KEV2020-10-28
If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has already fixed the issue in the following QTS versions. QTS 4.4.2.1231 on build 20200302; QTS 4.4.1.1201 on build 20200130; …
- CVE-2020-25223CRITICALCVSS 9.8EG 9.8⚠ KEV2020-09-25
A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11
- CVE-2020-10987CRITICALCVSS 9.8EG 9.8⚠ KEV2020-07-13
The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary system commands via the deviceName POST parameter.
- CVE-2020-15415CRITICALCVSS 9.8EG 9.8⚠ KEV2020-06-30
On DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote command execution via shell metacharacters in a filename when the text/x-python-script content type is used, a differe…
- CVE-2020-12641CRITICALCVSS 9.8EG 9.8⚠ KEV2020-05-04
rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.
- CVE-2020-9054CRITICALCVSS 9.8EG 9.8⚠ KEV2020-03-04
Multiple ZyXEL network-attached storage (NAS) devices running firmware version 5.21 contain a pre-authentication command injection vulnerability, which may allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable …
- CVE-2020-8515CRITICALCVSS 9.8EG 9.8⚠ KEV2020-02-01
DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow remote code execution as root (without authentication) via shell metacharacters to the cgi-bin/mainfunction.cgi URI. T…
- CVE-2020-7247CRITICALCVSS 9.8EG 9.8⚠ KEV2020-01-29
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP session, as demonstrated by shell metacharacters in a MAIL FROM f…
- CVE-2020-0646CRITICALCVSS 9.8EG 9.8⚠ KEV2020-01-14
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote Code Execution Injection Vulnerability'.
Map vulnerabilities like CWE-78 to your infrastructure
EchelonGraph correlates every CVE — across CWE-78 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →