CWE-78— OS Command Injection
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.— MITRE CWE catalog
7,002 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-78page 2 of 141
- CVE-2019-17621CRITICALCVSS 9.8EG 9.8⚠ KEV2019-12-30
The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system commands as root, by sending a specially crafted HTTP SUBSCRIBE request to the UPnP serv…
- CVE-2019-16920CRITICALCVSS 9.8EG 9.8⚠ KEV2019-09-27
Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565. The issue occurs when the attacker sends an arbitrary input to a "PingTest" device common gateway interface that could lead …
- CVE-2019-16057CRITICALCVSS 9.8EG 9.8⚠ KEV2019-09-16
The login_mgr.cgi script in D-Link DNS-320 through 2.05.B10 is vulnerable to remote command injection.
- CVE-2019-15107CRITICALCVSS 9.8EG 9.8⚠ KEV2019-08-16
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnerability.
- CVE-2019-10149CRITICALCVSS 9.8EG 9.8⚠ KEV2019-06-05
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.
- CVE-2018-14839CRITICALCVSS 9.8EG 9.8⚠ KEV2019-05-14
LG N1A1 NAS 3718.510 is affected by: Remote Command Execution. The impact is: execute arbitrary code (remote). The attack vector is: HTTP POST with parameters.
- CVE-2017-18368CRITICALCVSS 9.8EG 9.8⚠ KEV2019-05-02
The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user. The vul…
- CVE-2019-3929CRITICALCVSS 9.8EG 9.8⚠ KEV2019-04-30
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Barco wePresent WiPG-1600W before firmware 2.4.1.19, Extron ShareLink 200/250 firmware 2.0.3.4, Teq AV IT WIPS710 firmwar…
- CVE-2018-14558CRITICALCVSS 9.8EG 9.8⚠ KEV2018-10-30
An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9), and AC10 devices with firmware through V15.03.06.23_CN(AC10). A command Injection vulner…
- CVE-2018-14933CRITICALCVSS 9.8EG 9.8⚠ KEV2018-08-04
upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir parameter for a writeuploaddir command.
- CVE-2018-11138CRITICALCVSS 9.8EG 9.8⚠ KEV2018-05-31
The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be abused to execute arbitrary commands on the system.
- CVE-2018-10562CRITICALCVSS 9.8EG 9.8⚠ KEV2018-05-04
An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_action=ping request to a GponForm/diag_Form URI. Because the router saves ping results in /tmp and transmits them to the …
- CVE-2018-6530CRITICALCVSS 9.8EG 9.8⚠ KEV2018-03-06
OS command injection vulnerability in soap.cgi (soapcgi_main in cgibin) in D-Link DIR-880L DIR-880L_REVA_FIRMWARE_PATCH_1.08B04 and previous versions, DIR-868L DIR868LA1_FW112b04 and previous versions, DIR-65L DIR-865L_REVA_FIRMWARE_PATCH_…
- CVE-2017-6077CRITICALCVSS 9.8EG 9.8⚠ KEV2017-02-22
ping.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ping_IPAddr field of an HTTP POST request.
- CVE-2014-7169CRITICALCVSS 9.8EG 9.8⚠ KEV2014-09-25
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a cra…
- CVE-2014-6271CRITICALCVSS 9.8EG 9.8⚠ KEV2014-09-24
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the …
- CVE-2021-40407CRITICALCVSS 7.2EG 9.8⚠ KEV2022-01-28
An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_20121102. At [1] or [2], based on DDNS type, the ddns->domain variable, that has the value of the domain parameter pro…
- CVE-2025-54948CRITICALCVSS 9.4EG 9.4⚠ KEV2025-08-05
A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations.
- CVE-2020-4006CRITICALCVSS 9.1EG 9.1⚠ KEV2020-11-23
VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability.
- CVE-2020-4428CRITICALCVSS 9.1EG 9.1⚠ KEV2020-05-07
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary commands on the system. IBM X-Force ID: 180533.
- CVE-2025-48703CRITICALCVSS 9.0EG 9.0⚠ KEV2025-09-19
CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager changePerm request. A valid non-root username must be known.
- CVE-2026-73570CRITICALCVSS 8.9EG 9.0⚠ KEV2026-08-13
A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP no…
- CVE-2026-42271CRITICALCVSS 8.8EG 9.0⚠ KEV2026-05-08
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints used to preview an MCP server before saving it — POST /mcp-rest/test/connection and POST /m…
- CVE-2026-34197CRITICALCVSS 8.8EG 9.0⚠ KEV2026-04-07
Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console…
- CVE-2026-25108CRITICALCVSS 8.8EG 9.0⚠ KEV2026-02-13
FileZen contains an OS command injection vulnerability. When FileZen Antivirus Check Option is enabled, a logged-in user may send a specially crafted HTTP request to execute an arbitrary OS command.
- CVE-2025-8876CRITICALCVSS 8.8EG 9.0⚠ KEV2025-08-14
Improper Input Validation vulnerability in N-able N-central allows OS Command Injection.This issue affects N-central: before 2025.3.1.
- CVE-2024-40891CRITICALCVSS 8.8EG 9.0⚠ KEV2025-02-04
**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to exec…
- CVE-2024-40890CRITICALCVSS 8.8EG 9.0⚠ KEV2025-02-04
**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL CPE Zyxel VMG4325-B10A firmware version 1.00(AAFR.4)C0_20170615 could allow an authenticated attacker to execute opera…
- CVE-2023-47565CRITICALCVSS 8.8EG 9.0⚠ KEV2023-12-08
An OS command injection vulnerability has been found to affect legacy QNAP VioStor NVR models running QVR Firmware 4.x. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fix…
- CVE-2023-49897CRITICALCVSS 8.8EG 9.0⚠ KEV2023-12-06
An OS command injection vulnerability exists in AE1021PE firmware version 2.0.9 and earlier and AE1021 firmware version 2.0.9 and earlier. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can l…
- CVE-2023-39780CRITICALCVSS 8.8EG 9.0⚠ KEV2023-09-11
On ASUS RT-AX55 3.0.0.4.386.51598 devices, authenticated attackers can perform OS command injection via the /start_apply.htm qos_bw_rulelist parameter. NOTE: for the similar "token-generated module" issue, see CVE-2023-41345; for the simil…
- CVE-2022-36804CRITICALCVSS 8.8EG 9.0⚠ KEV2022-08-25
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from version 7.18.0 before version 7.21.4, from version 8.0.0 before version 8.0.3, from version 8…
- CVE-2022-33891CRITICALCVSS 8.8EG 9.0⚠ KEV2022-07-18
The Apache Spark UI offers the possibility to enable ACLs via the configuration option spark.acls.enable. With an authentication filter, this checks whether a user has access permissions to view or modify the application. If ACLs are enabl…
- CVE-2021-25298CRITICALCVSS 8.8EG 9.0⚠ KEV2021-02-15
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/cloud-vm/cloud-vm.inc.php due to improper sanitization of authenticated user-controlled in…
- CVE-2021-25297CRITICALCVSS 8.8EG 9.0⚠ KEV2021-02-15
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/switch/switch.inc.php due to improper sanitization of authenticated user-controlled input …
- CVE-2021-25296CRITICALCVSS 8.8EG 9.0⚠ KEV2021-02-15
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi/html/includes/configwizards/windowswmi/windowswmi.inc.php due to improper sanitization of authenticated user-controlle…
- CVE-2020-11978CRITICALCVSS 8.8EG 9.0⚠ KEV2020-07-17
An issue was found in Apache Airflow versions 1.10.10 and below. A remote code/command injection vulnerability was discovered in one of the example DAGs shipped with Airflow which would allow any authenticated user to run arbitrary command…
- CVE-2020-9377CRITICALCVSS 8.8EG 9.0⚠ KEV2020-07-09
D-Link DIR-610 devices allow Remote Command Execution via the cmd parameter to command.php. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
- CVE-2020-1956CRITICALCVSS 8.8EG 9.0⚠ KEV2020-05-22
Apache Kylin 2.3.0, and releases up to 2.6.5 and 3.0.1 has some restful apis which will concatenate os command with the user input string, a user is likely to be able to execute any os command without any protection or validation.
- CVE-2020-10221CRITICALCVSS 8.8EG 9.0⚠ KEV2020-03-08
lib/ajaxHandlers/ajaxAddTemplate.php in rConfig through 3.94 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the fileName POST parameter.
- CVE-2019-15949CRITICALCVSS 8.8EG 9.0⚠ KEV2019-09-05
Nagios XI before 5.6.6 allows remote command execution as root. The exploit requires access to the server as the nagios user, or access as the admin user via the web interface. The getprofile.sh script, invoked by downloading a system prof…
- CVE-2019-12991CRITICALCVSS 8.8EG 9.0⚠ KEV2019-07-16
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 have Improper Input Validation (issue 5 of 6).
- CVE-2017-6884CRITICALCVSS 8.8EG 9.0⚠ KEV2017-04-06
A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8. The vulnerability is located in the diagnostic tools, specifically the nslookup function. A malicious user may exploit numerou…
- CVE-2017-6334CRITICALCVSS 8.8EG 9.0⚠ KEV2017-03-06
dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the host_name field of an HTTP POST request, a different vulnerability …
- CVE-2014-6278CRITICALCVSS 8.8EG 9.0⚠ KEV2014-09-30
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary commands via a crafted environment, as demonstrated by vectors involvin…
- CVE-2018-6961CRITICALCVSS 8.1EG 9.0⚠ KEV2018-06-11
VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web UI component. This component is disabled by default and should not be enabled on untrusted networks. VeloCloud by VMware…
- CVE-2026-83549CRITICALCVSS 7.8EG 9.0⚠ KEV2026-09-01
Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potential…
- CVE-2021-27102CRITICALCVSS 7.8EG 9.0⚠ KEV2021-02-16
Accellion FTA 9_12_411 and earlier is affected by OS command execution via a local web service call. The fixed version is FTA_9_12_416 and later.
- CVE-2019-20500CRITICALCVSS 7.8EG 9.0⚠ KEV2020-03-05
D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Save Configuration functionality in the Web interface, using shell metacharacters in the admin.cgi?action=config_save configBackup or…
- CVE-2024-9463CRITICALCVSS 7.5EG 9.0⚠ KEV2024-10-09
An OS command injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations,…
Map vulnerabilities like CWE-78 to your infrastructure
EchelonGraph correlates every CVE — across CWE-78 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →