CWE-78— OS Command Injection
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.— MITRE CWE catalog
7,004 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-78page 4 of 141
- CVE-2025-15379CRITICALCVSS 10.0EG 10.02026-03-30
A command injection vulnerability exists in MLflow's model serving container initialization code, specifically in the `_install_model_dependencies_to_env()` function. When deploying a model with `env_manager=LOCAL`, MLflow reads dependency…
- CVE-2026-30302CRITICALCVSS 10.0EG 10.02026-03-27
The command auto-approval module in CodeRider-Kilo contains an OS Command Injection vulnerability, rendering its whitelist security mechanism ineffective. The vulnerability stems from the incorrect use of an incompatible command parser (th…
- CVE-2026-33478CRITICALCVSS 10.0EG 10.02026-03-23
WWBN AVideo is an open source video platform. In versions up to and including 26.0, multiple vulnerabilities in AVideo's CloneSite plugin chain together to allow a completely unauthenticated attacker to achieve remote code execution. The `…
- CVE-2021-35402CRITICALCVSS 10.0EG 10.02026-02-20
PROLiNK PRC2402M 20190909 before 2021-06-13 allows live_api.cgi?page=satellite_list OS command injection via shell metacharacters in the ip parameter (for satellite_status).
- CVE-2024-58338CRITICALCVSS 10.0EG 10.02025-12-30
Anevia Flamingo XL 3.2.9 contains a restricted shell vulnerability that allows remote attackers to escape the sandboxed environment through the traceroute command. Attackers can exploit the traceroute command to inject shell commands and g…
- CVE-2025-63414CRITICALCVSS 10.0EG 10.02025-12-16
A Path Traversal vulnerability in the Allsky WebUI version v2024.12.06_06 allows an unauthenticated remote attacker to achieve arbitrary command execution. By sending a crafted HTTP request to the /html/execute.php endpoint with a maliciou…
- CVE-2025-64128CRITICALCVSS 10.0EG 10.02025-11-26
An OS command injection vulnerability exists due to incomplete validation of user-supplied input. Validation fails to enforce sufficient formatting rules, which could permit attackers to append arbitrary data. This could allow an unauth…
- CVE-2025-64127CRITICALCVSS 10.0EG 10.02025-11-26
An OS command injection vulnerability exists due to insufficient sanitization of user-supplied input. The application accepts parameters that are later incorporated into OS commands without adequate validation. This could allow an unaut…
- CVE-2025-64126CRITICALCVSS 10.0EG 10.02025-11-26
An OS command injection vulnerability exists due to improper input validation. The application accepts a parameter directly from user input without verifying it is a valid IP address or filtering potentially malicious characters. This c…
- CVE-2025-10230CRITICALCVSS 10.0EG 10.02025-11-07
A flaw was found in Samba, in the front-end WINS hook handling: NetBIOS names from registration packets are passed to a shell without proper validation or escaping. Unsanitized NetBIOS name data from WINS registration packets are inserted …
- CVE-2018-25118CRITICALCVSS 10.0EG 10.02025-10-20
GeoVision embedded IP devices, confirmed on GV-BX1500 and GV-MFD1501, contain a remote command injection vulnerability via /PictureCatch.cgi that enables an attacker to execute arbitrary commands on the device. The vulnerable models hav…
- CVE-2009-20011CRITICALCVSS 10.0EG 10.02025-08-30
ContentKeeper Web Appliance (now maintained by Impero Software) versions prior to 125.10 are vulnerable to remote command execution due to insecure handling of file uploads via the mimencode CGI utility. The vulnerability allows unauthent…
- CVE-2025-34160CRITICALCVSS 10.0EG 10.02025-08-27
AnyShare contains a critical unauthenticated remote code execution vulnerability in the ServiceAgent API exposed on port 10250. The endpoint /api/ServiceAgent/start_service accepts user-supplied input via POST and fails to sanitize command…
- CVE-2024-13985CRITICALCVSS 10.0EG 10.02025-08-27
A command injection vulnerability in Dahua EIMS versions prior to 2240008 allows unauthenticated remote attackers to execute arbitrary system commands via the capture_handle.action interface. The flaw stems from improper input validation i…
- CVE-2018-25115CRITICALCVSS 10.0EG 10.02025-08-27
Multiple D-Link DIR-series routers, including DIR-110, DIR-412, DIR-600, DIR-610, DIR-615, DIR-645, and DIR-815 firmware version 1.03, contain a vulnerability in the service.cgi endpoint that allows remote attackers to execute arbitrary sy…
- CVE-2011-10017CRITICALCVSS 10.0EG 10.02025-08-13
Snort Report versions < 1.3.2 contains a remote command execution vulnerability in the nmap.php and nbtscan.php scripts. These scripts fail to properly sanitize user input passed via the target GET parameter, allowing attackers to inject a…
- CVE-2014-125124CRITICALCVSS 10.0EG 10.02025-07-31
An unauthenticated remote command execution vulnerability exists in Pandora FMS versions up to and including 5.0RC1 via the Anyterm web interface, which listens on TCP port 8023. The anyterm-module endpoint accepts unsanitized user input v…
- CVE-2025-5243CRITICALCVSS 10.0EG 10.02025-07-24
Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SMG Software Information Portal allows Code Injection, Upload a Web Shell to a Web…
- CVE-2025-34112CRITICALCVSS 10.0EG 10.02025-07-15
An authenticated multi-stage remote code execution vulnerability exists in Riverbed SteelCentral NetProfiler and NetExpress 10.8.7 virtual appliances. A SQL injection vulnerability in the '/api/common/1.0/login' endpoint can be exploited t…
- CVE-2025-3499CRITICALCVSS 10.0EG 10.02025-07-09
The device has two web servers that expose unauthenticated REST APIs on the management network (TCP ports 8084 and 8086). Exploiting OS command injection through these APIs, an attacker can send arbitrary commands that are executed with ad…
- CVE-2025-34073CRITICALCVSS 10.0EG 10.02025-07-02
An unauthenticated command injection vulnerability exists in stamparm/maltrail (Maltrail) versions <=0.54. A remote attacker can execute arbitrary operating system commands via the username parameter in a POST request to the /login endpoin…
- CVE-2025-34054CRITICALCVSS 10.0EG 10.02025-07-01
An unauthenticated command injection vulnerability exists in AVTECH DVR devices via Search.cgi?action=cgi_query. The use of wget without input sanitization allows attackers to inject shell commands through the username or queryb64str param…
- CVE-2025-34043CRITICALCVSS 10.0EG 10.02025-06-26
A remote command injection vulnerability exists in Vacron Network Video Recorder (NVR) devices v1.4 due to improper input sanitization in the board.cgi script. The vulnerability allows unauthenticated attackers to pass arbitrary commands t…
- CVE-2025-34041CRITICALCVSS 10.0EG 10.02025-06-24
An OS command injection vulnerability exists in the Chinese versions of Sangfor Endpoint Detection and Response (EDR) management platform versions 3.2.16, 3.2.17, and 3.2.19. The vulnerability allows unauthenticated attackers to construct …
- CVE-2025-34039CRITICALCVSS 10.0EG 10.02025-06-24
A code injection vulnerability exists in Yonyou UFIDA NC v6.5 and prior due to the exposure of the BeanShell testing servlet (bsh.servlet.BshServlet) without proper access controls. The servlet allows unauthenticated remote attackers to ex…
- CVE-2025-34037CRITICALCVSS 10.0EG 10.02025-06-24
An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /hndUnblock.cgi endpoints over HTTP on port 8080. The CGI scripts improperly process user-supplied input passed to the t…
- CVE-2025-34030CRITICALCVSS 10.0EG 10.02025-06-20
An OS command injection vulnerability exists in sar2html version 3.2.2 and prior via the plot parameter in index.php. The application fails to sanitize user-supplied input before using it in a system-level context. Remote, unauthenticated …
- CVE-2025-26389CRITICALCVSS 10.0EG 10.02025-05-13
A vulnerability has been identified in OZW672 (All versions < V8.0), OZW772 (All versions < V8.0). The web service in affected devices does not sanitize the input parameters required for the `exportDiagramPage` endpoint. This could allow a…
- CVE-2021-47667CRITICALCVSS 10.0EG 10.02025-04-05
An OS command injection vulnerability in lib/NSSDropoff.php in ZendTo 5.24-3 through 6.x before 6.10-7 allows unauthenticated remote attackers to execute arbitrary commands via shell metacharacters in the tmp_name parameter when dropping o…
- CVE-2025-2071CRITICALCVSS 10.0EG 10.02025-03-31
A critical OS Command Injection vulnerability has been identified in the FAST LTA Silent Brick WebUI, allowing remote attackers to execute arbitrary operating system commands via specially crafted input. This vulnerability arises due to im…
- CVE-2025-27364CRITICALCVSS 10.0EG 10.02025-02-24
In MITRE Caldera through 4.2.0 and 5.0.0 before 35bc06e, a Remote Code Execution (RCE) vulnerability was found in the dynamic agent (implant) compilation functionality of the server. This allows remote attackers to execute arbitrary code o…
- CVE-2024-52034CRITICALCVSS 10.0EG 10.02024-11-22
An OS Command Injection vulnerability exists within myPRO Manager. A parameter within a command can be exploited by an unauthenticated remote attacker to inject arbitrary operating system commands.
- CVE-2024-47407CRITICALCVSS 10.0EG 10.02024-11-22
A parameter within a command does not properly validate input within myPRO Manager which could be exploited by an unauthenticated remote attacker to inject arbitrary operating system commands.
- CVE-2024-51568CRITICALCVSS 10.0EG 10.02024-10-29
CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecutioner() sink. There is /filemanager/upload (aka File Manager upload) unauthenticated remote code execution via shell me…
- CVE-2024-47901CRITICALCVSS 10.0EG 10.02024-10-23
A vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fire Subscriber (All versions < V7.2.12 only if the IP interface is enabled (which is not the default configuration)). The…
- CVE-2024-7591CRITICALCVSS 10.0EG 10.02024-09-05
Improper Input Validation vulnerability in Progress LoadMaster allows OS Command Injection.This issue affects: * LoadMaster: 7.2.40.0 and above * ECS: All versions * Multi-Tenancy: 7.1.35.4 and above
- CVE-2023-3939CRITICALCVSS 10.0EG 10.02024-05-21
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in ZkTeco-based OEM devices allows OS Command Injection. Since all the found command implementations are executed from the superus…
- CVE-2024-32766CRITICALCVSS 10.0EG 10.02024-04-26
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. We have already fixed the vulnerability in the …
- CVE-2024-24576CRITICALCVSS 10.0EG 10.02024-04-09
Rust is a programming language. The Rust Security Response WG was notified that the Rust standard library prior to version 1.77.2 did not properly escape arguments when invoking batch files (with the `bat` and `cmd` extensions) on Windows …
- CVE-2024-2389CRITICALCVSS 10.0EG 10.02024-04-02
In Flowmon versions prior to 11.1.14 and 12.3.5, an operating system command injection vulnerability has been identified. An unauthenticated user can gain entry to the system via the Flowmon management interface, allowing for the execut…
- CVE-2024-30247CRITICALCVSS 10.0EG 10.02024-03-29
NextcloudPi is a ready to use image for Virtual Machines, Raspberry Pi, Odroid HC1, Rock64 and other boards. A command injection vulnerability in NextCloudPi allows command execution as the root user via the NextCloudPi web-panel. Due to a…
- CVE-2024-23109CRITICALCVSS 10.0EG 10.02024-02-05
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands via via crafted API requests.
- CVE-2024-23108CRITICALCVSS 10.0EG 10.02024-02-05
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands via via crafted API requests.
- CVE-2023-3991CRITICALCVSS 10.0EG 10.02023-10-16
An OS command injection vulnerability exists in the httpd iperfrun.cgi functionality of FreshTomato 2023.3. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this vuln…
- CVE-2023-34992CRITICALCVSS 10.0EG 10.02023-10-10
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands via crafted API requests.
- CVE-2023-3572CRITICALCVSS 10.0EG 10.02023-08-08
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote, unauthenticated attacker may use an attribute of a specific HTTP POST request releated to date/time operations to gain full access to the device.
- CVE-2023-2564CRITICALCVSS 10.0EG 10.02023-05-07
OS Command Injection in GitHub repository sbs20/scanservjs prior to v2.27.0.
- CVE-2023-2131CRITICALCVSS 10.0EG 10.02023-04-20
Versions of INEA ME RTU firmware prior to 3.36 are vulnerable to OS command injection, which could allow an attacker to remotely execute arbitrary code.
- CVE-2022-33195CRITICALCVSS 10.0EG 10.02022-10-25
Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A XCMD can lead to arbitrary command execution. An attacker can send a sequence of mali…
- CVE-2022-33194CRITICALCVSS 10.0EG 10.02022-10-25
Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A XCMD can lead to arbitrary command execution. An attacker can send a sequence of mali…
Map vulnerabilities like CWE-78 to your infrastructure
EchelonGraph correlates every CVE — across CWE-78 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →