CWE-78— OS Command Injection
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.— MITRE CWE catalog
7,004 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-78page 9 of 141
- CVE-2026-80442CRITICALCVSS 8.8EG 9.92026-09-18
IBM Guardium Data Protection 12.2 is vulnerable to an authenticated OS command injection vulnerability in the exportCertificate functionality. Successful exploitation could allow an attacker to execute unauthorized commands and impact the …
- CVE-2026-42364CRITICALCVSS 8.8EG 9.92026-05-04
An os command injection vulnerability exists in the DdnsSetting.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A specially crafted DDNS configuration can lead to arbitrary command execution. An attacker can modify a configuration val…
- CVE-2024-12828CRITICALCVSS 8.8EG 9.92024-12-30
Webmin CGI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Webmin. Authentication is required to exploit this vulnerability. The spe…
- CVE-2023-6201CRITICALCVSS 8.8EG 9.92023-11-28
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Univera Computer System Panorama allows Command Injection. This issue affects Panorama: before 8.0.
- CVE-2023-3573CRITICALCVSS 8.8EG 9.92023-08-08
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges may use a command injection in a HTTP POST request releated to font configuration operations to gain full access to the device.
- CVE-2023-3571CRITICALCVSS 8.8EG 9.92023-08-08
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges may use a specific HTTP POST releated to certificate operations to gain full access to the device.
- CVE-2023-3570CRITICALCVSS 8.8EG 9.92023-08-08
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges may use a specific HTTP DELETE request to gain full access to the device.
- CVE-2026-107780CRITICALCVSS 9.8EG 9.82026-10-08
Dromara Skyeye through commit 003549ae5615bd114ba5bb8ddf6a8e8ead97c321 contains an OS command injection vulnerability in the unauthenticated /post/TtsController/textToSpeech endpoint via the format parameter. Attackers can inject a single …
- CVE-2026-107704CRITICALCVSS 9.8EG 9.82026-10-08
The image_optimizer Ruby gem 1.3.0 through 1.9.0 contains an OS command injection vulnerability in ImageOptimizer#identify_format that allows attackers to execute commands by supplying a crafted image path when the identify option is enabl…
- CVE-2026-107703CRITICALCVSS 9.8EG 9.82026-10-08
@enmaso/node-convert through 1.0.0 contains an OS command injection vulnerability in convert.js that allows attackers to execute shell commands via unsanitized filepath and convertTo arguments. Attackers can inject shell metacharacters or …
- CVE-2026-107699CRITICALCVSS 9.8EG 9.82026-10-08
ppt2png through 0.0.6 contains an OS command injection vulnerability that allows attackers to execute operating system commands by supplying unsanitized input or output path arguments. Attackers can append shell metacharacters such as ';' …
- CVE-2026-105110CRITICALCVSS 9.8EG 9.82026-10-08
OS Command Injection in the login.xgi CGI endpoint in Iskratel Innbox GPON ONT devices allows an unauthenticated remote attacker to execute arbitrary commands as root via the CLI parameter.
- CVE-2026-107459CRITICALCVSS 9.8EG 9.82026-10-08
The SecuShare Pro developed by Openfind has an OS Command Injection vulnerability. Unauthenticated remote attackers can inject arbitrary OS commands and execute them on the server.
- CVE-2026-51870CRITICALCVSS 9.8EG 9.82026-09-30
DeepTutor v1.4.0 is vulnerable to command execution in /tutorbot/agent/tools/shell.py:ExecTool.execute.
- CVE-2026-102828CRITICALCVSS 9.8EG 9.82026-09-29
simple-git, an interface for running git commands in any node.js application, enables applications to execute Git operations from JavaScript. From 3.15.0 until 4.0.1, the default blockUnsafeOperationsPlugin does not classify trailer.<token…
- CVE-2026-13249CRITICALCVSS 9.8EG 9.82026-09-24
An unauthenticated Remote Code Execution via Arbitrary File Upload vulnerability in the web management interface in Honeywell PD45 Industrial Printer version F10.19.010040, allows upload of attacker controlled files without requiring authe…
- CVE-2026-6721CRITICALCVSS 9.8EG 9.82026-09-23
IBM Concert 1.0.0 through 3.0.0 allows an unauthenticated remote attacker can supply specially crafted input that is incorporated into OS commands, resulting in arbitrary command execution on the underlying system. Successful exploitation …
- CVE-2026-43641CRITICALCVSS 9.8EG 9.82026-09-22
Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an OS command injection vulnerability in the billing module handler that allows unauthenticated remote attackers to execute arbitrary commands as root by bypassing authentic…
- CVE-2026-65130CRITICALCVSS 9.8EG 9.82026-09-22
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and informa…
- CVE-2026-95675CRITICALCVSS 9.8EG 9.82026-09-22
D-Link DAP-1360 firmware version 6.14 and earlier contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted requests to the device's web management…
- CVE-2026-74849CRITICALCVSS 9.8EG 9.82026-09-22
Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to a remote code execution vulnerability in the GINA client.
- CVE-2026-93012CRITICALCVSS 9.8EG 9.82026-09-21
Email::Sender::Transport::Sendmail versions before 2.602 for Perl allow arbitrary command execution on Windows sending a message whose envelope address reaches the shell in _sendmail_pipe. On MSWin32 the envelope sender and every recipien…
- CVE-2026-90822CRITICALCVSS 9.8EG 9.82026-09-17
FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100 contain an OS command injection vulnerability in the xtremed daemon. An unauthenticated remote attacker with access to the affected management…
- CVE-2026-81476CRITICALCVSS 9.8EG 9.82026-09-17
Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could po…
- CVE-2026-91102CRITICALCVSS 9.8EG 9.82026-09-16
HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, infor…
- CVE-2026-91100CRITICALCVSS 9.8EG 9.82026-09-16
HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, infor…
- CVE-2026-27565CRITICALCVSS 9.8EG 9.82026-09-16
An unauthenticated remote attacker can upload a malicious IODD file that places and executes a shell script with root privileges. The shell script remains active even after a reboot.
- CVE-2026-89010CRITICALCVSS 9.8EG 9.82026-09-11
WAVLINK WN535M1 and WN535M3 routers running firmware prior to M35M1_V250922 contain an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary commands as root by sending crafted filenames to th…
- CVE-2026-79724CRITICALCVSS 9.8EG 9.82026-09-10
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command.
- CVE-2026-81467CRITICALCVSS 9.8EG 9.82026-09-10
Dell ThinOS 10, versions prior to 2605_10. 2616, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit…
- CVE-2026-79689CRITICALCVSS 9.8EG 9.82026-09-09
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthe…
- CVE-2026-71376CRITICALCVSS 9.8EG 9.82026-09-08
OS command injection vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, …
- CVE-2026-85696CRITICALCVSS 9.8EG 9.82026-09-04
SadTalker contains an OS command injection vulnerability in the video muxing process where uploaded audio filenames are interpolated into ffmpeg commands without proper escaping. Attackers can upload audio files with shell metacharacters i…
- CVE-2026-85672CRITICALCVSS 9.8EG 9.82026-09-04
zerox 1.1.20 contains an OS command injection vulnerability in the file download mechanism where the temporary file extension derived from document URLs is interpolated unsanitized into shell commands executed by poppler utilities. Attacke…
- CVE-2026-62928CRITICALCVSS 9.8EG 9.82026-09-04
XING CPTrans-ME-X contains an OS Command Injection (CWE-78). Unauthenticated OS command may be injected.
- CVE-2026-85426CRITICALCVSS 9.8EG 9.82026-09-03
MOOS-IvP uMemWatch through 24.8.1 constructs shell commands from attacker-chosen MOOS client names without sanitization. Attackers can inject shell metacharacters into client names to execute arbitrary commands as the uMemWatch process use…
- CVE-2026-85425CRITICALCVSS 9.8EG 9.82026-09-03
MOOS-IvP iSay through 24.8.1 contains a remote code execution vulnerability in the SAY_MOOS variable handler that passes unsanitized text to a shell command. Attackers can publish SAY_MOOS messages containing backticks or command substitut…
- CVE-2026-53611CRITICALCVSS 9.8EG 9.82026-09-02
Looking Glass is a modern, stateless network-diagnostic platform — a single self-contained Go binary that fronts a fleet of routers over SSH and exposes ping / traceroute / BGP lookups through a gRPC (ConnectRPC) API, an embedded SvelteK…
- CVE-2026-79408CRITICALCVSS 9.8EG 9.82026-08-31
An OS command injection vulnerability in MetaGPT 0.8.1 allows an attacker to execute arbitrary commands via the path argument of RepoParser.rebuild_class_views() in metagpt/repo_parser.py.
- CVE-2026-82082CRITICALCVSS 9.8EG 9.82026-08-28
NUMail developed by Green-Computing has an OS Command Injection vulnerability. Unauthenticated remote attackers can inject arbitrary OS commands and execute them on the server.
- CVE-2026-37751CRITICALCVSS 9.8EG 9.82026-08-28
An OS command injection vulnerability in the killSessionSync function (lib/agent-runtime.ts) of 23blocks-OS ai-maestro v0.24.17 allows attackers to execute arbitrary commands via a crafted input.
- CVE-2026-74233CRITICALCVSS 9.8EG 9.82026-08-27
Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE2426-C firmware 19.1112, Zbtlink WE5926-EC_QP firmware 20.0516, Zbtlink WF3526-P firmware 19.051, CTN720-W1, LF-1541, and …
- CVE-2026-80138CRITICALCVSS 9.8EG 9.82026-08-25
ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passing it to shell execution. Unauthenticated attackers can submit a crafted POST request to the installer with a malicious php_cli_f…
- CVE-2026-45018CRITICALCVSS 9.8EG 9.82026-08-25
Chainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0, Chainlit deployments with features.mcp.enabled set to true in .chainlit/config.toml expose the POST /mcp endpoint with…
- CVE-2026-63586CRITICALCVSS 9.8EG 9.82026-08-25
The web-based management interface uses a modified uhttpd server with CGI shell scripts. The HTTP Basic Authentication username, taken directly from the Authorization header without sanitization, is inserted into a shell command string exe…
- CVE-2026-71921CRITICALCVSS 9.8EG 9.82026-08-24
Multiple DrayTek VigorSwitch models contain a pre-authentication command injection vulnerability in the setget.cgi interface. The vulnerability is caused by insufficient filtering of the pass field before command execution. A remote attack…
- CVE-2026-71914CRITICALCVSS 9.8EG 9.82026-08-24
Multiple DrayTek VigorAP models contain a command injection vulnerability in the dray_apm component. The vulnerability is caused by insufficient validation of UDP message content after START_SPEED_TEST before command execution. A remote at…
- CVE-2026-78211CRITICALCVSS 9.8EG 9.82026-08-24
4MOSAn GCB Doctor developed by 4MOSAn Security Technology has a OS Command Injection vulnerability. Unauthenticated remote attackers can inject malicious commands through an unremoved ADOdb test page parameter, thereby executing arbitrary …
- CVE-2026-19586CRITICALCVSS 9.8EG 9.82026-08-20
A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an OpenVPN Server due to insufficient validation of client-supplied data during OpenVPN connection establishment. An una…
- CVE-2026-18482CRITICALCVSS 9.8EG 9.82026-08-20
Neo.mjs contains a command injection vulnerability within the FileSystemService.mjs component of the ai/mcp/server/file-system MCP server, where the checkSyntax() and runPlaywrightTest() functions unsafely interpolate caller-controlled abs…
Map vulnerabilities like CWE-78 to your infrastructure
EchelonGraph correlates every CVE — across CWE-78 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →