CWE-78— OS Command Injection
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.— MITRE CWE catalog
6,279 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-78page 109 of 126
- CVE-2026-21861HIGHCVSS 7.2EG 7.22026-03-31
baserCMS is a website development framework. Prior to version 5.2.3, baserCMS contains an OS command injection vulnerability in the core update functionality. An authenticated administrator can execute arbitrary OS commands on the server d…
- CVE-2026-2188HIGHCVSS 7.2EG 7.22026-02-08
A vulnerability was determined in UTT 进取 521G 3.1.1-190816. The impacted element is the function sub_446B18 of the file /goform/formPdbUpConfig. Executing a manipulation of the argument policyNames can lead to os command injection. It …
- CVE-2026-21893HIGHCVSS 7.2EG 7.22026-02-04
n8n is an open source workflow automation platform. From version 0.187.0 to before 1.120.3, a command injection vulnerability was identified in n8n’s community package installation functionality. The issue allowed authenticated users wit…
- CVE-2026-21915MEDIUMCVSS 6.7EG 6.72026-04-09
A Permissive List of Allowed Input vulnerability in the CLI of Juniper Networks Support Insights (JSI) Virtual Lightweight Collector (vLWC) allows a local, high privileged attacker to escalate their privileges to root. The CLI menu accept…
- CVE-2026-22035HIGHCVSS 7.3EG 7.72026-01-08
Greenshot is an open source Windows screenshot utility. Versions 1.3.310 and below arvulnerable to OS Command Injection through unsanitized filename processing. The FormatArguments method in ExternalCommandDestination.cs:269 uses string.Fo…
- CVE-2026-2210HIGHCVSS 7.2EG 7.22026-02-09
A vulnerability has been found in D-Link DIR-823X 250416. This affects the function sub_4211C8 of the file /goform/set_filtering. Such manipulation leads to os command injection. The attack may be launched remotely. The exploit has been di…
- CVE-2026-22100HIGHCVSS 8.6EG 8.62026-07-13
The OCPP DataTransfer message `ReserveLogin` is vulnerable to command injection. By manipulating the data value, arbitrary OS commands can be executed as root.
- CVE-2026-22169MEDIUMCVSS 6.7EG 6.72026-03-18
OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in the safeBins configuration that allows attackers to invoke external helpers through the compress-program option. When sort is explicitly added to tools.exec.…
- CVE-2026-22176MEDIUMCVSS 6.1EG 6.12026-03-19
OpenClaw versions prior to 2026.2.19 contain a command injection vulnerability in Windows Scheduled Task script generation where environment variables are written to gateway.cmd using unquoted set KEY=VALUE assignments, allowing shell meta…
- CVE-2026-22179HIGHCVSS 7.2EG 7.22026-03-18
OpenClaw versions prior to 2026.2.22 in macOS node-host system.run contain an allowlist bypass vulnerability that allows remote attackers to execute non-allowlisted commands by exploiting improper parsing of command substitution tokens. At…
- CVE-2026-22209MEDIUMCVSS 5.5EG 5.52026-03-13
wpDiscuz before 7.6.47 contains a cross-site scripting vulnerability in the customCss field that allows administrators to inject malicious scripts by breaking out of style tags. Attackers with admin access can inject payloads like </style>…
- CVE-2026-22221HIGHCVSS 8.0EG 8.02026-02-02
An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) allows adjacent authenticated attacker execute arbitrary code. Successful exploitation could allow an attacker to gain full administrative control of th…
- CVE-2026-22222HIGHCVSS 8.0EG 8.02026-02-02
An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(web modules) allows adjacent authenticated attacker to execute arbitrary code. Successful exploitation could allow an attacker to gain full administrative control of …
- CVE-2026-22223HIGHCVSS 8.0EG 8.02026-02-02
An OS Command Injection vulnerability in TP-Link Archer BE230 v1.2(vpn modules) allows adjacent authenticated attacker execute arbitrary code. Successful exploitation could allow an attacker to gain full administrative control of th…
- CVE-2026-22224HIGHCVSS 7.2EG 7.22026-02-02
A command injection vulnerability may be exploited after the admin's authentication in the cloud communication interface on the TP-Link Archer BE230 v1.2. Successful exploitation could allow an attacker to gain full administrative control …
- CVE-2026-22225HIGHCVSS 7.2EG 7.22026-02-02
A command injection vulnerability may be exploited after the admin's authentication in the VPN Connection Service on the Archer BE230 v1.2 and Archer AXE75 v1.0. Successful exploitation could allow an attacker to gain full administrative…
- CVE-2026-22226HIGHCVSS 8.5EG 8.52026-02-02
A command injection vulnerability may be exploited after the admin's authentication in the VPN server configuration module on TP-Link Archer BE230 v1.2 and Archer AX73 v2. Successful exploitation could allow an attacker to gain full admini…
- CVE-2026-22227HIGHCVSS 7.2EG 7.22026-02-02
A command injection vulnerability may be exploited after the admin's authentication via the configuration backup restoration function of the TP-Link Archer BE230 v1.2. Successful exploitation could allow an attacker to gain full administra…
- CVE-2026-22229HIGHCVSS 7.2EG 7.22026-02-02
A command injection vulnerability may be exploited after the admin's authentication via the import of a crafted VPN client configuration file on the TP-Link Archer BE230 v1.2 and Deco BE25 v1.0. Successful exploitation could allow an attac…
- CVE-2026-22265HIGHCVSS 7.5EG 7.52026-01-15
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. Prior to 8.2.8.2, command injection vulnerability exists in the log viewing functionality that allows authenticated users to execute arbitrary system co…
- CVE-2026-22277HIGHCVSS 7.8EG 7.82026-01-30
Dell UnityVSA, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vul…
- CVE-2026-22313CRITICALCVSS 9.1EG 9.12026-06-16
The device has a webserver that exposes a REST API authenticated with a token on the management network. By exploiting an OS command injection vulnerability an authenticated attacker can send arbitrary commands to the device that are execu…
- CVE-2026-22550HIGHCVSS 8.8EG 8.82026-02-03
OS command injection vulnerability exists in ELECOM wireless LAN products. A crafted request from a logged-in user may lead to an arbitrary OS command execution.
- CVE-2026-22553CRITICALCVSS 9.8EG 9.82026-02-24
All versions of InSAT MasterSCADA BUK-TS are susceptible to OS command injection through a field in its MMadmServ web interface. Malicious users that use the vulnerable endpoint are potentially able to cause remote code execution.
- CVE-2026-2260HIGHCVSS 7.2EG 7.22026-02-10
A vulnerability was found in D-Link DCS-931L up to 1.13.0. This affects an unknown part of the file /goform/setSysAdmin. The manipulation of the argument AdminID results in os command injection. The attack can be executed remotely. The exp…
- CVE-2026-22621HIGHCVSS 8.3EG 8.32026-07-30
Improper input validation in one of the session management interface of Eaton's Tripp Lite Series PADM firmware could allow an authenticated administrator to execute arbitrary commands within a restricted environment.
- CVE-2026-22622HIGHCVSS 8.8EG 8.82026-07-30
Improper input validation in one of the session management interface of Eaton's Tripp Lite series PADM firmware could allow an authenticated user to elevate privileges resulting in unrestricted access to the device.
- CVE-2026-22708CRITICALCVSS 9.8EG 9.82026-01-14
Cursor is a code editor built for programming with AI. Prior to 2.3, hen the Cursor Agent is running in Auto-Run Mode with Allowlist mode enabled, certain shell built-ins can still be executed without appearing in the allowlist and without…
- CVE-2026-22718MEDIUMCVSS 6.8EG 6.82026-01-14
The VSCode extension for Spring CLI are vulnerable to command injection, resulting in command execution on the users machine.
- CVE-2026-22761MEDIUMCVSS 6.7EG 6.72026-04-20
Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain a command injection vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution with root…
- CVE-2026-22781CRITICALCVSS 9.8EG 9.82026-01-12
TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. TinyWeb HTTP Server before version 1.98 is vulnerable to OS command injection via CGI ISINDEX-style query parameters. The query parameters are passed as command-line argume…
- CVE-2026-22844CRITICALCVSS 9.9EG 9.92026-01-20
A Command Injection vulnerability in Zoom Node Multimedia Routers (MMRs) before version 5.2.1716.0 may allow a meeting participant to conduct remote code execution of the MMR via network access.
- CVE-2026-22893HIGHCVSS 7.2EG 7.22026-06-10
A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have alre…
- CVE-2026-22897CRITICALCVSS 9.8EG 9.82026-03-20
A command injection vulnerability has been reported to affect QuNetSwitch. The remote attackers can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the following version: QuNetSwitc…
- CVE-2026-22901CRITICALCVSS 9.8EG 9.82026-03-20
A command injection vulnerability has been reported to affect QuNetSwitch. If a remote attacker gains a user account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability in the fo…
- CVE-2026-22902MEDIUMCVSS 6.7EG 6.72026-03-20
A command injection vulnerability has been reported to affect QuNetSwitch. If a local attacker gains an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have already fixed the vulnerability …
- CVE-2026-23500CRITICALCVSS 9.1EG 9.12026-04-17
Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versions prior to 23.0.0 , the ODT to PDF conversion process in odf.php concatenates the MAIN_ODT_AS_PDF configuration consta…
- CVE-2026-23515CRITICALCVSS 8.8EG 9.92026-02-02
Signal K Server is a server application that runs on a central hub in a boat. Prior to 1.5.0, a command injection vulnerability allows authenticated users with write permissions to execute arbitrary shell commands on the Signal K server wh…
- CVE-2026-23520CRITICALCVSS 8.0EG 9.02026-01-15
Arcane provides modern docker management. Prior to 1.13.0, Arcane has a command injection in the updater service. Arcane’s updater service supported lifecycle labels com.getarcaneapp.arcane.lifecycle.pre-update and com.getarcaneapp.arcan…
- CVE-2026-23592HIGHCVSS 7.2EG 7.22026-01-27
Insecure file operations in HPE Aruba Networking Fabric Composer’s backup functionality could allow authenticated attackers to achieve remote code execution. Successful exploitation could allow an attacker to execute arbitrary comma…
- CVE-2026-23678HIGHCVSS 8.8EG 8.82026-02-24
Binardat 10G08-0800GSM network switch firmware version V300SP10260209 and prior contain a command injection vulnerability in the traceroute diagnostic function of the affected device web management interface. By injecting the %1a charact…
- CVE-2026-23699HIGHCVSS 7.2EG 7.22026-01-22
AP180 series with firmware versions prior to AP_RGOS 11.9(4)B1P8 contains an OS command injection vulnerability. If this vulnerability is exploited, arbitrary commands may be executed on the devices.
- CVE-2026-23702HIGHCVSS 8.8EG 8.82026-02-27
An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by sending malicious input injected into the server username field of t…
- CVE-2026-23759HIGHCVSS 7.2EG 7.22026-03-17
Perle IOLAN STS/SCS terminal server models with firmware versions prior to 6.0 allow authenticated OS command injection via the restricted shell accessed over Telnet or SSH. The shell 'ps' command does not perform proper argument sanitizat…
- CVE-2026-23774HIGHCVSS 7.2EG 7.22026-04-20
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.10, LTS2024 release versions 7.13.1.0 through 7.13.1.40, contain an OS c…
- CVE-2026-23816HIGHCVSS 7.2EG 7.22026-03-11
A vulnerability in the command line interface of AOS-CX Switches could allow an authenticated remote attacker to execute arbitrary commands on the underlying operating system.
- CVE-2026-23820HIGHCVSS 7.2EG 7.22026-05-12
A vulnerability in the command line interface of Access Points running AOS-10 and AOS-8 Instant could allow an authenticated remote attacker to execute system commands in a restricted shell environment. Successful exploitation could allow …
- CVE-2026-23821HIGHCVSS 7.2EG 7.22026-05-12
A vulnerability in the configuration processing logic of Access Points running AOS-10 could allow an authenticated remote attacker to execute system commands under certain pre-existing conditions. Successful exploitation could allow an att…
- CVE-2026-23882HIGHCVSS 7.2EG 7.22026-03-23
Blinko is an AI-powered card note-taking project. Prior to version 1.8.4, the MCP (Model Context Protocol) server creation function allows specifying arbitrary commands and arguments, which are executed when testing the connection. This is…
- CVE-2026-23920HIGHCVSS 7.7EG 7.72026-03-24
Host and event action script input is validated with a regex (set by the administrator), but the validation runs in multiline mode. If ^ and $ anchors are used in user input validation, an injected newline lets authenticated users bypass t…
Map vulnerabilities like CWE-78 to your infrastructure
EchelonGraph correlates every CVE — across CWE-78 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →