CWE-78— OS Command Injection
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.— MITRE CWE catalog
6,273 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-78page 66 of 126
- CVE-2023-33271CRITICALCVSS 9.8EG 9.82023-10-03
An issue was discovered in DTS Monitoring 3.57.0. The parameter common_name within the SSL Certificate check function is vulnerable to OS command injection (blind).
- CVE-2023-33272CRITICALCVSS 9.8EG 9.82023-10-03
An issue was discovered in DTS Monitoring 3.57.0. The parameter ip within the Ping check function is vulnerable to OS command injection (blind).
- CVE-2023-33273CRITICALCVSS 9.8EG 9.82023-10-03
An issue was discovered in DTS Monitoring 3.57.0. The parameter url within the WGET check function is vulnerable to OS command injection (blind).
- CVE-2023-3333HIGHCVSS 7.2EG 7.22023-06-28
Improper Neutralization of Special Elements used in an OS Command vulnerability in NEC Corporation Aterm WG2600HP2, WG2600HP, WG2200HP, WG1800HP2, WG1800HP, WG1400HP, WG600HP, WG300HP, WF300HP, WR9500N, WR9300N, WR8750N, WR8700N, WR8600N, …
- CVE-2023-33364HIGHCVSS 8.8EG 8.82023-08-03
An OS Command injection vulnerability exists in Suprema BioStar 2 before V2.9.1, which allows authenticated users to execute arbitrary OS commands on the BioStar 2 server.
- CVE-2023-33374CRITICALCVSS 9.8EG 9.82023-08-04
Connected IO v2.1.0 and prior has a command as part of its communication protocol allowing the management platform to specify arbitrary OS commands for devices to execute. Attackers abusing this dangerous functionality may issue all device…
- CVE-2023-33377CRITICALCVSS 9.8EG 9.82023-08-04
Connected IO v2.1.0 and prior has an OS command injection vulnerability in the set firewall command in part of its communication protocol, enabling attackers to execute arbitrary OS commands on devices.
- CVE-2023-33381HIGHCVSS 7.2EG 7.22023-06-06
A command injection vulnerability was found in the ping functionality of the MitraStar GPT-2741GNAC router (firmware version AR_g5.8_110WVN0b7_2). The vulnerability allows an authenticated user to execute arbitrary OS commands by sending s…
- CVE-2023-33617HIGHCVSS 7.2EG 7.22023-05-23
An OS Command Injection vulnerability in Parks Fiberlink 210 firmware version V2.1.14_X000 was found via the /boaform/admin/formPing target_addr parameter.
- CVE-2023-3368CRITICALCVSS 9.8EG 9.82023-11-28
Command injection in `/main/webservices/additional_webservices.php` in Chamilo LMS <= v1.11.20 allows unauthenticated attackers to obtain remote code execution via improper neutralisation of special characters. This is a bypass of CVE-2023…
- CVE-2023-33839HIGHCVSS 7.2EG 7.22023-10-23
IBM Security Verify Governance 10.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 256036.
- CVE-2023-33869MEDIUMCVSS 6.3EG 6.32023-06-20
Enphase Envoy versions D7.0.88 is vulnerable to a command injection exploit that may allow an attacker to execute root commands.
- CVE-2023-33965CRITICALCVSS 9.6EG 9.62023-06-01
Brook is a cross-platform programmable network tool. The `tproxy` server is vulnerable to a drive-by command injection. An attacker may fool a victim into visiting a malicious web page which will trigger requests to the local `tproxy` serv…
- CVE-2023-34105HIGHCVSS 7.5EG 7.52023-06-12
SRS is a real-time video server supporting RTMP, WebRTC, HLS, HTTP-FLV, SRT, MPEG-DASH, and GB28181. Prior to versions 5.0.157, 5.0-b1, and 6.0.48, SRS's `api-server` server is vulnerable to a drive-by command injection. An attacker may se…
- CVE-2023-34108HIGHCVSS 8.8EG 8.82023-06-07
mailcow is a mail server suite based on Dovecot, Postfix and other open source software, that provides a modern web UI for user/server administration. A vulnerability has been discovered in mailcow which allows an attacker to manipulate in…
- CVE-2023-34116HIGHCVSS 8.2EG 8.22023-07-11
Improper input validation in the Zoom Desktop Client for Windows before version 5.15.0 may allow an unauthorized user to enable an escalation of privilege via network access.
- CVE-2023-34127CRITICALCVSS 8.8EG 9.02023-07-13
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SonicWall GMS, SonicWall Analytics enables an authenticated attacker to execute arbitrary code with root privileges. This issue aff…
- CVE-2023-34138HIGHCVSS 8.0EG 8.02023-07-17
A command injection vulnerability in the hotspot management feature of the Zyxel ATP series firmware versions 4.60 through 5.36 Patch 2, USG FLEX series firmware versions 4.60 through 5.36 Patch 2, USG FLEX 50(W) series firmware versions …
- CVE-2023-34139HIGHCVSS 8.8EG 8.82023-07-17
A command injection vulnerability in the Free Time WiFi hotspot feature of the Zyxel USG FLEX series firmware versions 4.50 through 5.36 Patch 2 and VPN series firmware versions 4.20 through 5.36 Patch 2, could allow an unauthenticated, L…
- CVE-2023-34141HIGHCVSS 8.0EG 8.02023-07-17
A command injection vulnerability in the access point (AP) management feature of the Zyxel ATP series firmware versions 5.00 through 5.36 Patch 2, USG FLEX series firmware versions 5.00 through 5.36 Patch 2, USG FLEX 50(W) series firmware…
- CVE-2023-34152CRITICALCVSS 9.8EG 9.82023-05-30
A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured.
- CVE-2023-34213HIGHCVSS 8.8EG 8.82023-08-17
TN-5900 Series firmware versions v3.3 and prior are vulnerable to command-injection vulnerability. This vulnerability stems from insufficient input validation and improper authentication in the key-generation function, which could potentia…
- CVE-2023-34214HIGHCVSS 7.2EG 7.22023-08-17
TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command-injection vulnerability. This vulnerability stems from insufficient input validation in the certificate-gen…
- CVE-2023-34215HIGHCVSS 7.2EG 7.22023-08-17
TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command-injection vulnerability. This vulnerability stems from insufficient input validation and improper authentication in the certification-generation function, which …
- CVE-2023-34254HIGHCVSS 7.6EG 7.62023-06-23
The GLPI Agent is a generic management agent. Prior to version 1.5, if glpi-agent is running remoteinventory task against an Unix platform with ssh command, an administrator user on the remote can manage to inject a command in a specific w…
- CVE-2023-34275HIGHCVSS 8.0EG 8.02024-05-03
D-Link DIR-2150 SetNTPServerSettings Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-2150 routers. Although authe…
- CVE-2023-34276HIGHCVSS 8.0EG 8.02024-05-03
D-Link DIR-2150 SetTriggerPPPoEValidate Username Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-2150 routers. Al…
- CVE-2023-34277HIGHCVSS 8.0EG 8.02024-05-03
D-Link DIR-2150 SetSysEmailSettings AccountName Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-2150 routers. Alt…
- CVE-2023-34278HIGHCVSS 8.0EG 8.02024-05-03
D-Link DIR-2150 SetSysEmailSettings EmailFrom Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-2150 routers. Altho…
- CVE-2023-34279HIGHCVSS 8.8EG 8.82024-05-03
D-Link DIR-2150 GetDeviceSettings Target Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-2150 routers. Authentica…
- CVE-2023-34280HIGHCVSS 8.0EG 8.02024-05-03
D-Link DIR-2150 SetSysEmailSettings EmailTo Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-2150 routers. Althoug…
- CVE-2023-34281HIGHCVSS 8.0EG 8.02024-05-03
D-Link DIR-2150 GetFirmwareStatus Target Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-2150 routers. Although a…
- CVE-2023-34334HIGHCVSS 7.2EG 7.22023-06-12
AMI BMC contains a vulnerability in the SPX REST API, where an attacker with the required privileges can inject arbitrary shell commands, which may lead to code execution, denial of service, information disclosure, or data tampering. …
- CVE-2023-34343HIGHCVSS 7.2EG 7.22023-06-12
AMI BMC contains a vulnerability in the SPX REST API, where an attacker with the required privileges can inject arbitrary shell commands, which may lead to code execution, denial of service, information disclosure, or data tampering.
- CVE-2023-34356HIGHCVSS 7.2EG 7.22023-10-11
An OS command injection vulnerability exists in the data.cgi xfer_dns functionality of peplink Surf SOHO HW1 v6.3.5 (in QEMU). A specially crafted HTTP request can lead to command execution. An attacker can make an authenticated HTTP reque…
- CVE-2023-34420HIGHCVSS 7.2EG 7.22023-06-26
A valid, authenticated LXCA user with elevated privileges may be able to execute command injections through crafted calls to a specific web API.
- CVE-2023-3450MEDIUMCVSS 4.7EG 6.32023-06-28
A vulnerability was found in Ruijie RG-BCR860 2.5.13 and classified as critical. This issue affects some unknown processing of the component Network Diagnostic Page. The manipulation leads to os command injection. The attack may be initiat…
- CVE-2023-3454HIGHCVSS 8.6EG 8.62024-04-04
Remote code execution (RCE) vulnerability in Brocade Fabric OS after v9.0 and before v9.2.0 could allow an attacker to execute arbitrary code and use this to gain root access to the Brocade switch.
- CVE-2023-34642HIGHCVSS 7.8EG 7.82023-06-19
KioWare for Windows through v8.33 was discovered to contain an incomplete blacklist filter for blocked dialog boxes on Windows 10. This issue can allow attackers to open a file dialog box via the function showDirectoryPicker() which can th…
- CVE-2023-34800CRITICALCVSS 9.8EG 9.82023-06-15
D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at genacgi_main.
- CVE-2023-34873HIGHCVSS 8.7EG 8.72025-05-23
On MOBOTIX P3 cameras before MX-V4.7.2.18 and Mx6 cameras before MX-V5.2.0.61, the tcpdump feature does not properly validate input, which allows authenticated users to execute code.
- CVE-2023-34974HIGHCVSS 8.8EG 8.82024-09-06
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow users to execute commands via a network. QuTScloud, QVR, QES are not affected. We have a…
- CVE-2023-34975HIGHCVSS 6.6EG 7.42023-10-13
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. QuTScloud is not affected…
- CVE-2023-34979MEDIUMCVSS 6.6EG 6.62024-09-06
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed th…
- CVE-2023-34980MEDIUMCVSS 5.9EG 5.92024-03-08
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed th…
- CVE-2023-34985HIGHCVSS 8.8EG 8.82023-10-10
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically…
- CVE-2023-34986HIGHCVSS 8.8EG 8.82023-10-10
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically…
- CVE-2023-34987HIGHCVSS 8.8EG 8.82023-10-10
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically…
- CVE-2023-34988HIGHCVSS 8.8EG 8.82023-10-10
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically…
- CVE-2023-34989HIGHCVSS 8.8EG 8.82023-10-10
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specifically…
Map vulnerabilities like CWE-78 to your infrastructure
EchelonGraph correlates every CVE — across CWE-78 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →