CWE-78— OS Command Injection
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.— MITRE CWE catalog
6,261 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-78page 101 of 126
- CVE-2025-59534HIGHCVSS 7.3EG 7.32025-09-23
CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to…
- CVE-2025-5965HIGHCVSS 7.2EG 7.22026-01-05
In the backup parameters, a user with high privilege is able to concatenate custom instructions to the backup setup. Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Centreon Infra…
- CVE-2025-59735CRITICALCVSS 9.8EG 9.82025-10-02
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system commands on the server by sending a POST request. The relationship between parameter and assigned…
- CVE-2025-59736CRITICALCVSS 9.8EG 9.82025-10-02
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system commands on the server by sending a POST request. The relationship between parameter and assigned…
- CVE-2025-59737CRITICALCVSS 9.8EG 9.82025-10-02
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system commands on the server by sending a POST request. The relationship between parameter and assigned…
- CVE-2025-59738CRITICALCVSS 9.8EG 9.82025-10-02
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system commands on the server by sending a POST request. The relationship between parameter and assigned…
- CVE-2025-59739CRITICALCVSS 9.8EG 9.82025-10-02
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system commands on the server by sending a POST request. The relationship between parameter and assigned…
- CVE-2025-59740CRITICALCVSS 9.8EG 9.82025-10-02
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system commands on the server by sending a POST request. The relationship between parameter and assigned…
- CVE-2025-59741CRITICALCVSS 9.8EG 9.82025-10-02
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to execute operating system commands on the server by sending a POST request. The relationship between parameter and assigned…
- CVE-2025-59783HIGHCVSS 7.2EG 7.22026-03-04
API endpoint for user synchronization in 2N Access Commander version 3.4.1 did not have a sufficient input validation allowing for OS command injection. This vulnerability can only be exploited after authenticating with administrator priv…
- CVE-2025-59831HIGHCVSS 8.8EG 8.82025-09-25
git-commiters is a Node.js function module providing committers stats for their git repository. Prior to version 0.1.2, there is a command injection vulnerability in git-commiters. This vulnerability manifests with the library's primary ex…
- CVE-2025-59834CRITICALCVSS 9.8EG 9.82025-09-25
ADB MCP Server is a MCP (Model Context Protocol) server for interacting with Android devices through ADB. In versions 0.1.0 and prior, the MCP Server is written in a way that is vulnerable to command injection vulnerability attacks as part…
- CVE-2025-59844HIGHCVSS 7.7EG 7.72025-09-26
SonarQube Server and Cloud is a static analysis solution for continuous code quality and security inspection. A command injection vulnerability exists in SonarQube GitHub Action in version 4.0.0 to before version 6.0.0 when workflows pass …
- CVE-2025-60006MEDIUMCVSS 5.3EG 5.32025-10-09
Multiple instances of an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the CLI of Juniper Networks Junos OS Evolved could be used to elevate privileges and/or execute unauthor…
- CVE-2025-60013MEDIUMCVSS 4.6EG 5.72025-10-15
When a highly-privileged, authenticated attacker attempts to initialize the rSeries FIPS module using a password with special shell metacharacters, arbitrary system commands may be executed, and the FIPS hardware security module (HSM) may …
- CVE-2025-60017HIGHCVSS 8.2EG 8.22025-09-26
Unitree Go2, G1, H1, and B2 devices through 2025-09-20 allow root OS command injection via the hostapd_restart.sh wifi_ssid or wifi_pass parameter (within restart_wifi_ap and restart_wifi_sta).
- CVE-2025-60738CRITICALCVSS 9.8EG 9.82025-11-20
An issue in Ilevia EVE X1 Server Firmware Version v4.7.18.0.eden and before Logic Version v6.00 - 2025_07_21 and before allows a remote attacker to execute arbitrary code via the ping.php component does not perform secure filtering on IP p…
- CVE-2025-60787HIGHCVSS 7.2EG 7.22025-10-03
MotionEye v0.43.1b4 and before is vulnerable to OS Command Injection in configuration parameters such as image_file_name. Unsanitized user input is written to Motion configuration files, allowing remote authenticated attackers with admin a…
- CVE-2025-60803CRITICALCVSS 9.8EG 9.82025-10-24
Antabot White-Jotter up to commit 9bcadc was discovered to contain an unauthenticated remote code execution (RCE) vulnerability via the component /api/aaa;/../register.
- CVE-2025-60957CRITICALCVSS 9.9EG 9.92025-10-06
OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute arbitrary code, cause a denial of service, gain escalated privileges, and gain sensitive …
- CVE-2025-60959HIGHCVSS 8.2EG 8.22025-10-06
OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to gain sensitive information.
- CVE-2025-60960HIGHCVSS 8.2EG 8.22025-10-06
OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute arbitrary code, cause a denial of service, gain escalated privileges, and gain sensitive …
- CVE-2025-60962HIGHCVSS 8.2EG 8.22025-10-06
OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to gain sensitive information, and possibly other unspecified impacts.
- CVE-2025-60963HIGHCVSS 8.2EG 8.22025-10-06
OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute arbitrary code, cause a denial of service, gain escalated privileges, and gain sensitive …
- CVE-2025-60964CRITICALCVSS 9.1EG 9.12025-10-06
OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute arbitrary code, cause a denial of service, gain escalated privileges, gain sensitive info…
- CVE-2025-60965CRITICALCVSS 9.1EG 9.12025-10-06
OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers to execute arbitrary code, cause a denial of service, gain escalated privileges, gain sensitive info…
- CVE-2025-6102HIGHCVSS 8.8EG 8.82025-06-16
A vulnerability classified as critical was found in Wifi-soft UniBox Controller up to 20250506. Affected by this vulnerability is an unknown functionality of the file /authentication/logout.php. The manipulation of the argument mac_address…
- CVE-2025-6103HIGHCVSS 8.8EG 8.82025-06-16
A vulnerability, which was classified as critical, has been found in Wifi-soft UniBox Controller up to 20250506. Affected by this issue is some unknown functionality of the file /billing/test_accesscodelogin.php. The manipulation of the ar…
- CVE-2025-6104HIGHCVSS 8.8EG 8.82025-06-16
A vulnerability, which was classified as critical, was found in Wifi-soft UniBox Controller up to 20250506. This affects an unknown part of the file /billing/pms_check.php. The manipulation of the argument ipaddress leads to os command inj…
- CVE-2025-61045CRITICALCVSS 9.8EG 9.82025-10-01
TOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability via the mac parameter in the setEasyMeshAgentCfg function.
- CVE-2025-61304CRITICALCVSS 9.8EG 9.82025-11-05
OS command injection vulnerability in Dynatrace ActiveGate ping extension up to 1.016 via crafted ip address.
- CVE-2025-61591HIGHCVSS 8.8EG 8.82025-10-03
Cursor is a code editor built for programming with AI. In versions 1.7 and below, when MCP uses OAuth authentication with an untrusted MCP server, an attacker can impersonate a malicious MCP server and return crafted, maliciously injected …
- CVE-2025-6181HIGHCVSS 8.5EG 8.52025-08-20
The StrongDM Windows service incorrectly handled input validation. Authenticated attackers could potentially exploit this leading to privilege escalation.
- CVE-2025-6183HIGHCVSS 7.0EG 7.02025-08-20
The StrongDM macOS client incorrectly processed JSON-formatted messages. Attackers could potentially modify macOS system configuration by crafting a malicious JSON message.
- CVE-2025-6193MEDIUMCVSS 5.9EG 5.92025-06-20
A command injection vulnerability was discovered in the TrustyAI Explainability toolkit. Arbitrary commands placed in certain fields of a LMEValJob custom resource (CR) may be executed in the LMEvalJob pod's terminal. This issue can be exp…
- CVE-2025-62193CRITICALCVSS 9.8EG 9.82026-01-15
Sites running NOAA PMEL Live Access Server (LAS) are vulnerable to remote code execution via specially crafted requests that include PyFerret expressions. By leveraging a SPAWN command, a remote, unauthenticated attacker can execute arbitr…
- CVE-2025-6225MEDIUMCVSS 6.9EG 6.92026-01-07
Kieback&Peter Neutrino-GLT product is used for building management. It's web component "SM70 PHWEB" is vulnerable to shell command injection via login form. The injected commands would execute with low privileges. The vulnerability has be…
- CVE-2025-62354CRITICALCVSS 9.8EG 9.82025-11-26
Improper neutralization of special elements used in an OS command ('command injection') in Cursor allows an unauthorized attacker to execute commands that are outside of those specified in the allowlist, resulting in arbitrary code executi…
- CVE-2025-62703HIGHCVSS 8.8EG 8.82025-11-25
Fugue is a unified interface for distributed computing that lets users execute Python, Pandas, and SQL code on Spark, Dask, and Ray with minimal rewrites. In version 0.9.2 and prior, there is a remote code execution vulnerability by pickle…
- CVE-2025-62713HIGHCVSS 7.2EG 7.22025-10-23
Kottster is a self hosted Node.js admin panel. From versions 3.2.0 to before 3.3.2, Kottster contains a pre-authentication remote code execution (RCE) vulnerability when running in development mode. This affects development mode only, prod…
- CVE-2025-62801HIGHCVSS 7.8EG 7.82025-10-28
FastMCP is the standard framework for building MCP applications. Versions prior to 2.13.0, a command-injection vulnerability lets any attacker who can influence the server_name field of an MCP execute arbitrary OS commands on Windows hosts…
- CVE-2025-6299MEDIUMCVSS 4.7EG 4.72025-06-20
A vulnerability classified as critical has been found in TOTOLINK N150RT 3.4.0-B20190525. This affects an unknown part of the file /boa/formWSC. The manipulation of the argument targetAPSsid leads to os command injection. It is possible to…
- CVE-2025-63261HIGHCVSS 7.8EG 7.82026-03-20
AWStats 8.0 is vulnerable to Command Injection via the open function
- CVE-2025-63334CRITICALCVSS 9.8EG 9.82025-11-05
PocketVJ CP PocketVJ-CP-v3 pvj version 3.9.1 contains an unauthenticated remote code execution vulnerability in the submit_opacity.php component. The application fails to sanitize user input in the opacityValue POST parameter before passin…
- CVE-2025-63408HIGHCVSS 7.8EG 7.82025-11-18
Local Agent DVR versions thru 6.6.1.0 are vulnerable to directory traversal that allows an unauthenticated local attacker to gain access to sensitive information, cause a server-side forgery request (SSRF), or execute OS commands.
- CVE-2025-63414CRITICALCVSS 10.0EG 10.02025-12-16
A Path Traversal vulnerability in the Allsky WebUI version v2024.12.06_06 allows an unauthenticated remote attacker to achieve arbitrary command execution. By sending a crafted HTTP request to the /html/execute.php endpoint with a maliciou…
- CVE-2025-63705HIGHCVSS 8.8EG 8.82026-05-07
NPM package node-ts-ocr 1.0.15 is vulnerable to OS Command Injection via the invokeImageOcr function in src/index.js.
- CVE-2025-63911HIGHCVSS 7.2EG 7.22026-03-03
Cohesity TranZman Migration Appliance Release 4.0 Build 14614 was discovered to contain an authenticated command injection vulnerability.
- CVE-2025-63916HIGHCVSS 8.1EG 8.12025-11-17
MyScreenTools v2.2.1.0 contains a critical OS command injection vulnerability in the GIF compression tool. The application fails to properly sanitize user-supplied file paths before passing them to cmd.exe, allowing attackers to execute ar…
- CVE-2025-63932HIGHCVSS 7.3EG 7.32025-11-19
D-Link Router DIR-868L A1 FW106KRb01.bin has an unauthenticated remote code execution vulnerability in the cgibin binary. The HNAP service provided by cgibin does not filter the HTTP SOAPAction header field. The unauthenticated remote atta…
Map vulnerabilities like CWE-78 to your infrastructure
EchelonGraph correlates every CVE — across CWE-78 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →