CWE-78— OS Command Injection
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.— MITRE CWE catalog
6,257 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-78page 75 of 126
- CVE-2024-11681MEDIUMCVSS 6.8EG 6.82025-01-07
A malicious or compromised MacPorts mirror can execute arbitrary commands as root on the machine of a client running port selfupdate against the mirror.
- CVE-2024-1180HIGHCVSS 8.0EG 8.02024-04-03
TP-Link Omada ER605 Access Control Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Omada ER605. Authentication is re…
- CVE-2024-11858HIGHCVSS 8.6EG 8.62024-12-15
A flaw was found in Radare2, which contains a command injection vulnerability caused by insufficient input validation when handling Pebble Application files. Maliciously crafted inputs can inject shell commands during command parsing, lead…
- CVE-2024-11983HIGHCVSS 7.2EG 7.22024-11-29
Certain models of routers from Billion Electric has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject arbitrary system commands into a specific SSH function and execute them on the dev…
- CVE-2024-12009HIGHCVSS 7.2EG 7.22025-03-11
A post-authentication command injection vulnerability in the "ZyEE" function of the Zyxel EX5601-T1 firmware version V5.70(ACDZ.3.6)C0 and earlier could allow an authenticated attacker with administrator privileges to execute operating sys…
- CVE-2024-12010HIGHCVSS 7.2EG 7.22025-03-11
A post-authentication command injection vulnerability in the ”zyUtilMailSend” function of the Zyxel AX7501-B1 firmware version V5.17(ABPC.5.3)C0 and earlier could allow an authenticated attacker with administrator privileges to execu…
- CVE-2024-1212CRITICALCVSS 9.8EG 10.0⚠ KEV2024-02-21
Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.
- CVE-2024-12358MEDIUMCVSS 6.3EG 6.32024-12-09
A vulnerability was found in WeiYe-Jing datax-web 2.1.1. It has been classified as critical. This affects an unknown part of the file /api/job/add/. The manipulation of the argument glueSource leads to os command injection. It is possible …
- CVE-2024-12686CRITICALCVSS 6.6EG 9.0⚠ KEV2024-12-18
A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacker with existing administrative privileges to inject commands and run as a site user.
- CVE-2024-12828CRITICALCVSS 8.8EG 9.92024-12-30
Webmin CGI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Webmin. Authentication is required to exploit this vulnerability. The spe…
- CVE-2024-12829HIGHCVSS 8.8EG 8.82024-12-20
Arista NG Firewall ExecManagerImpl Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Arista NG Firewall. Authentication is required to e…
- CVE-2024-12847CRITICALCVSS 9.8EG 9.82025-01-10
NETGEAR DGN1000 before 1.1.00.48 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated attacker can execute arbitrary operating system commands as root by sending crafted HTTP requests to the setup.cgi endpo…
- CVE-2024-12856HIGHCVSS 7.2EG 8.92024-12-27
The Four-Faith router models F3x24 and F3x36 are affected by an operating system (OS) command injection vulnerability. At least firmware version 2.0 allows authenticated and remote attackers to execute arbitrary OS commands over HTTP when …
- CVE-2024-1297CRITICALCVSS 7.2EG 10.02024-02-20
Loomio version 2.22.0 allows executing arbitrary commands on the server. This is possible because the application is vulnerable to OS Command Injection.
- CVE-2024-12970LOWCVSS 3.9EG 3.92025-01-06
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TUBITAK BILGEM Pardus OS My Computer allows OS Command Injection. This issue affects Pardus OS My Computer: before 0.7.2.
- CVE-2024-12985MEDIUMCVSS 6.3EG 6.32024-12-27
A vulnerability classified as critical was found in Overtek OT-E801G OTE801G65.1.1.0. This vulnerability affects unknown code of the file /diag_ping.cmd?action=test&interface=ppp0.1&ipaddr=8.8.8.8%26%26cat%20/etc/passwd&ipversion=4&session…
- CVE-2024-12986HIGHCVSS 7.3EG 7.42024-12-27
A vulnerability, which was classified as critical, has been found in DrayTek Vigor2960 and Vigor300B 1.5.1.3/1.5.1.4. This issue affects some unknown processing of the file /cgi-bin/mainfunction.cgi/apmcfgupptim of the component Web Manage…
- CVE-2024-12987CRITICALCVSS 7.3EG 9.0⚠ KEV2024-12-27
A vulnerability, which was classified as critical, was found in DrayTek Vigor2960 and Vigor300B 1.5.1.4. Affected is an unknown function of the file /cgi-bin/mainfunction.cgi/apmcfgupload of the component Web Management Interface. The mani…
- CVE-2024-13087MEDIUMCVSS 6.7EG 6.72025-06-06
A command injection vulnerability has been reported to affect QHora. If an attacker gains local network access who have also gained an administrator account, they can then exploit the vulnerability to execute arbitrary commands. We have a…
- CVE-2024-13089HIGHCVSS 7.2EG 7.22025-06-10
An OS command injection vulnerability within the update functionality may allow an authenticated administrator to execute unauthorized arbitrary OS commands. Users with administrative privileges may upload update packages to upgrade the…
- CVE-2024-13129HIGHCVSS 8.8EG 8.82025-01-03
A vulnerability was found in Roxy-WI up to 8.1.3. It has been declared as critical. Affected by this vulnerability is the function action_service of the file app/modules/roxywi/roxy.py. The manipulation of the argument action/service leads…
- CVE-2024-13502CRITICALCVSS 9.3EG 9.32025-01-17
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Newtec/iDirect NTC2218, NTC2250, NTC2299 on Linux, PowerPC, ARM allows Local Code Inclusion.This issue affects NTC2218, NTC2250, NT…
- CVE-2024-1367HIGHCVSS 7.2EG 7.22024-02-14
A command injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the Security Center application could modify Logging parameters, which could lead to the execution of arbitrary code on the …
- CVE-2024-13892HIGHCVSS 7.7EG 7.72025-03-06
Smartwares cameras CIP-37210AT and C724IP, as well as others which share the same firmware in versions up to 3.3.0, are vulnerable to command injection. During the initialization process, a user has to use a mobile app to provide device…
- CVE-2024-13985CRITICALCVSS 10.0EG 10.02025-08-27
A command injection vulnerability in Dahua EIMS versions prior to 2240008 allows unauthenticated remote attackers to execute arbitrary system commands via the capture_handle.action interface. The flaw stems from improper input validation i…
- CVE-2024-14003CRITICALCVSS 9.8EG 9.82025-10-30
Nagios XI versions prior to 2024R1.2 are vulnerable to remote code execution (RCE) through its NRDP (Nagios Remote Data Processor) server plugins. Insufficient validation of inbound NRDP request parameters allows crafted input to reach co…
- CVE-2024-14005HIGHCVSS 8.8EG 8.82025-10-30
Nagios XI versions prior to 2024R1.2 contain a command injection vulnerability in the Docker Wizard. Insufficient validation of user-supplied input in the wizard allows an authenticated administrator to inject shell metacharacters that are…
- CVE-2024-14008HIGHCVSS 7.2EG 7.22025-10-30
Nagios XI versions prior to 2024R1.3.2 contain a remote command execution vulnerability in the WinRM Configuration Wizard. Insufficient validation of user-supplied input allows an authenticated administrator to inject shell metacharacters…
- CVE-2024-14010CRITICALCVSS 9.8EG 9.82025-12-12
Typora 1.7.4 contains a command injection vulnerability in the PDF export preferences that allows attackers to execute arbitrary system commands. Attackers can inject malicious commands into the 'run command' input field during PDF export …
- CVE-2024-14026HIGHCVSS 7.8EG 7.82026-03-11
A command injection vulnerability has been reported to affect several QNAP operating system versions. If an attacker gains local network access who have also gained a user account, they can then exploit the vulnerability to execute arbitra…
- CVE-2024-1520CRITICALCVSS 9.8EG 9.82024-04-10
An OS Command Injection vulnerability exists in the '/open_code_folder' endpoint of the parisneo/lollms-webui application, due to improper validation of user-supplied input in the 'discussion_id' parameter. Attackers can exploit this vulne…
- CVE-2024-1624CRITICALCVSS 9.4EG 9.42024-03-01
An OS Command Injection vulnerability affecting documentation server on 3DEXPERIENCE from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x, SIMULIA Abaqus from Release 2022 through Release 2024, SIMULIA Isight from Release 2…
- CVE-2024-1628HIGHCVSS 8.4EG 8.42024-05-14
OS command injection vulnerabilities in GE HealthCare ultrasound devices
- CVE-2024-1655HIGHCVSS 8.8EG 8.82024-04-15
Certain ASUS WiFi routers models has an OS Command Injection vulnerability, allowing an authenticated remote attacker to execute arbitrary system commands by sending a specially crafted request.
- CVE-2024-1683HIGHCVSS 7.3EG 7.32024-02-23
A DLL injection vulnerability exists where an authenticated, low-privileged local attacker could modify application files on the TIE Secure Relay host, which could allow for overriding of the configuration and running of new Secure Relay …
- CVE-2024-1880HIGHCVSS 7.8EG 7.82024-06-06
An OS command injection vulnerability exists in the MacOS Text-To-Speech class MacOSTTS of the significant-gravitas/autogpt project, affecting versions up to v0.5.0. The vulnerability arises from the improper neutralization of special elem…
- CVE-2024-1881CRITICALCVSS 9.8EG 9.82024-06-06
AutoGPT, a component of significant-gravitas/autogpt, is vulnerable to an improper neutralization of special elements used in an OS command ('OS Command Injection') due to a flaw in its shell command validation function. Specifically, the …
- CVE-2024-20275MEDIUMCVSS 6.1EG 6.12024-10-23
A vulnerability in the cluster backup feature of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to execute arbitrary commands on the unde…
- CVE-2024-20277MEDIUMCVSS 6.8EG 6.82024-01-17
A vulnerability in the web-based management interface of Cisco ThousandEyes Enterprise Agent, Virtual Appliance installation type, could allow an authenticated, remote attacker to perform a command injection and elevate privileges to root.…
- CVE-2024-20289MEDIUMCVSS 4.4EG 4.42024-08-28
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, low-privileged, local attacker to execute arbitrary commands on the underlying operating system of an affected device. This vulnerability is due to i…
- CVE-2024-2029CRITICALCVSS 9.8EG 9.82024-04-10
A command injection vulnerability exists in the `TranscriptEndpoint` of mudler/localai, specifically within the `audioToWav` function used for converting audio files to WAV format for transcription. The vulnerability arises due to the lack…
- CVE-2024-20295HIGHCVSS 8.8EG 8.82024-04-24
A vulnerability in the CLI of the Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit …
- CVE-2024-20326HIGHCVSS 7.8EG 7.82024-05-16
A vulnerability in the ConfD CLI and the Cisco Crosswork Network Services Orchestrator CLI could allow an authenticated, low-privileged, local attacker to read and write arbitrary files as root on the underlying operating system. This v…
- CVE-2024-20328CRITICALCVSS 5.3EG 9.02024-03-01
A vulnerability in the VirusEvent feature of ClamAV could allow a local attacker to inject arbitrary commands with the privileges of the application service account.The vulnerability is due to unsafe handling of file names. A local attacke…
- CVE-2024-20335MEDIUMCVSS 6.5EG 6.52024-03-06
A vulnerability in the web-based management interface of Cisco Small Business 100, 300, and 500 Series Wireless APs could allow an authenticated, remote attacker to perform command injection attacks against an affected device. In order to …
- CVE-2024-20356HIGHCVSS 8.7EG 8.72024-04-24
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker with Administrator-level privileges to perform command injection attacks on an affected sys…
- CVE-2024-20358MEDIUMCVSS 6.0EG 6.02024-04-24
A vulnerability in the Cisco Adaptive Security Appliance (ASA) restore functionality that is available in Cisco ASA Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrar…
- CVE-2024-20398HIGHCVSS 8.8EG 8.82024-09-11
A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to obtain read/write file system access on the underlying operating system of an affected device. This vulnerability is due to insufficient…
- CVE-2024-20399CRITICALCVSS 6.0EG 9.0⚠ KEV2024-07-01
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated user in possession of Administrator credentials to execute arbitrary commands as root on the underlying operating system of an affected device. This vulnera…
- CVE-2024-20424CRITICALCVSS 9.9EG 9.92024-10-23
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software, formerly Firepower Management Center Software, could allow an authenticated, remote attacker to execute arbitrary commands on …
Map vulnerabilities like CWE-78 to your infrastructure
EchelonGraph correlates every CVE — across CWE-78 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →