CWE-78 · 5,951 records
OS command injection
Why does it happen?
User input is inserted as text into a shell command. The shell may interpret special characters in the input as part of the command.
Vulnerable and fixed code
A representative teaching example. Highlighted lines mark where the bug and the fix are.
Vulnerable
const host = req.body.host;exec("ping -c 1 " + host, onResult);Fixed
const host = req.body.host;if (!/^[a-z0-9.-]{1,253}$/i.test(host)) return res.sendStatus(400);execFile("ping", ["-c", "1", host], onResult);How to prevent it
- 01Instead of running through a shell, use APIs that take arguments as an array.
- 02Validate input against an allowlist (for example, hostname format only).
- 03Where possible, use a library function instead of an OS command.
CVEs in this class
5,960 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
100Now | CVE-2026-10520Weaponized | An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated userivanti · standalone sentry · CWE-78 | Critical10.0 | KEV | 99.9% | Jun 9, 2026 |
99Now | CVE-2021-1498Weaponized | Cisco HyperFlex HX Command Injection Vulnerabilitiescisco · hyperflex hx data platform · CWE-78 | Critical9.8 | KEV | 100.0% | May 6, 2021 |
99Now | CVE-2014-6271Weaponized | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attacgnu · bash · CWE-78 | Critical9.8 | KEV | 100.0% | Sep 24, 2014 |
99Now | CVE-2019-16920Weaponized | Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565.dlink · dir-655 firmware · CWE-78 | Critical9.8 | KEV | 100.0% | Sep 27, 2019 |
99Now | CVE-2022-44877Weaponized | login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commacontrol-webpanel · webpanel · CWE-78 | Critical9.8 | KEV | 100.0% | Jan 5, 2023 |
99Now | CVE-2020-8515Weaponized | DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow remote code executidraytek · vigor2960 firmware · CWE-78 | Critical9.8 | KEV | 100.0% | Feb 1, 2020 |
99Now | CVE-2020-9054Weaponized | ZyXEL NAS products running firmware version 5.21 and earlier are vulnerable to pre-authentication command injection in weblogin.cgizyxel · nas326 firmware · CWE-78 | Critical9.8 | KEV | 100.0% | Mar 4, 2020 |
99Now | CVE-2024-4577Weaponized | Argument Injection in PHP-CGIphp · php · CWE-78 | Critical9.8 | KEV | 100.0% | Jun 9, 2024 |
99Now | CVE-2020-25506Weaponized | D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead to remote arbitrary dlink · dns-320 firmware · CWE-78 | Critical9.8 | KEV | 100.0% | Feb 2, 2021 |
99Now | CVE-2019-10149Weaponized | A flaw was found in Exim versions 4.87 to 4.91 (inclusive).exim · exim · CWE-78 | Critical9.8 | KEV | 100.0% | Jun 5, 2019 |
99Now | CVE-2018-10562Weaponized | An issue was discovered on Dasan GPON home routers.dasannetworks · gpon router firmware · CWE-78 | Critical9.8 | KEV | 99.9% | May 3, 2018 |
99Now | CVE-2022-30525Weaponized | A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 fzyxel · usg flex 100w firmware · CWE-78 | Critical9.8 | KEV | 99.9% | May 12, 2022 |
99Now | CVE-2014-7169Weaponized | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variablgnu · bash · CWE-78 | Critical9.8 | KEV | 99.9% | Sep 24, 2014 |
99Now | CVE-2021-1497Weaponized | Cisco HyperFlex HX Command Injection Vulnerabilitiescisco · hyperflex hx data platform · CWE-78 | Critical9.8 | KEV | 99.9% | May 6, 2021 |
99Now | CVE-2024-45519Weaponized | The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.synacor · zimbra collaboration suite · CWE-78 | Critical9.8 | KEV | 99.9% | Oct 2, 2024 |
99Now | CVE-2021-36260Weaponized | A command injection vulnerability in the web server of some Hikvision product.hikvision · ds-2cd2026g2-iu\/sl firmware · CWE-78 | Critical9.8 | KEV | 99.9% | Sep 22, 2021 |
99Now | CVE-2021-35394Weaponized | Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as 'UDPServer' binary.realtek · rtl819x jungle software development kit · CWE-78 | Critical9.8 | KEV | 99.9% | Aug 16, 2021 |
99Now | CVE-2019-15107Weaponized | An issue was discovered in Webmin <=1.920.webmin · webmin · CWE-78 | Critical9.8 | KEV | 99.7% | Aug 15, 2019 |
99Now | CVE-2020-16846Weaponized | An issue was discovered in SaltStack Salt through 3002.saltstack · salt · CWE-78 | Critical9.8 | KEV | 99.6% | Nov 6, 2020 |
99Now | CVE-2023-28771Weaponized | Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.zyxel · atp100 firmware · CWE-78 | Critical9.8 | KEV | 99.3% | Apr 24, 2023 |
99Now | CVE-2020-7247Weaponized | smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary coopenbsd · opensmtpd · CWE-78 | Critical9.8 | KEV | 99.0% | Jan 29, 2020 |
99Now | CVE-2024-9463Weaponized | Expedition: Unauthenticated OS Command Injection Vulnerability Leads to Firewall Credential Disclosurepaloaltonetworks · expedition · CWE-78 | Critical9.9 | KEV | 98.5% | Oct 9, 2024 |
99Now | CVE-2024-50603Weaponized | An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996.aviatrix · controller · CWE-78 | Critical9.8 | KEV | 98.5% | Jan 7, 2025 |
98Now | CVE-2022-29303Weaponized | SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php.contec · sv-cpt-mc310 firmware · CWE-78 | Critical9.8 | KEV | 98.0% | May 12, 2022 |
98Now | CVE-2023-25280Weaponized | OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload with tdlink · dir-820l firmware · CWE-78 | Critical9.8 | KEV | 97.9% | Mar 15, 2023 |
- CVE-2026-10520100Now
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user
CriticalCVSS 10.0KEVWeaponizedEPSS 100%ivanti · standalone sentryJun 9, 2026
- CVE-2021-149899Now
Cisco HyperFlex HX Command Injection Vulnerabilities
CriticalCVSS 9.8KEVWeaponizedEPSS 100%cisco · hyperflex hx data platformMay 6, 2021
- CVE-2014-627199Now
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac
CriticalCVSS 9.8KEVWeaponizedEPSS 100%gnu · bashSep 24, 2014
- CVE-2019-1692099Now
Unauthenticated remote code execution occurs in D-Link products such as DIR-655C, DIR-866L, DIR-652, and DHP-1565.
CriticalCVSS 9.8KEVWeaponizedEPSS 100%dlink · dir-655 firmwareSep 27, 2019
- CVE-2022-4487799Now
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS comma
CriticalCVSS 9.8KEVWeaponizedEPSS 100%control-webpanel · webpanelJan 5, 2023
- CVE-2020-851599Now
DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow remote code executi
CriticalCVSS 9.8KEVWeaponizedEPSS 100%draytek · vigor2960 firmwareFeb 1, 2020
- CVE-2020-905499Now
ZyXEL NAS products running firmware version 5.21 and earlier are vulnerable to pre-authentication command injection in weblogin.cgi
CriticalCVSS 9.8KEVWeaponizedEPSS 100%zyxel · nas326 firmwareMar 4, 2020
- CVE-2024-457799Now
Argument Injection in PHP-CGI
CriticalCVSS 9.8KEVWeaponizedEPSS 100%php · phpJun 9, 2024
- CVE-2020-2550699Now
D-Link DNS-320 FW v2.06B01 Revision Ax is affected by command injection in the system_mgr.cgi component, which can lead to remote arbitrary
CriticalCVSS 9.8KEVWeaponizedEPSS 100%dlink · dns-320 firmwareFeb 2, 2021
- CVE-2019-1014999Now
A flaw was found in Exim versions 4.87 to 4.91 (inclusive).
CriticalCVSS 9.8KEVWeaponizedEPSS 100%exim · eximJun 5, 2019
- CVE-2018-1056299Now
An issue was discovered on Dasan GPON home routers.
CriticalCVSS 9.8KEVWeaponizedEPSS 100%dasannetworks · gpon router firmwareMay 3, 2018
- CVE-2022-3052599Now
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 f
CriticalCVSS 9.8KEVWeaponizedEPSS 100%zyxel · usg flex 100w firmwareMay 12, 2022
- CVE-2014-716999Now
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl
CriticalCVSS 9.8KEVWeaponizedEPSS 100%gnu · bashSep 24, 2014
- CVE-2021-149799Now
Cisco HyperFlex HX Command Injection Vulnerabilities
CriticalCVSS 9.8KEVWeaponizedEPSS 100%cisco · hyperflex hx data platformMay 6, 2021
- CVE-2024-4551999Now
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9, and 10.1 before 10.
CriticalCVSS 9.8KEVWeaponizedEPSS 100%synacor · zimbra collaboration suiteOct 2, 2024
- CVE-2021-3626099Now
A command injection vulnerability in the web server of some Hikvision product.
CriticalCVSS 9.8KEVWeaponizedEPSS 100%hikvision · ds-2cd2026g2-iu\/sl firmwareSep 22, 2021
- CVE-2021-3539499Now
Realtek Jungle SDK version v2.x up to v3.4.14B provides a diagnostic tool called 'MP Daemon' that is usually compiled as 'UDPServer' binary.
CriticalCVSS 9.8KEVWeaponizedEPSS 100%realtek · rtl819x jungle software development kitAug 16, 2021
- CVE-2019-1510799Now
An issue was discovered in Webmin <=1.920.
CriticalCVSS 9.8KEVWeaponizedEPSS 100%webmin · webminAug 15, 2019
- CVE-2020-1684699Now
An issue was discovered in SaltStack Salt through 3002.
CriticalCVSS 9.8KEVWeaponizedEPSS 100%saltstack · saltNov 6, 2020
- CVE-2023-2877199Now
Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware versions 4.60 through 5.
CriticalCVSS 9.8KEVWeaponizedEPSS 99%zyxel · atp100 firmwareApr 24, 2023
- CVE-2020-724799Now
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary co
CriticalCVSS 9.8KEVWeaponizedEPSS 99%openbsd · opensmtpdJan 29, 2020
- CVE-2024-946399Now
Expedition: Unauthenticated OS Command Injection Vulnerability Leads to Firewall Credential Disclosure
CriticalCVSS 9.9KEVWeaponizedEPSS 99%paloaltonetworks · expeditionOct 9, 2024
- CVE-2024-5060399Now
An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996.
CriticalCVSS 9.8KEVWeaponizedEPSS 99%aviatrix · controllerJan 7, 2025
- CVE-2022-2930398Now
SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php.
CriticalCVSS 9.8KEVWeaponizedEPSS 98%contec · sv-cpt-mc310 firmwareMay 12, 2022
- CVE-2023-2528098Now
OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload with t
CriticalCVSS 9.8KEVWeaponizedEPSS 98%dlink · dir-820l firmwareMar 15, 2023