CWE-78

High likelihood

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Parent: CWE-77 - Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

6,223 vulnerabilities with CWE-78
CVE-2026-55748 MEDIUM
Openstack Horizon - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS 6.0
CVE-2026-55743 CRITICAL
OpenHuman desktop agent shell tool sandbox bypass leads to arbitrary command execution
CVSS 9.6
CVE-2026-53876 HIGH
RadiX AX6600 WiFi 6 Tri-Band Gaming Router - Authenticated OS Command Injection
CVSS 7.2
CVE-2026-11410 HIGH
OS Command Injection in BigPond Cable (BPA) Configuration in TP-Link TL-WR940N
CVSS 7.2
CVE-2026-11409 HIGH
OS Command Injection in IPv6 PPPoE Configuration in TP-Link TL-WR940N
CVSS 7.2
CVE-2026-22313 CRITICAL
OS Commands Executed with Administrative Permissions in Radiflow iSAP Smart Collector
CVSS 9.1
CVE-2026-44932 HIGH
indirect remote shell command injection via unsanitized DHCP options in wicked
CVSS 8.8
CVE-2026-12398 HIGH
Galaxy_ng: shell injection in legacy role import via unsanitized git ref names
CVSS 7.5
CVE-2026-5416 HIGH
TURCK TBEN-LL-SE-M2 - Command Injection via Name Parameter
CVSS 8.8
CVE-2026-12161 HIGH
Devolutions Remote Desktop Manager < 2026.2.7 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS 8.8
CVE-2026-48723 HIGH
BrowserStack Cypress CL: Command Injection via cypress_config_file leads to arbitrary code execution through malicious browserstack.json
CVSS 7.8
CVE-2026-50874 HIGH
kanishka-linux Reminiscence 0.3.0 - OS Command Injection via Media Feature
CVSS 8.1
CVE-2026-38065 CRITICAL
Tenda 5G03 V05.03.02.04 - OS Command Injection via ims_apn Parameter
CVSS 9.8
CVE-2026-38064 CRITICAL
Tenda 5G03 V05.03.02.04 - OS Command Injection via dialNumber Parameter
CVSS 9.8
CVE-2026-38063 CRITICAL
Tenda 5G03 V05.03.02.04 - OS Command Injection via ia Parameter
CVSS 9.8
CVE-2026-38062 CRITICAL
Tenda 5G03 V05.03.02.04 - OS Command Injection via ratMode Parameter
CVSS 9.8
CVE-2026-38061 CRITICAL
Tenda 5G03 V05.03.02.04 - OS Command Injection via Volume Parameter
CVSS 9.8
CVE-2026-38060 CRITICAL
Tenda 5G03 V05.03.02.04 - OS Command Injection via action_unlock_sim pin Parameter
CVSS 9.8
CVE-2026-9863 HIGH
Core Privileged Access Manager (BoKS) upgrade tooling command injection vulnerability
CVSS 7.5
CVE-2026-9862 CRITICAL
Core Privileged Access Manager (BoKS) autoregistration service command injection vulnerability
CVSS 9.8
CVE-2026-11527 HIGH
Perl Config::IniFiles < 3.001000 - OS Command Injection via -file 2-Arg open()
CVSS 8.6
CVE-2026-11526 CRITICAL
Perl GD < 2.86 - OS Command Injection via 2-Arg open()
CVSS 9.8
CVE-2026-46716 CRITICAL
Nezha Monitoring: RoleMember can run shell on every server (cross-tenant RCE) via POST /api/v1/cron
CVSS 9.9
CVE-2026-42853 MEDIUM
@apostrophecms/cli: Command Injection in apos create via Unsanitized Password Input
CVSS 6.5
CVE-2026-48165 HIGH
MariaDB: unsafe usage of `wsrep_sst_receive_address` values on the joiner side
CVSS 8.0
Details
Vulnerabilities 6,223
Exploit Likelihood High