CWE-78

High likelihood

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Parent: CWE-77 - Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

6,224 vulnerabilities with CWE-78
CVE-2026-10727 HIGH
Ivanti Endpoint Manager Mobile - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS 7.2
CVE-2026-10520 CRITICAL KEV
Ivanti Sentry - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS 10.0
CVE-2026-9279 HIGH
Shell command injection in Logseq
CVE-2026-46746 HIGH
Siemens Sinec Ins < V1.0 SP2 Update 6 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS 8.8
CVE-2026-11572 HIGH
Degit - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS 8.8
CVE-2026-40519 HIGH
Nginx Proxy Manager Authenticated RCE via setupCertbotPlugins()
CVSS 7.5
CVE-2026-10544 MEDIUM
Devolutions Server - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS 6.5
CVE-2026-8913 HIGH
Command Injection in TP-Link's Archer MR600 WireGuard Client Configuration
CVE-2026-11556 HIGH
Tenda F451 Web Management WriteFacMac formWriteFacMac os command injection
CVSS 8.8
CVE-2026-25855 HIGH
OpenBullet2 0.3.2 Authenticated RCE via FileProxySource Script Upload
CVSS 8.8
CVE-2026-11408 MEDIUM
vertex-app vertex Log Viewer Endpoint LogMod.js os command injection
CVSS 6.3
CVE-2026-45777 CRITICAL
Open XDMoD Vulnerable to Unauthenticated Remote Code Execution (RCE) via OS Command Injection
CVSS 9.8
CVE-2026-25623 MEDIUM
Arista Edge Threat Management NGFW UI Arbitrary Command Execution
CVSS 6.0
CVE-2026-25622 MEDIUM
Arista Edge Threat Management NGFW Captive Portal Custom Handler Command Injection
CVSS 6.0
CVE-2026-25621 MEDIUM
Arista Edge Threat Management NGFW Reports Application Insecure Input Validation
CVSS 6.0
CVE-2026-25620 MEDIUM
Arista Edge Threat Management NGFW Captive Portal Encrypted Password Command Injection
CVSS 6.0
CVE-2026-46399 CRITICAL
haxtheweb haxcms-nodejs - Authenticated Remote Code Execution via File Overwrite
CVE-2026-46394 HIGH
Haxtheweb Haxcms-php < 26.0.0 - Remote Code Execution
CVE-2026-49492 HIGH
Markdown Preview Enhanced OS Command Injection in External File and Link Opening
CVSS 8.8
CVE-2026-45750 CRITICAL
Termix Vulnerable to Arbitrary Command Execution in File Manager
CVSS 9.0
CVE-2026-45748 CRITICAL
Termix Vulnerable to Remote Code Execution via SSH Tunnel Forward Command Injection
CVSS 9.8
CVE-2026-45744 CRITICAL
Termix <2.3.2 File Manager resolvePath - OS Command Injection
CVSS 9.9
CVE-2026-11341 MEDIUM
D-Link DWR-M920 formIMEISetup sub_412DA0 os command injection
CVSS 6.3
CVE-2026-21837 HIGH
HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API
CVSS 8.8
CVE-2026-10873 HIGH
Shibby Tomato Web UI rstats rstats_path os command injection
CVSS 7.2
Details
Vulnerabilities 6,224
Exploit Likelihood High