CWE-78
High likelihoodImproper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
6,224 vulnerabilities with CWE-78
CVE-2026-9343
MEDIUM
Edimax EW-7438RPn webs formWpsStart os command injection
CVSS 6.3
CVE-2026-9277
HIGH
shell-quote `quote()` does not validate object-token shapes, allowing command injection via line terminators in `.op`
CVSS 8.1
CVE-2026-45255
HIGH
Remote code execution via installer Wi-Fi access point scans
CVSS 7.5
CVE-2026-44076
MEDIUM
Netatalk 3.1.0-4.4.2 - Authenticated OS Command Injection via Volume Path
CVSS 6.7
CVE-2026-44072
LOW
Netatalk 2.2.1-4.4.2 and >=4.5.0 - OS Command Injection via Improper chdir Error Handling
CVSS 3.0
CVE-2026-44055
HIGH
Netatalk 3.1.4-4.4.2 - Authenticated OS Command Injection via Bitwise OR Logic Error
CVSS 7.5
CVE-2026-8632
HIGH
HP Linux Imaging and Printing Software – Potential Escalation of Privilege and Arbitrary Code Execution
CVSS 7.8
CVE-2026-20206
MEDIUM
Cisco ThousandEyes BrowserBot Command Injection Vulnerability
CVSS 6.3
CVE-2026-34234
CRITICAL
CtrlPanel: Unauthenticated RCE using installer script
CVSS 10.0
CVE-2026-8603
CRITICAL
Improper neutralization of special elements used in an OS command ('OS command injection') in ScadaBR
CVSS 9.8
CVE-2026-36828
HIGH
Panabit PAP-XM320 <= v7.7 - Authenticated OS Command Injection via runcmd Parameter
CVSS 8.8
CVE-2026-36827
MEDIUM
Panabit PAP-XM320 <= V7.7 - Authenticated Command Injection via /usr/sbin/pappiw Helper
CVSS 5.4
CVE-2026-37281
CRITICAL
Zenshin < 2.7.0 - OS Command Injection via /stream-to-vlc URL Parameter
CVSS 9.8
CVE-2026-27130
CRITICAL
Dokploy has Command Injection in its Service Operations
CVSS 9.9
CVE-2026-25244
CRITICAL
WebdriverIO has Command Injection in the BrowserStack Service
CVSS 9.8
CVE-2026-8767
MEDIUM
vercel ai PR Branch Name Interpolation prettier-on-automerge.yml run os command injection
CVSS 5.0
CVE-2026-45036
HIGH
Tabby auto-confirms ZMODEM detection on terminal output, leading to shell command execution from displayed file content under fish, bash, and zsh
CVSS 7.0
CVE-2026-45035
HIGH
Tabby: RCE via `tabby://run` URL Scheme
CVSS 8.8
CVE-2026-46483
LOW
Vim: Command injection in tar#Vimuntar via missing shellescape {special} flag
CVSS 3.6
CVE-2026-41553
CRITICAL
Remote Code Execution in PDF Export Module
CVSS 10.0
CVE-2026-8654
HIGH
Delphix Continuous Data Ibm Db2 Connector - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2026-45369
HIGH
python-utcp: Command Injection via Unsanitized Argument Substitution in CLI Communication Protocol
CVSS 8.3
CVE-2026-44666
CRITICAL
HRConvert2: Missing Sanitization enables Unauthenticated Remote Command Execution
CVE-2026-26191
CRITICAL
Fleet vulnerable to OS command injection in software packages
CVSS 9.8
CVE-2026-41315
CRITICAL
mdserver-web: Missing Authorization and Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS 9.8
Details
Vulnerabilities
6,224
Exploit Likelihood
High