CWE-78

High likelihood

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Parent: CWE-77 - Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

6,224 vulnerabilities with CWE-78
CVE-2026-9343 MEDIUM
Edimax EW-7438RPn webs formWpsStart os command injection
CVSS 6.3
CVE-2026-9277 HIGH
shell-quote `quote()` does not validate object-token shapes, allowing command injection via line terminators in `.op`
CVSS 8.1
CVE-2026-45255 HIGH
Remote code execution via installer Wi-Fi access point scans
CVSS 7.5
CVE-2026-44076 MEDIUM
Netatalk 3.1.0-4.4.2 - Authenticated OS Command Injection via Volume Path
CVSS 6.7
CVE-2026-44072 LOW
Netatalk 2.2.1-4.4.2 and >=4.5.0 - OS Command Injection via Improper chdir Error Handling
CVSS 3.0
CVE-2026-44055 HIGH
Netatalk 3.1.4-4.4.2 - Authenticated OS Command Injection via Bitwise OR Logic Error
CVSS 7.5
CVE-2026-8632 HIGH
HP Linux Imaging and Printing Software – Potential Escalation of Privilege and Arbitrary Code Execution
CVSS 7.8
CVE-2026-20206 MEDIUM
Cisco ThousandEyes BrowserBot Command Injection Vulnerability
CVSS 6.3
CVE-2026-34234 CRITICAL
CtrlPanel: Unauthenticated RCE using installer script
CVSS 10.0
CVE-2026-8603 CRITICAL
Improper neutralization of special elements used in an OS command ('OS command injection') in ScadaBR
CVSS 9.8
CVE-2026-36828 HIGH
Panabit PAP-XM320 <= v7.7 - Authenticated OS Command Injection via runcmd Parameter
CVSS 8.8
CVE-2026-36827 MEDIUM
Panabit PAP-XM320 <= V7.7 - Authenticated Command Injection via /usr/sbin/pappiw Helper
CVSS 5.4
CVE-2026-37281 CRITICAL
Zenshin < 2.7.0 - OS Command Injection via /stream-to-vlc URL Parameter
CVSS 9.8
CVE-2026-27130 CRITICAL
Dokploy has Command Injection in its Service Operations
CVSS 9.9
CVE-2026-25244 CRITICAL
WebdriverIO has Command Injection in the BrowserStack Service
CVSS 9.8
CVE-2026-8767 MEDIUM
vercel ai PR Branch Name Interpolation prettier-on-automerge.yml run os command injection
CVSS 5.0
CVE-2026-45036 HIGH
Tabby auto-confirms ZMODEM detection on terminal output, leading to shell command execution from displayed file content under fish, bash, and zsh
CVSS 7.0
CVE-2026-45035 HIGH
Tabby: RCE via `tabby://run` URL Scheme
CVSS 8.8
CVE-2026-46483 LOW
Vim: Command injection in tar#Vimuntar via missing shellescape {special} flag
CVSS 3.6
CVE-2026-41553 CRITICAL
Remote Code Execution in PDF Export Module
CVSS 10.0
CVE-2026-8654 HIGH
Delphix Continuous Data Ibm Db2 Connector - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2026-45369 HIGH
python-utcp: Command Injection via Unsanitized Argument Substitution in CLI Communication Protocol
CVSS 8.3
CVE-2026-44666 CRITICAL
HRConvert2: Missing Sanitization enables Unauthenticated Remote Command Execution
CVE-2026-26191 CRITICAL
Fleet vulnerable to OS command injection in software packages
CVSS 9.8
CVE-2026-41315 CRITICAL
mdserver-web: Missing Authorization and Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS 9.8
Details
Vulnerabilities 6,224
Exploit Likelihood High