CWE-78

High likelihood

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Parent: CWE-77 - Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

6,220 vulnerabilities with CWE-78
CVE-2026-59686 HIGH
Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Management Interface
CVSS 8.4
CVE-2026-17497 HIGH
NoteGen arbitrary OS command execution via Tauri shell:allow-execute for bash/python
CVSS 8.3
CVE-2026-16766 CRITICAL
Catalyst::View::Wkhtmltopdf < 0.6.1 - Shell Command Injection
CVSS 9.8
CVE-2026-65711 HIGH
sysPass 3.2.11 Authenticated OS Command Injection via Backup Path
CVSS 7.2
CVE-2026-66138 HIGH
Openstack Ironic Python Agent - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS 7.2
CVE-2026-63732 CRITICAL
9router before 0.4.60 Remote Code Execution via default password
CVSS 9.9
CVE-2026-16763 MEDIUM
localstack serverless-localstack Configuration index.js os command injection
CVSS 5.3
CVE-2026-47670 CRITICAL
DbGate Vulnerable to Authenticated Remote Code Execution via loadReader functionName code injection
CVE-2026-6516 CRITICAL
Zohocorp ManageEngine ADAudit Plus < 8606 - Remote Code Execution
CVSS 10.0
CVE-2026-16735 MEDIUM
release-it conventional-changelog Changelog File index.js writeChangelog os command injection
CVSS 5.3
CVE-2026-16733 MEDIUM
bahmutov find-cypress-specs Branch index.js shell.exec os command injection
CVSS 5.3
CVE-2026-16287 HIGH
Root Command Injection via Offline Update in TÜBİTAK BİLGEM's pardus-update
CVSS 7.8
CVE-2026-16631 MEDIUM
publint package-manager pack.js child_process.exec os command injection
CVSS 5.3
CVE-2026-16630 MEDIUM
syncfusion ej2-javascript-ui-controls package.json child_process.exec os command injection
CVSS 5.3
CVE-2026-16629 MEDIUM
danger danger-js CLI localGetFileAtSHA.ts danger.git.diffForFile os command injection
CVSS 5.3
CVE-2026-16628 MEDIUM
oclif JIT Plugin Entry child_process.exec os command injection
CVSS 5.3
CVE-2026-14881 HIGH
MongoDB Compass < 1.49.7 - OIDC Browser Command Injection
CVSS 7.8
CVE-2026-44191 HIGH
Ansible-lightspeed: visual studio code ansible lightspeed extension: remote code execution via command injection in configuration settings
CVSS 7.8
CVE-2026-65590 CRITICAL
n8n before 2.30.1 Shell Sandbox Bypass on Linux Windows
CVSS 9.8
CVE-2026-44190 HIGH
Ansible-lightspeed: ansible lightspeed visual studio code extension: arbitrary code execution via command injection in activation script setting
CVSS 7.8
CVE-2026-3821 HIGH
Supermicro SMASH service contain an Arbitrary code execution issue
CVSS 8.8
CVE-2026-16492 MEDIUM
umijs umi GIT File Helper getFileGitIno.ts git.getFileCreateInfo os command injection
CVSS 5.5
CVE-2026-16489 MEDIUM
jsforce SFDX Connection Registry sfdx.js _execCommand os command injection
CVSS 5.3
CVE-2026-16488 MEDIUM
QUSETIONS MiniCode-Python Project File config.py subprocess.Popen os command injection
CVSS 5.0
CVE-2026-8986 CRITICAL
Autel MaxiCharger Single - Command Injection via Malicious OCPP Server
Details
Vulnerabilities 6,220
Exploit Likelihood High