CWE-78
High likelihoodImproper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
6,220 vulnerabilities with CWE-78
CVE-2026-59686
HIGH
Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager, and MOVEit WAF OS Command Injection via Management Interface
CVSS 8.4
CVE-2026-17497
HIGH
NoteGen arbitrary OS command execution via Tauri shell:allow-execute for bash/python
CVSS 8.3
CVE-2026-16766
CRITICAL
Catalyst::View::Wkhtmltopdf < 0.6.1 - Shell Command Injection
CVSS 9.8
CVE-2026-65711
HIGH
sysPass 3.2.11 Authenticated OS Command Injection via Backup Path
CVSS 7.2
CVE-2026-66138
HIGH
Openstack Ironic Python Agent - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS 7.2
CVE-2026-63732
CRITICAL
9router before 0.4.60 Remote Code Execution via default password
CVSS 9.9
CVE-2026-16763
MEDIUM
localstack serverless-localstack Configuration index.js os command injection
CVSS 5.3
CVE-2026-47670
CRITICAL
DbGate Vulnerable to Authenticated Remote Code Execution via loadReader functionName code injection
CVE-2026-6516
CRITICAL
Zohocorp ManageEngine ADAudit Plus < 8606 - Remote Code Execution
CVSS 10.0
CVE-2026-16735
MEDIUM
release-it conventional-changelog Changelog File index.js writeChangelog os command injection
CVSS 5.3
CVE-2026-16733
MEDIUM
bahmutov find-cypress-specs Branch index.js shell.exec os command injection
CVSS 5.3
CVE-2026-16287
HIGH
Root Command Injection via Offline Update in TÜBİTAK BİLGEM's pardus-update
CVSS 7.8
CVE-2026-16631
MEDIUM
publint package-manager pack.js child_process.exec os command injection
CVSS 5.3
CVE-2026-16630
MEDIUM
syncfusion ej2-javascript-ui-controls package.json child_process.exec os command injection
CVSS 5.3
CVE-2026-16629
MEDIUM
danger danger-js CLI localGetFileAtSHA.ts danger.git.diffForFile os command injection
CVSS 5.3
CVE-2026-16628
MEDIUM
oclif JIT Plugin Entry child_process.exec os command injection
CVSS 5.3
CVE-2026-14881
HIGH
MongoDB Compass < 1.49.7 - OIDC Browser Command Injection
CVSS 7.8
CVE-2026-44191
HIGH
Ansible-lightspeed: visual studio code ansible lightspeed extension: remote code execution via command injection in configuration settings
CVSS 7.8
CVE-2026-65590
CRITICAL
n8n before 2.30.1 Shell Sandbox Bypass on Linux Windows
CVSS 9.8
CVE-2026-44190
HIGH
Ansible-lightspeed: ansible lightspeed visual studio code extension: arbitrary code execution via command injection in activation script setting
CVSS 7.8
CVE-2026-3821
HIGH
Supermicro SMASH service contain an Arbitrary code execution issue
CVSS 8.8
CVE-2026-16492
MEDIUM
umijs umi GIT File Helper getFileGitIno.ts git.getFileCreateInfo os command injection
CVSS 5.5
CVE-2026-16489
MEDIUM
jsforce SFDX Connection Registry sfdx.js _execCommand os command injection
CVSS 5.3
CVE-2026-16488
MEDIUM
QUSETIONS MiniCode-Python Project File config.py subprocess.Popen os command injection
CVSS 5.0
CVE-2026-8986
CRITICAL
Autel MaxiCharger Single - Command Injection via Malicious OCPP Server
Details
Vulnerabilities
6,220
Exploit Likelihood
High