CWE-78
High likelihoodImproper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
6,224 vulnerabilities with CWE-78
CVE-2026-31246
MEDIUM
GPT-Pilot thru 0819827 - Command Injection
CVSS 6.5
CVE-2026-4802
HIGH
Cockpit: cockpit: arbitrary command execution via crafted links in system logs ui
CVSS 8.0
CVE-2026-8273
MEDIUM
D-Link DNS-320 system_mgr.cgi cgi_merge_user os command injection
CVSS 4.7
CVE-2026-8272
MEDIUM
D-Link DNS-320 webfile_mgr.cgi chown os command injection
CVSS 4.7
CVE-2026-8271
MEDIUM
D-Link DNS-320 network_mgr.cgi cgi_upnp_edit os command injection
CVSS 4.7
CVE-2026-8265
MEDIUM
Tenda AC6 httpd getLogFile get_log_file os command injection
CVSS 4.7
CVE-2026-8264
MEDIUM
Tenda AC6 httpd WifiApScan formWifiApScan os command injection
CVSS 6.3
CVE-2026-8263
MEDIUM
Tenda AC6 httpd WifiExtraSet fromSetWirelessRepeat os command injection
CVSS 4.7
CVE-2026-8259
MEDIUM
Tenda AC6 httpd telnet os command injection
CVSS 4.7
CVE-2026-8235
MEDIUM
8421bit MiniClaw System kernel.ts resolveSkillScriptPath os command injection
CVSS 5.5
CVE-2026-8230
MEDIUM
Wavlink NU516U1 login.cgi sys_login1 os command injection
CVSS 6.3
CVE-2026-8229
MEDIUM
Wavlink NU516U1 wireless.cgi WifiBasic os command injection
CVSS 6.3
CVE-2026-8228
MEDIUM
Wavlink NU516U1 wireless.cgi advance os command injection
CVSS 6.3
CVE-2026-8227
MEDIUM
Wavlink NU516U1 adm.cgi wzdapMesh os command injection
CVSS 6.3
CVE-2026-8217
MEDIUM
Industrial Application Software IAS Canias ERP RMI Runtime.getRuntime.exec os command injection
CVSS 6.3
CVE-2026-8192
MEDIUM
Wavlink NU516U1 adm.cgi wzdap os command injection
CVSS 6.3
CVE-2026-8191
MEDIUM
Wavlink NU516U1 adm.cgi wifi_region os command injection
CVSS 6.3
CVE-2026-8190
MEDIUM
Wavlink NU516U1 adm.cgi wan os command injection
CVSS 6.3
CVE-2026-8189
MEDIUM
Wavlink NU516U1 adm.cgi wzdrepeater os command injection
CVSS 6.3
CVE-2026-8188
MEDIUM
Wavlink NU516U1 adm.cgi change_wifi_password os command injection
CVSS 6.3
CVE-2026-3828
HIGH
Hikvision DS-3E1310P-SI - Authenticated RCE
CVSS 7.2
CVE-2026-44656
MEDIUM
Vim path Completion - OS Command Injection
CVSS 5.3
CVE-2026-42454
CRITICAL
Termix: OS Command Injection in Docker Container Management Endpoints
CVSS 9.9
CVE-2026-42307
MEDIUM
Vim netrw - OS Command Injection
CVSS 4.4
CVE-2026-41497
CRITICAL
Incomplete fix for CVE-2026-34935: Command Injection in MervinPraison/PraisonAI
CVSS 9.8
Details
Vulnerabilities
6,224
Exploit Likelihood
High