CWE-78

High likelihood

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Parent: CWE-77 - Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

6,224 vulnerabilities with CWE-78
CVE-2026-33208 HIGH
Roxy-WI Vulnerable to Authenticated Remote Code Execution via OS Command Injection in find-in-config Endpoint
CVSS 8.8
CVE-2026-6942 CRITICAL
radare2-mcp <=1.6.0 OS Command Injection via Shell Metacharacter Bypass
CVSS 9.8
CVE-2026-41247 CRITICAL
elFinder: Command injection in resize background color parameter when using ImageMagick CLI
CVSS 9.8
CVE-2026-31181 CRITICAL
ToToLink A3300R v17.0.0cu.557_B20221024 - Command Injection
CVSS 9.8
CVE-2026-31178 CRITICAL
ToToLink A3300R v17.0.0cu.557_B20221024 - Command Injection
CVSS 9.8
CVE-2026-31177 CRITICAL
ToToLink A3300R v17.0.0cu.557_B20221024 - Command Injection
CVSS 9.8
CVE-2026-41208 HIGH
Paperclip: Privilege Escalation via Agent-Controlled workspaceStrategy.provisionCommand Leading to OS Command Execution
CVSS 8.8
CVE-2026-5935 HIGH
IBM TSSC/TS4500 IMC 9.2 to 9.6 - OS Command Injection
CVSS 7.3
CVE-2026-41179 CRITICAL
RClone: Unauthenticated operations/fsinfo allows attacker-controlled backend instantiation and local command execution
CVSS 9.8
CVE-2026-40517 HIGH
radare2 < 6.1.4 Command Injection via PDB Parser Symbol Names
CVSS 7.8
CVE-2026-41064 CRITICAL
AVideo <=29.0 test.php URL Handling - Command Injection
CVSS 9.3
CVE-2026-40933 CRITICAL
Flowise: Authenticated RCE Via MCP Adapters
CVSS 9.9
CVE-2026-21571 CRITICAL
Atlassian Bamboo Data Center < 12.1.0 to 12.1.3 - Remote Code Execution
CVE-2026-31019 HIGH
Dolibarr ERP & CRM <=22.0.4 - Authenticated RCE
CVSS 8.8
CVE-2026-40520 HIGH
FreePBX api module Command Injection via GraphQL
CVSS 7.2
CVE-2026-41036 HIGH
Command Injection Vulnerability in Quantum Networks Router QN-I-470
CVSS 8.8
CVE-2026-5965 CRITICAL
NewSoft|NewSoftOA - OS Command Injection
CVSS 9.8
CVE-2026-32311 CRITICAL
Command Injection and Docker container escape allows root on host machine
CVSS 9.8
CVE-2026-26943 HIGH
Dell PowerProtect Data Domain Authenticated RCE via OS Command Injection
CVSS 7.2
CVE-2026-26942 MEDIUM
Dell PowerProtect Data Domain 8.5-8.6 - Authenticated OS Command Injection
CVSS 6.7
CVE-2026-24506 HIGH
Dell PowerProtect Data Domain 7.7.1.0-8.6, 8.3.1.0-8.3.1.20, 7.13.1.0-7.13.1.60 - Authenticated Remote Code Execution
CVSS 7.2
CVE-2026-22761 MEDIUM
Dell PowerProtect Data Domain 8.5-8.6 - Authenticated OS Command Injection
CVSS 6.7
CVE-2026-23774 HIGH
Dell PowerProtect Data Domain 7.7.1.0-8.5, 8.3.1.0-8.3.1.10, 7.13.1.0-7.13.1.40 - Authenticated Remote Code Execution
CVSS 7.2
CVE-2026-5967 HIGH
TeamT5|ThreatSonar Anti-Ransomware - Privilege Escalation
CVSS 8.8
CVE-2026-6644 CRITICAL
A command injection vulnerability was found in the PPTP VPN Clients on the ADM
CVSS 9.1
Details
Vulnerabilities 6,224
Exploit Likelihood High