CWE-78
High likelihoodImproper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
6,220 vulnerabilities with CWE-78
CVE-2026-8985
CRITICAL
Autel MaxiCharger Single < V1.03.51 - Command Injection
CVE-2026-64881
HIGH
Tenable, Inc. Security Center < 6.8.0 - Command Injection
CVSS 8.8
CVE-2026-30631
CRITICAL
bytebot-ai - OS Command Injection via computer_write_file Path Parameter
CVSS 9.8
CVE-2026-64879
CRITICAL
Tenable, Inc. Security Center < 6.8.0 - Command Injection
CVSS 9.9
CVE-2026-64878
CRITICAL
Tenable, Inc. Security Center < 6.8.0 - Remote Code Execution
CVSS 9.9
CVE-2026-16445
HIGH
Dracut: dracut: root code execution via dhcp options command injection in networkmanager initrd module
CVSS 7.5
CVE-2026-6952
HIGH
Zyxel AX7501-B1 Firmware - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS 7.2
CVE-2026-64625
CRITICAL
AVideo before 29.0 OS Command Injection via execAsync
CVSS 9.8
CVE-2026-63766
CRITICAL
GPT-SoVITS 20250606v2pro OS Command Injection via webui.py
CVSS 9.8
CVE-2026-54051
CRITICAL
Network-AI has an an OS Command Injection issue
CVSS 9.9
CVE-2026-40187
HIGH
Authenticated RCE via Malicious eTemplate Upload in EGroupware
CVE-2026-14448
HIGH
MB connect line mbCONNECT24 - Authenticated RCE in system_certificates View
CVSS 7.2
CVE-2026-50289
HIGH
systeminformation: OS command injection in networkInterfaces() via interfaces(5) source-directive path on Linux
CVSS 8.8
CVE-2026-46420
MEDIUM
setup-php: Command Injection in Repository-Derived PHP Version Resolution
CVSS 5.6
CVE-2026-42168
CRITICAL
django-pyas2 <= 1.2.3 - Authenticated OS Command Injection via cmd_receive and cmd_send Partner Model Fields
CVSS 9.1
CVE-2026-15069
MEDIUM
IBM Engineering AI Hub 1.0.0-1.2.0 - Arbitrary Script Execution
CVSS 5.4
CVE-2026-14499
HIGH
IBM Langflow OSS 1.0.0-1.10.1 - Python Interpreter Command Injection
CVSS 8.8
CVE-2026-58195
HIGH
Agentic-Flow: OS Command Injection in agentic-flow MCP server tools via unsanitized tool-parameter interpolation into execSync
CVSS 8.8
CVE-2026-55173
HIGH
AVideo < 29.0 - Command Injection
CVSS 8.1
CVE-2026-47751
MEDIUM
Claude Code Action: Malicious MCP Server Configuration in PRs Enables Remote Code Execution and Secret Exfiltration
CVE-2026-14371
HIGH
Lenovo XClarity Integrator For Microsoft Windows Admin Center - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2026-45695
CRITICAL
Kopia: Unauthenticated RCE via SSH ProxyCommand Injection when --insecure --without-password is used
CVSS 9.8
CVE-2026-63305
HIGH
AVideo through 29.0 OS Command Injection via ffmpeg.json.php
CVSS 8.1
CVE-2026-63304
HIGH
AVideo through 29.0 OS Command Injection via listFFmpegProcesses
CVSS 8.1
CVE-2026-55576
HIGH
MaaAssistantArknights: PR-title expression injection in release-preparation.yml
Details
Vulnerabilities
6,220
Exploit Likelihood
High