CWE-78

High likelihood

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Parent: CWE-77 - Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

6,220 vulnerabilities with CWE-78
CVE-2026-8985 CRITICAL
Autel MaxiCharger Single < V1.03.51 - Command Injection
CVE-2026-64881 HIGH
Tenable, Inc. Security Center < 6.8.0 - Command Injection
CVSS 8.8
CVE-2026-30631 CRITICAL
bytebot-ai - OS Command Injection via computer_write_file Path Parameter
CVSS 9.8
CVE-2026-64879 CRITICAL
Tenable, Inc. Security Center < 6.8.0 - Command Injection
CVSS 9.9
CVE-2026-64878 CRITICAL
Tenable, Inc. Security Center < 6.8.0 - Remote Code Execution
CVSS 9.9
CVE-2026-16445 HIGH
Dracut: dracut: root code execution via dhcp options command injection in networkmanager initrd module
CVSS 7.5
CVE-2026-6952 HIGH
Zyxel AX7501-B1 Firmware - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS 7.2
CVE-2026-64625 CRITICAL
AVideo before 29.0 OS Command Injection via execAsync
CVSS 9.8
CVE-2026-63766 CRITICAL
GPT-SoVITS 20250606v2pro OS Command Injection via webui.py
CVSS 9.8
CVE-2026-54051 CRITICAL
Network-AI has an an OS Command Injection issue
CVSS 9.9
CVE-2026-40187 HIGH
Authenticated RCE via Malicious eTemplate Upload in EGroupware
CVE-2026-14448 HIGH
MB connect line mbCONNECT24 - Authenticated RCE in system_certificates View
CVSS 7.2
CVE-2026-50289 HIGH
systeminformation: OS command injection in networkInterfaces() via interfaces(5) source-directive path on Linux
CVSS 8.8
CVE-2026-46420 MEDIUM
setup-php: Command Injection in Repository-Derived PHP Version Resolution
CVSS 5.6
CVE-2026-42168 CRITICAL
django-pyas2 <= 1.2.3 - Authenticated OS Command Injection via cmd_receive and cmd_send Partner Model Fields
CVSS 9.1
CVE-2026-15069 MEDIUM
IBM Engineering AI Hub 1.0.0-1.2.0 - Arbitrary Script Execution
CVSS 5.4
CVE-2026-14499 HIGH
IBM Langflow OSS 1.0.0-1.10.1 - Python Interpreter Command Injection
CVSS 8.8
CVE-2026-58195 HIGH
Agentic-Flow: OS Command Injection in agentic-flow MCP server tools via unsanitized tool-parameter interpolation into execSync
CVSS 8.8
CVE-2026-55173 HIGH
AVideo < 29.0 - Command Injection
CVSS 8.1
CVE-2026-47751 MEDIUM
Claude Code Action: Malicious MCP Server Configuration in PRs Enables Remote Code Execution and Secret Exfiltration
CVE-2026-14371 HIGH
Lenovo XClarity Integrator For Microsoft Windows Admin Center - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2026-45695 CRITICAL
Kopia: Unauthenticated RCE via SSH ProxyCommand Injection when --insecure --without-password is used
CVSS 9.8
CVE-2026-63305 HIGH
AVideo through 29.0 OS Command Injection via ffmpeg.json.php
CVSS 8.1
CVE-2026-63304 HIGH
AVideo through 29.0 OS Command Injection via listFFmpegProcesses
CVSS 8.1
CVE-2026-55576 HIGH
MaaAssistantArknights: PR-title expression injection in release-preparation.yml
Details
Vulnerabilities 6,220
Exploit Likelihood High