CWE-78
High likelihoodImproper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
6,220 vulnerabilities with CWE-78
CVE-2026-52891
CRITICAL
Wekan: Shell Injection via Avatar Upload
CVSS 9.9
CVE-2026-62312
HIGH
9Router: Authenticated RCE via Unvalidated MCP Plugin Arguments
CVSS 8.8
CVE-2026-55410
MEDIUM
NocoBase backup restore schema name allows command injection
CVSS 6.7
CVE-2026-46339
CRITICAL
9Router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes
CVSS 10.0
CVE-2026-15895
HIGH
OS command injection in jsii-diff in AWS jsii
CVSS 7.8
CVE-2026-46709
HIGH
Tabby < 1.0.234 - Drag-and-Drop Path Command Injection
CVSS 7.8
CVE-2026-61438
HIGH
PraisonAI before 4.6.78 Remote Code Execution via Broken AST Sandbox
CVSS 7.3
CVE-2026-48347
HIGH
Animate | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
CVSS 7.7
CVE-2026-48345
HIGH
Animate | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
CVSS 8.2
CVE-2026-15428
HIGH
OS Command Injection in TR-069 (CWMP) Management Interface in TP-Link Archer VX1800v
CVE-2026-15427
HIGH
OS Command Injection in TR-069 (CWMP) Management Interface in TP-Link Archer VX1800v
CVE-2026-58479
CRITICAL
Sustainable Irrigation Platform 5.2.16 RCE via cli_control Plugin Command Injection
CVSS 9.8
CVE-2026-62392
CRITICAL
Apache Kylin: OS Command Injection via Async Query API
CVSS 9.8
CVE-2026-3014
CRITICAL
Remote Code Execution by administrative user on the Management Server
CVSS 9.1
CVE-2026-14852
MEDIUM
mk_sap_hana: Privilege escalation via crafted sapstartsrv process name
CVE-2026-15669
MEDIUM
louisho5 picobot exec Tool exec.go ExecTool.Execute os command injection
CVSS 5.3
CVE-2026-61498
CRITICAL
Vitec Flamingo 4.12.2 Unauthenticated OS Command Injection via gen_graphs.php
CVSS 9.8
CVE-2026-60121
CRITICAL
Vitec Flamingo 4.12.2 Unauthenticated OS Command Injection via ping.php
CVSS 9.8
CVE-2026-22100
HIGH
EVbee DC-80 - Comnand Injection in OCPP ReserveLogin Message
CVE-2026-15547
MEDIUM
Shibby Tomato CIFS Mount sub_2D048 os command injection
CVSS 6.3
CVE-2026-15546
MEDIUM
Shibby Tomato start_jffs2 sub_2D568 os command injection
CVSS 6.3
CVE-2026-15513
MEDIUM
Wavlink WL-NU516U1 adm.cgi wlink_uci_set_value os command injection
CVSS 6.3
CVE-2026-15511
CRITICAL
Comfast CF-WR631AX V3 FastCGI Backend webmgnt system_wl_upload_pic_file os command injection
CVSS 9.8
CVE-2026-15496
MEDIUM
SonicCloudOrg sonic-agent Groovy Script GroovyScriptImpl.java evalIsFailed os command injection
CVSS 6.3
CVE-2026-15495
MEDIUM
SonicCloudOrg sonic-agent Android WebSocket Server AndroidWSServer.java os command injection
CVSS 6.3
Details
Vulnerabilities
6,220
Exploit Likelihood
High