CWE-78

High likelihood

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Parent: CWE-77 - Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

6,220 vulnerabilities with CWE-78
CVE-2026-52891 CRITICAL
Wekan: Shell Injection via Avatar Upload
CVSS 9.9
CVE-2026-62312 HIGH
9Router: Authenticated RCE via Unvalidated MCP Plugin Arguments
CVSS 8.8
CVE-2026-55410 MEDIUM
NocoBase backup restore schema name allows command injection
CVSS 6.7
CVE-2026-46339 CRITICAL
9Router: Unauthenticated Remote Code Execution via unprotected MCP custom plugin routes
CVSS 10.0
CVE-2026-15895 HIGH
OS command injection in jsii-diff in AWS jsii
CVSS 7.8
CVE-2026-46709 HIGH
Tabby < 1.0.234 - Drag-and-Drop Path Command Injection
CVSS 7.8
CVE-2026-61438 HIGH
PraisonAI before 4.6.78 Remote Code Execution via Broken AST Sandbox
CVSS 7.3
CVE-2026-48347 HIGH
Animate | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
CVSS 7.7
CVE-2026-48345 HIGH
Animate | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
CVSS 8.2
CVE-2026-15428 HIGH
OS Command Injection in TR-069 (CWMP) Management Interface in TP-Link Archer VX1800v
CVE-2026-15427 HIGH
OS Command Injection in TR-069 (CWMP) Management Interface in TP-Link Archer VX1800v
CVE-2026-58479 CRITICAL
Sustainable Irrigation Platform 5.2.16 RCE via cli_control Plugin Command Injection
CVSS 9.8
CVE-2026-62392 CRITICAL
Apache Kylin: OS Command Injection via Async Query API
CVSS 9.8
CVE-2026-3014 CRITICAL
Remote Code Execution by administrative user on the Management Server
CVSS 9.1
CVE-2026-14852 MEDIUM
mk_sap_hana: Privilege escalation via crafted sapstartsrv process name
CVE-2026-15669 MEDIUM
louisho5 picobot exec Tool exec.go ExecTool.Execute os command injection
CVSS 5.3
CVE-2026-61498 CRITICAL
Vitec Flamingo 4.12.2 Unauthenticated OS Command Injection via gen_graphs.php
CVSS 9.8
CVE-2026-60121 CRITICAL
Vitec Flamingo 4.12.2 Unauthenticated OS Command Injection via ping.php
CVSS 9.8
CVE-2026-22100 HIGH
EVbee DC-80 - Comnand Injection in OCPP ReserveLogin Message
CVE-2026-15547 MEDIUM
Shibby Tomato CIFS Mount sub_2D048 os command injection
CVSS 6.3
CVE-2026-15546 MEDIUM
Shibby Tomato start_jffs2 sub_2D568 os command injection
CVSS 6.3
CVE-2026-15513 MEDIUM
Wavlink WL-NU516U1 adm.cgi wlink_uci_set_value os command injection
CVSS 6.3
CVE-2026-15511 CRITICAL
Comfast CF-WR631AX V3 FastCGI Backend webmgnt system_wl_upload_pic_file os command injection
CVSS 9.8
CVE-2026-15496 MEDIUM
SonicCloudOrg sonic-agent Groovy Script GroovyScriptImpl.java evalIsFailed os command injection
CVSS 6.3
CVE-2026-15495 MEDIUM
SonicCloudOrg sonic-agent Android WebSocket Server AndroidWSServer.java os command injection
CVSS 6.3
Details
Vulnerabilities 6,220
Exploit Likelihood High