CWE-78
High likelihoodImproper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
6,220 vulnerabilities with CWE-78
CVE-2026-49815
HIGH
Dell PowerProtect Data Domain - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS 7.2
CVE-2026-49814
HIGH
Dell PowerProtect Data Domain - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS 7.2
CVE-2026-49813
MEDIUM
Dell PowerProtect Data Domain - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS 6.7
CVE-2026-54483
MEDIUM
Dell PowerProtect Data Domain - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS 6.7
CVE-2026-26355
MEDIUM
Dell PowerProtect Data Domain - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS 6.5
CVE-2026-58455
CRITICAL
Dockwatch 0.6.567 Unauthenticated OS Command Injection via ajax/compose.php
CVSS 9.8
CVE-2026-56004
CRITICAL
openSUSE obs-service-tar_scm < 0.12.4 - Command Injection via Mercurial Handler
CVSS 10.0
CVE-2026-58652
HIGH
luci-app-travelmate - Arbitrary Command Execution via UCI Script Parameter
CVSS 7.5
CVE-2026-58457
CRITICAL
Shenzhen Aitemi M300 MT02 Unauthenticated OS Command Injection via protocol.csp
CVSS 9.8
CVE-2026-13760
HIGH
AWS CDK < 2.260.0 - OS Command Injection in Docker Bundling
CVSS 7.3
CVE-2026-58452
HIGH
JAIOTlink C492A-W6 4.8.30.57701411 OS Command Injection via SetMAC Endpoint
CVSS 8.8
CVE-2026-34117
CRITICAL
Guardian Language-System Unauthenticated OS Command Injection via id Parameter in text_to_subtitles.php
CVSS 9.8
CVE-2026-34116
CRITICAL
Guardian Language-System Unauthenticated OS Command Injection via id Parameter in transcribe.php
CVSS 9.8
CVE-2026-34115
CRITICAL
Guardian Language-System Unauthenticated OS Command Injection via id Parameter in transcribe_amazon.php
CVSS 9.8
CVE-2026-34114
CRITICAL
Guardian Language-System Unauthenticated OS Command Injection via id Parameter in translate_text.php
CVSS 9.8
CVE-2026-34113
CRITICAL
Guardian Language-System Unauthenticated OS Command Injection via id Parameter in speech_text.php
CVSS 9.8
CVE-2026-34112
CRITICAL
Guardian Language-System Unauthenticated OS Command Injection via id Parameter in speechmac.php
CVSS 9.8
CVE-2026-34111
CRITICAL
Guardian Language-System Unauthenticated OS Command Injection via id Parameter in speechmac_text.php
CVSS 9.8
CVE-2026-34110
CRITICAL
Guardian Language-System Unauthenticated OS Command Injection via id Parameter in complex_start.php
CVSS 9.8
CVE-2026-34109
CRITICAL
Guardian Language-System Unauthenticated OS Command Injection via id Parameter in speech.php
CVSS 9.8
CVE-2026-34108
CRITICAL
Guardian Language-System Unauthenticated OS Command Injection via id Parameter in text.php
CVSS 9.8
CVE-2026-34107
CRITICAL
Guardian Language-System Unauthenticated OS Command Injection via id Parameter in translate.php
CVSS 9.8
CVE-2026-34106
CRITICAL
Guardian Language-System Unauthenticated OS Command Injection via id Parameter in subtitles.php
CVSS 9.8
CVE-2026-50043
HIGH
Seiko Solutions Inc. SkyBridge MB-A100/MB-A110 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS 7.2
CVE-2026-56700
CRITICAL
Grav - Multiple Remote Code Execution Vulnerabilities via Unsafe Unserialize and Command Injection
CVSS 9.8
Details
Vulnerabilities
6,220
Exploit Likelihood
High