CWE-78

High likelihood

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Parent: CWE-77 - Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

6,220 vulnerabilities with CWE-78
CVE-2026-49815 HIGH
Dell PowerProtect Data Domain - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS 7.2
CVE-2026-49814 HIGH
Dell PowerProtect Data Domain - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS 7.2
CVE-2026-49813 MEDIUM
Dell PowerProtect Data Domain - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS 6.7
CVE-2026-54483 MEDIUM
Dell PowerProtect Data Domain - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS 6.7
CVE-2026-26355 MEDIUM
Dell PowerProtect Data Domain - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS 6.5
CVE-2026-58455 CRITICAL
Dockwatch 0.6.567 Unauthenticated OS Command Injection via ajax/compose.php
CVSS 9.8
CVE-2026-56004 CRITICAL
openSUSE obs-service-tar_scm < 0.12.4 - Command Injection via Mercurial Handler
CVSS 10.0
CVE-2026-58652 HIGH
luci-app-travelmate - Arbitrary Command Execution via UCI Script Parameter
CVSS 7.5
CVE-2026-58457 CRITICAL
Shenzhen Aitemi M300 MT02 Unauthenticated OS Command Injection via protocol.csp
CVSS 9.8
CVE-2026-13760 HIGH
AWS CDK < 2.260.0 - OS Command Injection in Docker Bundling
CVSS 7.3
CVE-2026-58452 HIGH
JAIOTlink C492A-W6 4.8.30.57701411 OS Command Injection via SetMAC Endpoint
CVSS 8.8
CVE-2026-34117 CRITICAL
Guardian Language-System Unauthenticated OS Command Injection via id Parameter in text_to_subtitles.php
CVSS 9.8
CVE-2026-34116 CRITICAL
Guardian Language-System Unauthenticated OS Command Injection via id Parameter in transcribe.php
CVSS 9.8
CVE-2026-34115 CRITICAL
Guardian Language-System Unauthenticated OS Command Injection via id Parameter in transcribe_amazon.php
CVSS 9.8
CVE-2026-34114 CRITICAL
Guardian Language-System Unauthenticated OS Command Injection via id Parameter in translate_text.php
CVSS 9.8
CVE-2026-34113 CRITICAL
Guardian Language-System Unauthenticated OS Command Injection via id Parameter in speech_text.php
CVSS 9.8
CVE-2026-34112 CRITICAL
Guardian Language-System Unauthenticated OS Command Injection via id Parameter in speechmac.php
CVSS 9.8
CVE-2026-34111 CRITICAL
Guardian Language-System Unauthenticated OS Command Injection via id Parameter in speechmac_text.php
CVSS 9.8
CVE-2026-34110 CRITICAL
Guardian Language-System Unauthenticated OS Command Injection via id Parameter in complex_start.php
CVSS 9.8
CVE-2026-34109 CRITICAL
Guardian Language-System Unauthenticated OS Command Injection via id Parameter in speech.php
CVSS 9.8
CVE-2026-34108 CRITICAL
Guardian Language-System Unauthenticated OS Command Injection via id Parameter in text.php
CVSS 9.8
CVE-2026-34107 CRITICAL
Guardian Language-System Unauthenticated OS Command Injection via id Parameter in translate.php
CVSS 9.8
CVE-2026-34106 CRITICAL
Guardian Language-System Unauthenticated OS Command Injection via id Parameter in subtitles.php
CVSS 9.8
CVE-2026-50043 HIGH
Seiko Solutions Inc. SkyBridge MB-A100/MB-A110 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS 7.2
CVE-2026-56700 CRITICAL
Grav - Multiple Remote Code Execution Vulnerabilities via Unsafe Unserialize and Command Injection
CVSS 9.8
Details
Vulnerabilities 6,220
Exploit Likelihood High