CWE-78
High likelihoodImproper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
6,223 vulnerabilities with CWE-78
CVE-2026-54636
CRITICAL
Dokku: OS Command Injection via app.json managed Cron
CVSS 9.0
CVE-2026-45408
CRITICAL
Dokku: OS Command Injection via App Name in Git Pre-Receive Hook
CVSS 9.0
CVE-2026-40711
HIGH
Dell Container Storage Modules - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS 8.0
CVE-2026-54088
CRITICAL
File Browser < 2.63.6 - Pre-Authentication Remote Code Execution
CVE-2026-46606
HIGH
Glances: Command Injection via KVM/QEMU VM Domain Names in glances/plugins/vms/engines/virsh.py
CVSS 7.8
CVE-2026-55697
HIGH
pnpm: Repository-controlled configDependencies can select a pacquet native install engine
CVSS 7.5
CVE-2026-9717
HIGH
Schneider Electric PowerLogic™ P7 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS 7.2
CVE-2026-55895
HIGH
Vim: Vimscript Code Injection in netrw NetrwLocalRmFile() via crafted filename
CVSS 7.8
CVE-2026-46735
HIGH
Dell Display And Peripheral Manager - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS 7.8
CVE-2026-8658
MEDIUM
OS Command Injection in Rapid7 InsightConnect Tcpdump Plugin
CVSS 6.0
CVE-2026-8666
HIGH
OS Command Injection in Rapid7 InsightConnect Traceroute Plugin
CVSS 7.7
CVE-2026-8665
HIGH
OS Command Injection in Rapid7 InsightConnect Translate Plugin
CVSS 7.7
CVE-2026-8664
MEDIUM
OS Command Injection in Rapid7 InsightConnect Finger Plugin
CVSS 6.0
CVE-2026-8660
HIGH
OS Command Injection in Rapid7 InsightConnect Ping Plugin
CVSS 7.7
CVE-2026-8592
HIGH
OS Command Injection in Rapid7 InsightConnect AWK Plugin
CVSS 7.7
CVE-2026-9155
HIGH
OS Command Injection in Rapid7 InsightConnect Sed Plugin via expression parameter.
CVSS 8.8
CVE-2026-9787
HIGH
Quest NetVault Backup NVBULogDaemon Command Injection Remote Code Execution Vulnerability
CVSS 8.8
CVE-2026-8663
MEDIUM
OS Command Injection in Rapid7 InsightConnect RPM Plugin
CVSS 6.0
CVE-2026-8659
MEDIUM
OS Command Injection in Rapid7 InsightConnect SQLmap Plugin
CVSS 6.0
CVE-2026-40079
CRITICAL
Cacti: Command Injection via escape_command() no-op in RRDtool execution
CVSS 9.8
CVE-2026-39938
CRITICAL
Cacti: Unauthenticated RCE on Graph Image
CVSS 9.8
CVE-2026-9773
HIGH
Unraid Web Server ToggleState Command Injection Remote Code Execution Vulnerability
CVSS 8.8
CVE-2026-9772
HIGH
Unraid Web Server FileUpload Command Injection Remote Code Execution Vulnerability
CVSS 8.8
CVE-2026-49980
CRITICAL
Rclone 1.46.0 to < 1.74.3 - Unauthenticated Command Execution via rc-serve
CVSS 9.8
CVE-2026-54699
HIGH
Warp: OS command injection when opening terminal links from WSL
CVSS 7.7
Details
Vulnerabilities
6,223
Exploit Likelihood
High