CWE-78

High likelihood

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Parent: CWE-77 - Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

6,223 vulnerabilities with CWE-78
CVE-2026-54636 CRITICAL
Dokku: OS Command Injection via app.json managed Cron
CVSS 9.0
CVE-2026-45408 CRITICAL
Dokku: OS Command Injection via App Name in Git Pre-Receive Hook
CVSS 9.0
CVE-2026-40711 HIGH
Dell Container Storage Modules - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS 8.0
CVE-2026-54088 CRITICAL
File Browser < 2.63.6 - Pre-Authentication Remote Code Execution
CVE-2026-46606 HIGH
Glances: Command Injection via KVM/QEMU VM Domain Names in glances/plugins/vms/engines/virsh.py
CVSS 7.8
CVE-2026-55697 HIGH
pnpm: Repository-controlled configDependencies can select a pacquet native install engine
CVSS 7.5
CVE-2026-9717 HIGH
Schneider Electric PowerLogic™ P7 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS 7.2
CVE-2026-55895 HIGH
Vim: Vimscript Code Injection in netrw NetrwLocalRmFile() via crafted filename
CVSS 7.8
CVE-2026-46735 HIGH
Dell Display And Peripheral Manager - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVSS 7.8
CVE-2026-8658 MEDIUM
OS Command Injection in Rapid7 InsightConnect Tcpdump Plugin
CVSS 6.0
CVE-2026-8666 HIGH
OS Command Injection in Rapid7 InsightConnect Traceroute Plugin
CVSS 7.7
CVE-2026-8665 HIGH
OS Command Injection in Rapid7 InsightConnect Translate Plugin
CVSS 7.7
CVE-2026-8664 MEDIUM
OS Command Injection in Rapid7 InsightConnect Finger Plugin
CVSS 6.0
CVE-2026-8660 HIGH
OS Command Injection in Rapid7 InsightConnect Ping Plugin
CVSS 7.7
CVE-2026-8592 HIGH
OS Command Injection in Rapid7 InsightConnect AWK Plugin
CVSS 7.7
CVE-2026-9155 HIGH
OS Command Injection in Rapid7 InsightConnect Sed Plugin via expression parameter.
CVSS 8.8
CVE-2026-9787 HIGH
Quest NetVault Backup NVBULogDaemon Command Injection Remote Code Execution Vulnerability
CVSS 8.8
CVE-2026-8663 MEDIUM
OS Command Injection in Rapid7 InsightConnect RPM Plugin
CVSS 6.0
CVE-2026-8659 MEDIUM
OS Command Injection in Rapid7 InsightConnect SQLmap Plugin
CVSS 6.0
CVE-2026-40079 CRITICAL
Cacti: Command Injection via escape_command() no-op in RRDtool execution
CVSS 9.8
CVE-2026-39938 CRITICAL
Cacti: Unauthenticated RCE on Graph Image
CVSS 9.8
CVE-2026-9773 HIGH
Unraid Web Server ToggleState Command Injection Remote Code Execution Vulnerability
CVSS 8.8
CVE-2026-9772 HIGH
Unraid Web Server FileUpload Command Injection Remote Code Execution Vulnerability
CVSS 8.8
CVE-2026-49980 CRITICAL
Rclone 1.46.0 to < 1.74.3 - Unauthenticated Command Execution via rc-serve
CVSS 9.8
CVE-2026-54699 HIGH
Warp: OS command injection when opening terminal links from WSL
CVSS 7.7
Details
Vulnerabilities 6,223
Exploit Likelihood High