← Back to feed Search feed

CWE-78 OS Command Injection vulnerabilities

125 CVEs — updated 2026-09-18 · vulnfeed

CVE / IDTitleSeverityCVSSEPSSSourceDate
CVE-2026-85885Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorizedCRITICAL9.944%ileNVD2026-09-17
CVE-2026-57124PraisonAI is a multi-agent teams system. Prior to 4.6.59, the default UI host applications expose POST /api/mcp/connect CRITICAL9.849%ileNVD2026-09-14
CVE-2026-27565An unauthenticated remote attacker can upload a malicious IODD file that places and executes a shell script with root prCRITICAL9.859%ileNVD2026-09-16
CVE-2026-90822FatPipe MPVPN, WARP, and IPVPN appliances running the end-of-life firmware version 10.1.2r60p100 contain an OS command iCRITICAL9.871%ileNVD2026-09-17
CVE-2026-73447A privileged attacker can exploit certain operation to execute arbitrary commands with root privileges, leading to full CRITICAL9.454%ileNVD2026-09-16
CVE-2026-58146WNC T-Mobile 5G Box IDU router is vulnerable to OS command injection vulnerability. The vulnerability exists within the CRITICAL9.481%ileNVD2026-09-16
CVE-2026-54501Browsertrix is a high-fidelity, browser-based crawling service for web archiving that can be self-hosted or used throughCRITICAL9.467%ileNVD2026-09-17
CVE-2026-89308An unauthenticated OS command injection vulnerability exists in the ping.php endpoint, allowing remote attackers to execCRITICAL9.387%ileNVD2026-09-15
CVE-2026-40855WNC T-Mobile 5G Box IDU router is vulnerable to a command injection. The vulnerability exists in the ping functionality CRITICAL9.365%ileNVD2026-09-16
CVE-2026-58147WNC T-Mobile 5G Box IDU router contains an OS command injection vulnerability in the portal.cgi component's password chaCRITICAL9.367%ileNVD2026-09-16
CVE-2026-73172Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS CommandCRITICAL9.377%ileNVD2026-09-16
CVE-2026-55158Conflibot warns in advance when merging a pull request will cause conflicts in other open pull requests. Prior to 1.2.1,CRITICAL9.138%ileNVD2026-09-15
CVE-2026-76675A command injection vulnerability exists in the command line interface of EdgeConnect SD-WAN Gateways. Successful exploiCRITICAL9.170%ileNVD2026-09-15
CVE-2026-20305A vulnerability in the diagnostic tools of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perforCRITICAL9.171%ileNVD2026-09-16
CVE-2026-20306A vulnerability in the REST API of Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to perform commanCRITICAL9.171%ileNVD2026-09-16
CVE-2026-8450HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file()CRITICAL9.171%ileMicrosoft2026-05-12
CVE-2026-91931Flowise before 3.1.4 contains a remote code execution vulnerability in the Custom MCP node that allows authenticated attCRITICAL9.049%ileNVD2026-09-15
CVE-2026-16466IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitraHIGH8.858%ileNVD2026-09-14
CVE-2026-16673IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitraHIGH8.836%ileNVD2026-09-14
CVE-2026-57133PraisonAI is a multi-agent teams system. From 1.5.1 until 1.7.2, the shell() helper exported from src/praisonai-ts/src/tHIGH8.837%ileNVD2026-09-15
CVE-2026-57136PraisonAI is a multi-agent teams system. From 1.2.3 until 1.7.2, CommandValidator in src/praisonai-ts/src/cli/features/sHIGH8.833%ileNVD2026-09-15
CVE-2026-52484An issue in MitraStar GPT-2742GX4X5v6-SV GL_g2.5_100XNT0b23_3 allows an authenticated attacker to execute arbitrary codeHIGH8.839%ileNVD2026-09-15
CVE-2026-27547A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_menu_infoHIGH8.881%ileNVD2026-09-16
CVE-2026-27548A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_port_infoHIGH8.881%ileNVD2026-09-16
CVE-2026-27549A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/doHIGH8.881%ileNVD2026-09-16
CVE-2026-27550A low-privileged remote attacker can exploit a command injection vulnerability in the Field_Shadow_Password class using HIGH8.881%ileNVD2026-09-16
CVE-2026-27551A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/parameterManage enHIGH8.881%ileNVD2026-09-16
CVE-2026-27554A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/save_iodd_parameteHIGH8.881%ileNVD2026-09-16
CVE-2026-27558A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/ajHIGH8.881%ileNVD2026-09-16
CVE-2026-27559A low-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sendiHIGH8.881%ileNVD2026-09-16
CVE-2026-88622NUUO Network Video Recorder 2.0.0 is vulnerable to Command Injection in handle_import_privilege.php.HIGH8.8NVD2026-09-18
CVE-2025-14754IBM Cloud Pak for Data 5.1.2 could allow an authenticated user to execute arbitrary commands with elevated privileges onHIGH8.8NVD2026-09-18
CVE-2026-6893Dracut: dracut: root code execution via dhcp options command injectionHIGH8.869%ileMicrosoft2026-06-09
CVE-2024-5585Command injection via array-ish $command parameter of proc_open() (bypass CVE-2024-1874 fix)HIGH8.898%ileMicrosoft2024-06-11
CVE-2026-90444A file-transfer interface that requires valid credentials accepts attacker-controlled filenames without restricting shelHIGH8.715%ileNVD2026-09-11
CVE-2026-90770Spug through 3.4.0 contains a remote code execution vulnerability in the ping_check function that interpolates user-suppHIGH8.752%ileNVD2026-09-13
CVE-2026-82762Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec FX5000HIGH8.766%ileNVD2026-09-14
CVE-2026-82766Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in SGA1000. If tHIGH8.766%ileNVD2026-09-14
CVE-2026-82774Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS M2MHIGH8.766%ileNVD2026-09-14
CVE-2026-82777Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS PACHIGH8.766%ileNVD2026-09-14
CVE-2026-82779Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS TM HIGH8.762%ileNVD2026-09-14
CVE-2026-82791Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec CAN 2.HIGH8.762%ileNVD2026-09-14
CVE-2026-82794SolarView Compact contains an OS command Injection vulnerability in in Schedule Settings. If this vulnerability is exploHIGH8.762%ileNVD2026-09-14
CVE-2026-77853Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in FF-RFI079I4 aHIGH8.762%ileNVD2026-09-15
CVE-2026-92580In AVideo through 29.0, the CloneSite plugin is vulnerable to stored OS command injection. In plugin/CloneSite/cloneClieHIGH8.764%ileNVD2026-09-16
CVE-2026-81942PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware versions before 1.2412b260707 and 2.2412b260519 contHIGH8.7NVD2026-09-18
CVE-2026-62943btrbk is a tool for creating snapshots and remote backups of Btrfs subvolumes. From 0.29.0 until 0.32.7, btrbk's ssh_filHIGH8.7NVD2026-09-18
CVE-2026-90699A weakness has been identified in D-Link DWR-M920 1.1.7. This issue affects the function sub_41E60C of the file /boafrm/HIGH8.675%ileNVD2026-09-14
CVE-2026-57586CodeRAG is a lightweight semantic code search and distillation utility for AI coding agents. Prior to 1.3.1, the defaultHIGH8.64%ileNVD2026-09-15
CVE-2026-73163Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS CommandHIGH8.659%ileNVD2026-09-16
CVE-2026-73164Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS CommandHIGH8.659%ileNVD2026-09-16
CVE-2026-73165Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS CommandHIGH8.660%ileNVD2026-09-16
CVE-2026-73167Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS CommandHIGH8.660%ileNVD2026-09-16
CVE-2026-73176Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS CommandHIGH8.660%ileNVD2026-09-16
CVE-2026-90702A flaw has been found in D-Link DWR-M921 1.1.52. Impacted is the function system of the file /boafrm/formDiskFormat. ThiHIGH8.586%ileNVD2026-09-14
CVE-2026-90703A vulnerability has been found in D-Link DWR-M921 1.1.52. The affected element is the function system of the file /boafrHIGH8.586%ileNVD2026-09-14
CVE-2026-90847A vulnerability was determined in EFM ipTIME C200E 1.094. The impacted element is an unknown function of the file iux_seHIGH8.582%ileNVD2026-09-15
CVE-2026-92397A vulnerability has been found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this vulnerability is the function ccHIGH8.582%ileNVD2026-09-16
CVE-2026-92398A vulnerability was found in Ruijie RG-EW3000GX EW_3.0(1)B11P380. Affected by this issue is some unknown functionality oHIGH8.584%ileNVD2026-09-16
CVE-2026-71538@cyclonedx/cyclonedx-npm creates CycloneDX Software Bill of Materials from npm projects. Prior to version 6.0.0, the WinHIGH8.54%ileNVD2026-09-17
CVE-2026-91102HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several HIGH8.416%ileNVD2026-09-16
CVE-2026-91936Flowise versions before 3.1.4 contain a script injection vulnerability in Docker image build workflows where workflow_diHIGH8.328%ileNVD2026-09-15
CVE-2026-54182backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages thaHIGH8.138%ileNVD2026-09-14
CVE-2026-81476Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Neutralization of Special ElementHIGH8.168%ileNVD2026-09-17
CVE-2026-53790rsync < 3.5.0 Command Injection via Multiple Code PathsHIGH8.143%ileMicrosoft2026-08-11
CVE-2026-90894Parallels Desktop runs prl_disp_service as root. Local clients reach it on the world-writable socket /var/run/prl_disp_sHIGH7.84%ileNVD2026-09-14
CVE-2026-17133IBM App Connect Enterprise 13.0.1.0 through 13.0.8.0, and 12.0.1.0 through 12.0.12.27 could allow a local attacker to exHIGH7.84%ileNVD2026-09-14
CVE-2026-79992Emacs: local shell command injection through the user field in emacs trampHIGH7.83%ileMicrosoft2026-08-11
CVE-2026-40034gitoxide - Command Injection via Partial .gitmodules Override in gix-submoduleHIGH7.829%ileMicrosoft2026-05-12
CVE-2026-84838Rpm: command injection in rpmuncompress via unescaped filenames passed to popen()HIGH7.862%ileMicrosoft2026-09-08
CVE-2026-59960Argos JavaScript provides official Argos SDKs for JavaScript. Prior to Argos core package version 6.2.1, attacker-controHIGH7.540%ileNVD2026-09-14
CVE-2026-86108Insufficient validation of inputs supplied through affected VeloCloud Edge management and configuration workflows may alHIGH7.556%ileNVD2026-09-16
CVE-2026-85756SSH.NET is a Secure Shell (SSH) library for .NET. Prior to 2026.0.0, ScpClient places caller-supplied remote paths into HIGH7.546%ileNVD2026-09-16
CVE-2026-53534JabRef is a desktop application for managing BibTeX and BibLaTeX libraries. Prior to 6.0-alpha.6, when jabsrv or JabRef'HIGH7.529%ileNVD2026-09-17
CVE-2026-78501Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business HIGH7.441%ileNVD2026-09-17
CVE-2026-85013A flaw was found in environment-modules. A local attacker can exploit this vulnerability by placing a maliciously named HIGH7.312%ileNVD2026-09-15
CVE-2026-71179Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Neutralization of Special Elements used HIGH7.342%ileNVD2026-09-16
CVE-2026-27560A high-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sendHIGH7.282%ileNVD2026-09-16
CVE-2026-27561A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sendHIGH7.282%ileNVD2026-09-16
CVE-2026-27562A high-privileged remote attacker can exploit a command injection vulnerability in the /api/iodd/config endpoint by sendHIGH7.282%ileNVD2026-09-16
CVE-2026-27563A high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint byHIGH7.280%ileNVD2026-09-16
CVE-2026-27564A high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint byHIGH7.280%ileNVD2026-09-16
CVE-2026-58502githubtoplanguages generates a user's top GitHub languages as an SVG. The .github/workflows/discord-issue.yml workflow rHIGH7.123%ileNVD2026-09-15
CVE-2026-10144Rsbuild before 2.0.9 contains a command injection vulnerability that allows attackers to execute arbitrary OS commands bHIGH7.175%ileNVD2026-09-15
CVE-2026-19515The WSO2 Integrator MI VS Code extension fails to properly sanitize or validate user-supplied input when processing MicrHIGH7.04%ileNVD2026-09-15
CVE-2026-91100HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several MEDIUM6.816%ileNVD2026-09-16
CVE-2026-76698A command injection vulnerability exists in the web-based management interface of HPE Networking EdgeConnect SD-WAN GateMEDIUM6.590%ileNVD2026-09-15
CVE-2026-20283A vulnerability in the IPsec Open API endpoint of Cisco ISE could allow an authenticated, remote attacker to inject arbiMEDIUM6.537%ileNVD2026-09-16
CVE-2026-57453Vim: PowerShell Command Injection via Unescaped Filename in zip.vim ExtractionMEDIUM6.511%ileMicrosoft2026-06-09
CVE-2026-14275IBM i Access Family 1.1.2.0 through 1.1.9.15 IBM i Access Client Solutions could allow an authenticated user to execute MEDIUM6.320%ileNVD2026-09-14
CVE-2026-14276IBM i Access Family 1.1.2.0 through 1.1.9.15 IBM i Access Client Solutions could allow an authenticated user to execute MEDIUM6.320%ileNVD2026-09-14
CVE-2026-14277IBM i Access Family 1.1.2.0 through 1.1.9.15 could allow an authenticated user to execute arbitrary commands with normalMEDIUM6.342%ileNVD2026-09-14
CVE-2026-55946Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unautMEDIUM6.134%ileNVD2026-09-17
CVE-2026-54575mport is the MidnightBSD Package Manager. Prior to 2.7.8, privileged package fetch and cache-cleaning operations used raMEDIUM5.82%ileNVD2026-09-17
CVE-2026-90617A vulnerability was detected in GH05TCREW PentestAgent up to cf882dabea3ed91cef016cdd115e5426315665a2. This vulnerabilitMEDIUM5.575%ileNVD2026-09-14
CVE-2026-90618A flaw has been found in GH05TCREW PentestAgent up to cf882dabea3ed91cef016cdd115e5426315665a2. This issue affects the fMEDIUM5.575%ileNVD2026-09-14
CVE-2026-90619A vulnerability has been found in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. Impacted is an unknMEDIUM5.570%ileNVD2026-09-14
CVE-2026-90690A weakness has been identified in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The affected elemenMEDIUM5.570%ileNVD2026-09-14
CVE-2026-90843A security vulnerability has been detected in SabyasachiRana WebMap up to 8b95fe4dc301a3c09ddf145b895de0bf9f8d2a25. ThisMEDIUM5.571%ileNVD2026-09-15
CVE-2026-93371A security vulnerability has been detected in marcopiovanello yt-dlp-web-ui up to v4. This issue affects the function NeMEDIUM5.570%ileNVD2026-09-18
CVE-2026-93533A vulnerability was determined in spatie Scotty up to 1.4.4. This impacts the function DoctorCommand::checkSshConnectiviMEDIUM5.3NVD2026-09-18
CVE-2026-20350A vulnerability in the web-based management interface of Cisco ThousandEyes Virtual Appliance could allow an authenticatMEDIUM4.727%ileNVD2026-09-16
CVE-2026-28417Vim has OS Command Injection in netrwMEDIUM4.466%ileMicrosoft2026-02-10
CVE-2026-11526GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments MEDIUM4.270%ileMicrosoft2026-06-09
CVE-2026-46483Vim: Command injection in tar#Vimuntar via missing shellescape {special} flagLOW3.645%ileMicrosoft2026-05-12
CVE-2026-35867A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of the LB-LILOW3.143%ileNVD2026-09-13
CVE-2026-90492A security vulnerability has been detected in webgjc web_robot 2.4.0/2.5.0/2.8.0. The affected element is the function cLOW2.173%ileNVD2026-09-13
CVE-2026-90621A vulnerability was identified in ipa-lab HackingBuddyGPT up to 0.5.0. This affects the function ssh_run_command of the LOW2.164%ileNVD2026-09-14
CVE-2026-90880A security flaw has been discovered in D-Link DSL-3782 2016-07-28. This issue affects the function system of the file /cLOW2.163%ileNVD2026-09-15
CVE-2026-91853A vulnerability has been found in TOTOLINK X5000R 9.1.0cu.2089_B20211224. The impacted element is the function exportOvpLOW2.171%ileNVD2026-09-15
CVE-2026-92993A vulnerability was detected in Dromara mayfly-go up to 1.11.5. The impacted element is the function RunMachineScript ofLOW2.172%ileNVD2026-09-17
CVE-2026-90704A vulnerability was found in D-Link DWR-M921 1.1.52. The impacted element is the function system of the file /boafrm/forLOW2.074%ileNVD2026-09-14
CVE-2026-90705A vulnerability was determined in D-Link DWR-M921 1.1.52. This affects the function formsysCmd of the file /boafrm/formsLOW2.074%ileNVD2026-09-14
CVE-2026-90706A vulnerability was identified in D-Link DWR-M921 1.1.52. This impacts the function formWsc of the file /boafrm/formWsc.LOW2.074%ileNVD2026-09-14
CVE-2026-90788A security flaw has been discovered in magicblack MacCMS10 2026.1000.4055. Affected by this vulnerability is an unknown LOW2.074%ileNVD2026-09-14
CVE-2026-44656Vim: OS Command Injection via 'path' completionUNKNOWN59%ileMicrosoft2026-05-12
CVE-2026-42257net-imap: Command Injection via "raw" arguments to multiple commandsUNKNOWN37%ileMicrosoft2026-05-12
CVE-2026-42258net-imap: Command Injection via unvalidated Symbol inputsUNKNOWN54%ileMicrosoft2026-05-12
CVE-2026-47240Net::IMAP: Command Injection via non-synchronizing literal in "raw" argumentUNKNOWN41%ileMicrosoft2026-06-09
CVE-2026-47242Net::IMAP: Command Injection via ID command argumentUNKNOWN3%ileMicrosoft2026-06-09
OSS-20260912-2[vim-security] Ex Command Injection in sign_jump() in Vim &lt; v9.2.1090UNKNOWNOSS-Security2026-09-12
FG-IR-26-167Cron Job Injection in Remote BackupUNKNOWNFortinet2026-09-08
FG-IR-26-141Second-Order OS Command Injection via JSON Input on start vnc featureUNKNOWNFortinet2026-06-09
FG-IR-26-131Command injection in CLIUNKNOWNFortinet2026-05-12
FG-IR-26-133OS command injection in CLIUNKNOWNFortinet2026-05-12