The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
Volume of CVEs assigned to CWE-78 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
6,190 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-10520CRITICAL An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execu | Jun 9, 2026 | 10.0 | 99 | YES | YES |
CVE-2026-34197HIGH Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ.
Apache ActiveMQ Classic exposes the | Apr 7, 2026 | 8.8 | 99 | YES | YES |
CVE-2024-51378CRITICAL getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via / | Oct 29, 2024 | 9.8 | 99 | YES | YES |
CVE-2024-4577CRITICAL In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows m | Jun 9, 2024 | 9.8 | 99 | YES | YES |
CVE-2024-1212CRITICAL Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution. | Feb 21, 2024 | 9.8 | 99 | YES | YES |
CVE-2022-44877CRITICAL login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the logi | Jan 5, 2023 | 9.8 | 99 | YES | YES |
CVE-2022-46169CRITICAL Cacti is an open source platform which provides a robust and extensible operational monitoring and fault management framework for users. In affected versions a command injection vu | Dec 5, 2022 | 9.8 | 99 | YES | YES |
CVE-2022-36804HIGH Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from version 7.18.0 before version 7.21 | Aug 25, 2022 | 8.8 | 99 | YES | YES |
CVE-2022-30525CRITICAL A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 firmware versions 5.00 through 5.21 Patch | May 12, 2022 | 9.8 | 99 | YES | YES |
CVE-2021-36260CRITICAL A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vulnerability to launch a command | Sep 22, 2021 | 9.8 | 99 | YES | YES |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.