Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

6,190
Assigned CVEs
14th
Commonality Rank
8.5
Avg CVSS
1.9%
In CISA KEV

Volume and Severity of Assigned CVEs Over Time

Volume of CVEs assigned to CWE-78 and their average CVSS base score over time.

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 20, 1996
30 years ago
Most Recent CVE
Jul 24, 2026
0 days ago

Top CVEs Assigned This CWE

Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.

6,190 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-10520CRITICAL
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execu
Jun 9, 202610.099YESYES
CVE-2026-34197HIGH
Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the
Apr 7, 20268.899YESYES
CVE-2024-51378CRITICAL
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /
Oct 29, 20249.899YESYES
CVE-2024-4577CRITICAL
In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows m
Jun 9, 20249.899YESYES
CVE-2024-1212CRITICAL
Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary system command execution.
Feb 21, 20249.899YESYES
CVE-2022-44877CRITICAL
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the logi
Jan 5, 20239.899YESYES
CVE-2022-46169CRITICAL
Cacti is an open source platform which provides a robust and extensible operational monitoring and fault management framework for users. In affected versions a command injection vu
Dec 5, 20229.899YESYES
CVE-2022-36804HIGH
Multiple API endpoints in Atlassian Bitbucket Server and Data Center 7.0.0 before version 7.6.17, from version 7.7.0 before version 7.17.10, from version 7.18.0 before version 7.21
Aug 25, 20228.899YESYES
CVE-2022-30525CRITICAL
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Patch 1, USG FLEX 200 firmware versions 5.00 through 5.21 Patch
May 12, 20229.899YESYES
CVE-2021-36260CRITICAL
A command injection vulnerability in the web server of some Hikvision product. Due to the insufficient input validation, attacker can exploit the vulnerability to launch a command
Sep 22, 20219.899YESYES
View all 6,190 CVEs →

CVE Severity & Scoring

This CWEGlobal (All CVEs)
0.0-0.9
1.0-1.9
2.0-2.9
3.0-3.9
10%
4.0-4.9
19%
5.0-5.9
16%
6.0-6.9
23%
26%
7.0-7.9
31%
11%
8.0-8.9
36%
14%
9.0-10.0
unknown
CVSS Score Range

Exploit Exposure

Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.

CISA KEV
116 CVEs
1.9% of CVEs· 94th percentile
Metasploit
244 CVEs
3.9% of CVEs· 96th percentile
Nuclei
189 CVEs
3.1% of CVEs· 92nd percentile
ExploitDB
284 CVEs
4.6% of CVEs· 94th percentile

Social Chatter

Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.

Media Mentions

Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.

Top Affected Vendors

Top Affected Products