VulnSea

CWE-78

CVEs classified under CWE-78, newest first.

727 CVEsRSS

CVE-2026-78327Critical· 9.1
3w ago

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows an authenticated attacker with SuperAdmin pri…

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the SonicWall Network Security Manager (NSM) On-Prem Management interface allows an authenticated attacker with SuperAdmin pri…

▾ MidnightEPSS 1.6%via NVD
CVE-2026-85672Critical· 9.8PoC
3w ago

zerox 1.1.20 contains an OS command injection vulnerability in the file download mechanism where the temporary file extension derived from document URLs is interpolated unsanitized into shell commands executed by poppler utilities

zerox 1.1.20 contains an OS command injection vulnerability in the file download mechanism where the temporary file extension derived from document URLs is interpolated unsanitized into shell commands executed by poppler utilities. Attac…

▾ Abyssalgetomni-ai · zeroxEPSS 2.6%via NVD
CVE-2026-62928Critical· 9.8
3w ago

XING CPTrans-ME-X contains an OS Command Injection (CWE-78)

XING CPTrans-ME-X contains an OS Command Injection (CWE-78). Unauthenticated OS command may be injected.

▾ MidnightEPSS 2.0%via NVD
CVE-2026-85656High· 7.8
3w ago

An OS command injection issue in the log4j-cve-2021-44228-hotpatch package in Amazon Linux before 1.3-9 might allow a local user to execute arbitrary commands with root privileges via a Java process whose executable path contains embedde…

An OS command injection issue in the log4j-cve-2021-44228-hotpatch package in Amazon Linux before 1.3-9 might allow a local user to execute arbitrary commands with root privileges via a Java process whose executable path contains embedde…

▾ TwilightEPSS 1.1%via NVD
CVE-2026-79423High· 8.8PoC
3w ago

An authenticated remote code execution (RCE) vulnerability in the admin_config.php component of seacms v13.6 allows attackers to execute arbitrary code via a crafted POST request.

An authenticated remote code execution (RCE) vulnerability in the admin_config.php component of seacms v13.6 allows attackers to execute arbitrary code via a crafted POST request.

▾ MidnightEPSS 0.85%via NVD
CVE-2026-18073Medium· 4.4
3w ago

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to inject parameters into a CL command due to improper neutralization of special elements.

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to inject parameters into a CL command due to improper neutralization of special elements.

▾ Sunlitibm · iEPSS 0.10%via NVD
CVE-2026-17499Medium· 4.4
3w ago

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

▾ Sunlitibm · iEPSS 0.12%via NVD
CVE-2026-16826Medium· 5.3
3w ago

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.

▾ Sunlitibm · iEPSS 0.13%via NVD
CVE-2026-53932High· 8.0
3w ago

laravel-backup-restore restores database backups made with spatie/laravel-backup

laravel-backup-restore restores database backups made with spatie/laravel-backup. Prior to version 1.9.4, a crafted backup archive can trigger OS command injection during database restore. This issue has been patched in version 1.9.4.

▾ Twilightstefanzweifel · laravel-backup-restoreEPSS 1.7%via NVD
CVE-2026-84967Medium· 4.3
3w ago

A component of the MongoDB extension for Visual Studio Code does not neutralize special characters in a connection string before that value is placed into a command line the extension composes for an integrated terminal

A component of the MongoDB extension for Visual Studio Code does not neutralize special characters in a connection string before that value is placed into a command line the extension composes for an integrated terminal. An unauthenticat…

▾ Sunlitmongodb · mongodbEPSS 0.27%via NVD
CVE-2025-12737High· 8.4
3w ago

The administrative operations within the Carbon Console do not adequately validate specific user-supplied input

The administrative operations within the Carbon Console do not adequately validate specific user-supplied input. This oversight allows a malicious actor with administrative privileges to inject and execute arbitrary code remotely. Succe…

▾ Twilightwso2 · api_control_planeEPSS 0.22%via NVD
CVE-2026-71963High· 8.8
3w ago

Hermes Agent 0.18.2 through 0.21.0, fixed in commit f6234d0, contains a remote code execution vulnerability that allows attackers to execute arbitrary OS commands by supplying a malicious repository with a crafted .git/config that sets c…

Hermes Agent 0.18.2 through 0.21.0, fixed in commit f6234d0, contains a remote code execution vulnerability that allows attackers to execute arbitrary OS commands by supplying a malicious repository with a crafted .git/config that sets c…

▾ TwilightEPSS 0.86%via NVD
CVE-2026-85168High· 8.8
3w ago

n8n versions before 1.123.73, 2.35.4, and 2.36.2 contain a remote code execution vulnerability in the Git node

n8n versions before 1.123.73, 2.35.4, and 2.36.2 contain a remote code execution vulnerability in the Git node. The node reset a fixed list of command-bearing configuration keys before each operation, but that list did not cover the cont…

▾ Twilightn8n · n8nEPSS 0.83%via NVD
CVE-2026-85426Critical· 9.8
3w ago

MOOS-IvP uMemWatch through 24.8.1 constructs shell commands from attacker-chosen MOOS client names without sanitization

MOOS-IvP uMemWatch through 24.8.1 constructs shell commands from attacker-chosen MOOS client names without sanitization. Attackers can inject shell metacharacters into client names to execute arbitrary commands as the uMemWatch process u…

▾ MidnightEPSS 0.92%via NVD
CVE-2026-85425Critical· 9.8
3w ago

MOOS-IvP iSay through 24.8.1 contains a remote code execution vulnerability in the SAY_MOOS variable handler that passes unsanitized text to a shell command

MOOS-IvP iSay through 24.8.1 contains a remote code execution vulnerability in the SAY_MOOS variable handler that passes unsanitized text to a shell command. Attackers can publish SAY_MOOS messages containing backticks or command substit…

▾ MidnightEPSS 1.4%via NVD
CVE-2026-85012High· 8.0
3w ago

Improper neutralization of special elements used in an OS command (CWE-78) in the blueprint resynthesis framework in Amazon Web Services codecatalyst-blueprints before 0.3.156 might allow a user with permission to commit to a repository …

Improper neutralization of special elements used in an OS command (CWE-78) in the blueprint resynthesis framework in Amazon Web Services codecatalyst-blueprints before 0.3.156 might allow a user with permission to commit to a repository …

▾ TwilightEPSS 2.3%via NVD
CVE-2026-85439High· 7.8
3w ago

MOOS-IvP through 24.8.1 contains a remote code execution vulnerability in alogsplit's SplitHandler::handlePreCheckSplitDir() function that fails to sanitize shell metacharacters in log file pathnames

MOOS-IvP through 24.8.1 contains a remote code execution vulnerability in alogsplit's SplitHandler::handlePreCheckSplitDir() function that fails to sanitize shell metacharacters in log file pathnames. Attackers can embed shell syntax in …

▾ TwilightEPSS 0.38%via NVD
CVE-2026-84694High· 8.8
3w ago

Coolify before 4.2.0 fails to properly escape environment variable key names in Docker commands executed over SSH on managed servers

Coolify before 4.2.0 fails to properly escape environment variable key names in Docker commands executed over SSH on managed servers. Authenticated attackers can inject shell metacharacters into environment variable keys to execute arbit…

▾ TwilightEPSS 0.84%via NVD
CVE-2026-79756None
3w ago

Nuclio is a "Serverless" framework for Real-Time Events and Data Processing

Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.17.4, the fix for unauthenticated OS command injection in the nuclio dashboard on the local/Docker platform is incomplete. The fix added vali…

▾ SunlitEPSS 7.5%via NVD
CVE-2026-79755High· 8.0
3w ago

Nuclio is a "Serverless" framework for Real-Time Events and Data Processing

Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.17.4, on the Nuclio local Docker platform, the function namespace is interpolated—unvalidated—into a double-quoted docker ps --filter "label=…

▾ TwilightEPSS 0.67%via NVD
CVE-2026-53611Critical· 9.8
3w ago

Looking Glass is a modern, stateless network-diagnostic platform — a single self-contained Go binary that fronts a fleet of routers over SSH and exposes ping / traceroute / BGP lookups through a gRPC (ConnectRPC) API, an embedded SvelteK…

Looking Glass is a modern, stateless network-diagnostic platform — a single self-contained Go binary that fronts a fleet of routers over SSH and exposes ping / traceroute / BGP lookups through a gRPC (ConnectRPC) API, an embedded SvelteK…

▾ MidnightEPSS 2.0%via NVD
CVE-2025-46418High· 7.6
3w ago

Westermo WeOS 5.x starting from 5.24 allows OS command injection via a media definition.

Westermo WeOS 5.x starting from 5.24 allows OS command injection via a media definition.

▾ TwilightEPSS 0.68%via NVD
CVE-2026-52831High· 8.0⚖ disputed
3w ago

Nuclio is a "Serverless" framework for Real-Time Events and Data Processing

Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.4, the Nuclio controller builds a curl invocation string for each cron trigger and stores it as the args of a Kubernetes CronJob container…

▾ Twilightnuclio · github.com/nuclio/nuclioEPSS 0.53%via NVD
CVE-2026-83549High· 7.8CISA KEV0dayPoC
3w ago

Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potenti…

Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potenti…

▾ Abyssalsonicwall · sma8200vEPSS 11%via NVD
CVE-2026-73753High· 8.8
3w ago

Exploitation through affected command-line operations could allow an authenticated low-privileged user to execute arbitrary commands as a privileged user on the underlying operating system.

Exploitation through affected command-line operations could allow an authenticated low-privileged user to execute arbitrary commands as a privileged user on the underlying operating system.

▾ Twilighthpe · arubaos-cxEPSS 0.66%via NVD
CVE-2026-84361HighPoC
3w ago

Composer is a dependency Manager for the PHP language

Composer is a dependency Manager for the PHP language. From 1.0 until 2.2.30 and 2.10.3, a malicious dependency package from a custom Composer repository or an untrusted composer.lock file could set source.type to perforce and source.url…

▾ Midnightcomposer · composer/composerEPSS 0.55%via NVD
CVE-2026-84194None
3w ago

LibreNMS versions >= 23.10.0 and < 26.2.0 (fixed in 26.4.0) contain an authenticated OS command injection vulnerability in libvirt discovery

LibreNMS versions >= 23.10.0 and < 26.2.0 (fixed in 26.4.0) contain an authenticated OS command injection vulnerability in libvirt discovery. When libvirt support is enabled (enable_libvirt=true), the device hostname ($this->getDevice()-…

▾ SunlitEPSS 1.5%via NVD
CVE-2026-82636High· 7.9
4w ago

Qubes OS before qubes-core-dom0-linux 4.3.22 allows OS command injection during a qvm-copy-to-vm call from dom0 to an attacker-controlled qube, because the "system" library function is used to process an error message that may have shell…

Qubes OS before qubes-core-dom0-linux 4.3.22 allows OS command injection during a qvm-copy-to-vm call from dom0 to an attacker-controlled qube, because the "system" library function is used to process an error message that may have shell…

▾ TwilightEPSS 1.9%via NVD
CVE-2026-55378None
1mo ago

JS Recon is a JavaScript enumeration and SAST tool

JS Recon is a JavaScript enumeration and SAST tool. From 1.2.1-beta.1 until 1.3.1-beta.2, the PR Branch Checker workflow in .github/workflows/pr_checker.yml places github.head_ref and github.event.pull_request.head.repo.full_name into BR…

▾ SunlitEPSS 0.85%via NVD
CVE-2026-38822High· 7.6
1mo ago

In openNDS before 11.0.0, the client_params.sh script, invoked by the openNDS daemon to serve the authenticated client status page, is vulnerable to OS command injection through crafted HTTP GET query parameter keys

In openNDS before 11.0.0, the client_params.sh script, invoked by the openNDS daemon to serve the authenticated client status page, is vulnerable to OS command injection through crafted HTTP GET query parameter keys. An authenticated cap…

▾ TwilightEPSS 2.3%via NVD
CWE-78 vulnerabilities (CVEs) — page 9 · VulnSea