Rosetta Intel
Datasets/KEV CatalogThreat Actors
Rosetta Lab ↗Blur Horizon LLC
Datasets

KEV Catalog

CISA, queryable

Known exploited vulnerabilities as a queryable table — by CVE, vendor or product.

1676 entries·352 Ransomware·Updated 2026-08-25

CWE-78 · OS command injectionDefinition on MITRE ↗Clear

108 results·Page 1 / 3

CVE-2026-73570
2026-08-21
Zimbra Collaboration Suite (ZCS) OS Command Injection Vulnerability
Synacor

Zimbra Collaboration Suite (ZCS) contains an OS command injection vulnerability which could allow an unauthenticated attacker to send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.

CWE-78 · OS command injection
Refswiki.zimbra.comblog.zimbra.comBOD 26-04Forensics Triage Requirementsnvd.nist.gov
Federal remediation due 2026-08-24
CVE-2026-16812
2026-07-27
Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability
Arista

Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.

CWE-78 · OS command injection
Refsarista.comBOD 26-04Forensics Triage Requirementsnvd.nist.gov
Federal remediation due 2026-07-30
CVE-2026-39808
2026-07-16
Fortinet FortiSandbox OS Command Injection Vulnerability
Fortinet

Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests.

CWE-78 · OS command injection
Refsfortiguard.fortinet.comBOD 26-04Forensics Triage Requirementsnvd.nist.gov
Federal remediation due 2026-07-19
CVE-2026-25089
2026-07-16
Fortinet FortiSandbox OS Command Injection Vulnerability
Fortinet

Fortinet FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS contain an OS command injection vulnerability that allows an unauthenticated attacker to execute unauthorized commands via specifically crafted HTTP requests.

CWE-78 · OS command injection
Refsfortiguard.fortinet.comBOD 26-04Forensics Triage Requirementsnvd.nist.gov
Federal remediation due 2026-07-19
CVE-2025-67038
2026-06-23
Lantronix EDS5000 Code Injection Vulnerability
Lantronix

Lantronix EDS5000 contains a code injection vulnerability that could allow attackers to inject arbitrary OS commands into the username parameter. Injected commands are executed with root privileges.

CWE-78 · OS command injectionCWE-94 · Code injection
Refsltrxdev.atlassian.netBOD 26-04Forensics Triage Requirementsnvd.nist.gov
Federal remediation due 2026-06-26
CVE-2026-10520
2026-06-11
Ivanti Sentry OS Command Injection Vulnerability
Ivanti

Ivanti Sentry (formerly known as MobileIron Sentry) contains an OS command injection vulnerability which could allow a remote unauthenticated user to achieve root-level remote code execution. This vulnerability can be successfully exploited in cases where the Sentry appliance is in an unmanaged state with its endpoints externally reachable. The use of mTLS with EPMM or restricted HTTPS access through Neurons for MDM makes interfaces inaccessible to external actors.

CWE-78 · OS command injection
Refshub.ivanti.comBOD 26-04Forensics Triage Requirementsnvd.nist.gov
Federal remediation due 2026-06-14
CVE-2026-42271
2026-06-08
BerriAI LiteLLM Command Injection Vulnerability
BerriAI

BerriAI LiteLLM contains a command injection vulnerability that could allow any authenticated user, including holders of low-privilege internal-user keys, to run arbitrary commands on the host.

CWE-78 · OS command injectionCWE-77 · Command injection
RefsThis vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please seegithub.comnvd.nist.gov
Federal remediation due 2026-06-22
CVE-2026-25108
2026-02-24
Soliton Systems K.K FileZen OS Command Injection Vulnerability
Soliton Systems K.K

Soliton Systems K.K FileZen contains an OS command injection vulnerability when an user logs-in to the affected product and sends a specially crafted HTTP request.

CWE-78 · OS command injection
Refsjvn.jpnvd.nist.gov
Federal remediation due 2026-03-17
CVE-2026-1731
2026-02-13
BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection VulnerabilityRansomware
BeyondTrust

BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA)contain an OS command injection vulnerability. Successful exploitation could allow an unauthenticated remote attacker to execute operating system commands in the context of the site user. Successful exploitation requires no authentication or user interaction and may lead to system compromise, including unauthorized access, data exfiltration, and service disruption.

CWE-78 · OS command injection
RefsPlease adhere to the vendor's guidelines to assess exposure and mitigate risks. Check for signs of potential compromise on all internet accessible BeyondTrust products affected by this vulnerability. For more information please: seenvd.nist.gov
Federal remediation due 2026-02-16
CVE-2025-11953
2026-02-05
React Native Community CLI OS Command Injection Vulnerability
React Native Community

React Native Community CLI contains an OS command injection vulnerability which could allow unauthenticated network attackers to send POST requests to the Metro Development Server and run arbitrary executables via a vulnerable endpoint exposed by the server. On Windows, attackers can also execute arbitrary shell commands with fully controlled arguments.

CWE-78 · OS command injection
RefsThis vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please seegithub.comnvd.nist.gov
Federal remediation due 2026-02-26
CVE-2025-64328
2026-02-03
Sangoma FreePBX OS Command Injection Vulnerability
Sangoma

Sangoma FreePBX Endpoint Manager contains an OS command injection vulnerability that could allow for a post-authentication command injection by an authenticated known user via the testconnection -> check_ssh_connect() function. An attacker can leverage this vulnerability to potentially obtain remote access to the system as an asterisk user.

CWE-78 · OS command injection
Refsgithub.comnvd.nist.gov
Federal remediation due 2026-02-24
CVE-2025-66644
2025-12-08
Array Networks ArrayOS AG OS Command Injection Vulnerability
Array Networks

Array Networks ArrayOS AG contains an OS command injection vulnerability that could allow an attacker to execute arbitrary commands.

CWE-78 · OS command injection
Refssupport.arraynetworks.netjpcert.or.jpnvd.nist.gov
Federal remediation due 2025-12-29
CVE-2025-58034
2025-11-18
Fortinet FortiWeb OS Command Injection Vulnerability
Fortinet

Fortinet FortiWeb contains an OS command Injection vulnerability that may allow an authenticated attacker to execute unauthorized code on the underlying system via crafted HTTP requests or CLI commands.

CWE-78 · OS command injection
Refsfortiguard.fortinet.comnvd.nist.gov
Federal remediation due 2025-11-25
CVE-2025-48703
2025-11-04
CWP Control Web Panel OS Command Injection Vulnerability
CWP

CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command Injection vulnerability that allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager changePerm request. A valid non-root username must be known.

CWE-78 · OS command injection
Refscontrol-webpanel.comnvd.nist.gov
Federal remediation due 2025-11-25
CVE-2014-6278
2025-10-02
GNU Bash OS Command Injection Vulnerability
GNU

GNU Bash contains an OS command injection vulnerability which allows remote attackers to execute arbitrary commands via a crafted environment.

CWE-78 · OS command injection
RefsThis vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please seesupport.broadcom.comsec.cloudapps.cisco.comibm.comnvd.nist.gov
Federal remediation due 2025-10-23
CVE-2025-9377
2025-09-03
TP-Link Archer C7(EU) and TL-WR841N/ND(MS) OS Command Injection Vulnerability
TP-Link / Multiple Routers

TP-Link Archer C7(EU) and TL-WR841N/ND(MS) contain an OS command injection vulnerability that exists in the Parental Control page. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

CWE-78 · OS command injection
Refstp-link.comnvd.nist.gov
Federal remediation due 2025-09-24
CVE-2025-54948
2025-08-18
Trend Micro Apex One OS Command Injection Vulnerability
Trend Micro

Trend Micro Apex One Management Console (on-premise) contains an OS command injection vulnerability that could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations.

CWE-78 · OS command injection
Refssuccess.trendmicro.comnvd.nist.gov
Federal remediation due 2025-09-08
CVE-2023-39780
2025-06-02
ASUS RT-AX55 Routers OS Command Injection Vulnerability
ASUS

ASUS RT-AX55 devices contain an OS command injection vulnerability that could allow a remote, authenticated attacker to execute arbitrary commands. As represented by CVE-2023-41346.

CWE-78 · OS command injection
Refsasus.comasus.comnvd.nist.gov
Federal remediation due 2025-06-23
CVE-2024-12987
2025-05-15
DrayTek Vigor Routers OS Command Injection Vulnerability
DrayTek

DrayTek Vigor2960, Vigor300B, and Vigor3900 routers contain an OS command injection vulnerability due to an unknown function of the file /cgi-bin/mainfunction.cgi/apmcfgupload of the component web management interface.

CWE-78 · OS command injection
Refsfw.draytek.com.twfw.draytek.com.twfw.draytek.com.twnvd.nist.gov
Federal remediation due 2025-06-05
CVE-2024-6047
2025-05-07
GeoVision Devices OS Command Injection Vulnerability
GeoVision / Multiple Devices

Multiple GeoVision devices contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to inject and execute arbitrary system commands. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

CWE-78 · OS command injection
Refsdlcdn.geovision.com.twnvd.nist.gov
Federal remediation due 2025-05-28
CVE-2024-11120
2025-05-07
GeoVision Devices OS Command Injection Vulnerability
GeoVision / Multiple Devices

Multiple GeoVision devices contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to inject and execute arbitrary system commands. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

CWE-78 · OS command injection
Refsdlcdn.geovision.com.twnvd.nist.gov
Federal remediation due 2025-05-28
CVE-2023-44221
2025-05-01
SonicWall SMA100 Appliances OS Command Injection Vulnerability
SonicWall

SonicWall SMA100 appliances contain an OS command injection vulnerability in the SSL-VPN management interface that allows a remote, authenticated attacker with administrative privilege to inject arbitrary commands as a 'nobody' user.

CWE-78 · OS command injection
Refspsirt.global.sonicwall.comnvd.nist.gov
Federal remediation due 2025-05-22
CVE-2021-20035
2025-04-16
SonicWall SMA100 Appliances OS Command Injection Vulnerability
SonicWall

SonicWall SMA100 appliances contain an OS command injection vulnerability in the management interface that allows a remote authenticated attacker to inject arbitrary commands as a 'nobody' user, which could potentially lead to code execution.

CWE-78 · OS command injection
Refspsirt.global.sonicwall.comnvd.nist.gov
Federal remediation due 2025-05-07
CVE-2025-1316
2025-03-19
Edimax IC-7100 IP Camera OS Command Injection Vulnerability
Edimax

Edimax IC-7100 IP camera contains an OS command injection vulnerability due to improper input sanitization that allows an attacker to achieve remote code execution via specially crafted requests. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.

CWE-78 · OS command injection
Refsedimax.comnvd.nist.gov
Federal remediation due 2025-04-09
CVE-2024-40891
2025-02-11
Zyxel DSL CPE OS Command Injection Vulnerability
Zyxel / DSL CPE Devices

Multiple Zyxel DSL CPE devices contain a post-authentication command injection vulnerability in the management commands that could allow an authenticated attacker to execute OS commands via Telnet.

CWE-78 · OS command injection
Refszyxel.comzyxel.comnvd.nist.gov
Federal remediation due 2025-03-04
CVE-2024-40890
2025-02-11
Zyxel DSL CPE OS Command Injection Vulnerability
Zyxel / DSL CPE Devices

Multiple Zyxel DSL CPE devices contain a post-authentication command injection vulnerability in the CGI program that could allow an authenticated attacker to execute OS commands via a crafted HTTP request.

CWE-78 · OS command injection
Refszyxel.comzyxel.comnvd.nist.gov
Federal remediation due 2025-03-04
CVE-2018-9276
2025-02-04
Paessler PRTG Network Monitor OS Command Injection Vulnerability
Paessler

Paessler PRTG Network Monitor contains an OS command injection vulnerability that allows an attacker with administrative privileges to execute commands via the PRTG System Administrator web console.

CWE-78 · OS command injection
Refspaessler.comnvd.nist.gov
Federal remediation due 2025-02-25
CVE-2024-50603
2025-01-16
Aviatrix Controllers OS Command Injection Vulnerability
Aviatrix

Aviatrix Controllers contain an OS command injection vulnerability that could allow an unauthenticated attacker to execute arbitrary code. Shell metacharacters can be sent to /v1/api in cloud_type for list_flightpath_destination_instances, or src_cloud_type for flightpath_connection_test.

CWE-78 · OS command injection
Refsdocs.aviatrix.comnvd.nist.gov
Federal remediation due 2025-02-06
CVE-2024-12686
2025-01-13
BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) OS Command Injection Vulnerability
BeyondTrust

BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain an OS command injection vulnerability that can be exploited by an attacker with existing administrative privileges to upload a malicious file. Successful exploitation of this vulnerability can allow a remote attacker to execute underlying operating system commands within the context of the site user.

CWE-78 · OS command injection
Refsbeyondtrust.comnvd.nist.gov
Federal remediation due 2025-02-03
CVE-2021-40407
2024-12-18
Reolink RLC-410W IP Camera OS Command Injection Vulnerability
Reolink

Reolink RLC-410W IP cameras contain an authenticated OS command injection vulnerability in the device network settings functionality.

CWE-78 · OS command injection
Refsreolink.comreolink.comnvd.nist.gov
Federal remediation due 2025-01-08
CVE-2019-11001
2024-12-18
Reolink Multiple IP Cameras OS Command Injection Vulnerability
Reolink

Reolink RLC-410W, C1 Pro, C2 Pro, RLC-422W, and RLC-511W IP cameras contain an authenticated OS command injection vulnerability. This vulnerability allows an authenticated admin to use the "TestEmail" functionality to inject and run OS commands as root.

CWE-78 · OS command injection
Refsreolink.comreolink.comnvd.nist.gov
Federal remediation due 2025-01-08
CVE-2018-14933
2024-12-18
NUUO NVRmini Devices OS Command Injection Vulnerability
NUUO

NUUO NVRmini devices contain an OS command injection vulnerability. This vulnerability allows remote command execution via shell metacharacters in the uploaddir parameter for a writeuploaddir command.

CWE-78 · OS command injection
Refsnuuo.comnvd.nist.gov
Federal remediation due 2025-01-08
CVE-2024-1212
2024-11-18
Progress Kemp LoadMaster OS Command Injection Vulnerability
Progress

Progress Kemp LoadMaster contains an OS command injection vulnerability that allows an unauthenticated, remote attacker to access the system through the LoadMaster management interface, enabling arbitrary system command execution.

CWE-78 · OS command injection
Refscommunity.progress.comnvd.nist.gov
Federal remediation due 2024-12-09
CVE-2024-9463
2024-11-14
Palo Alto Networks Expedition OS Command Injection Vulnerability
Palo Alto Networks

Palo Alto Networks Expedition contains an OS command injection vulnerability that allows an unauthenticated attacker to run arbitrary OS commands as root in Expedition, resulting in disclosure of usernames, cleartext passwords, device configurations, and device API keys of PAN-OS firewalls.

CWE-78 · OS command injection
Refssecurity.paloaltonetworks.comnvd.nist.gov
Federal remediation due 2024-12-05
CVE-2024-8957
2024-11-04
PTZOptics PT30X-SDI/NDI Cameras OS Command Injection Vulnerability
PTZOptics

PTZOptics PT30X-SDI/NDI cameras contain an OS command injection vulnerability that allows a remote, authenticated attacker to escalate privileges to root via a crafted payload with the ntp_addr parameter of the /cgi-bin/param.cgi CGI script.

CWE-78 · OS command injection
Refsptzoptics.comnvd.nist.gov
Federal remediation due 2024-11-25
CVE-2023-25280
2024-09-30
D-Link DIR-820 Router OS Command Injection Vulnerability
D-Link

D-Link DIR-820 routers contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp.

CWE-78 · OS command injection
Refssupportannouncement.us.dlink.comnvd.nist.gov
Federal remediation due 2024-10-21
CVE-2020-15415
2024-09-30
DrayTek Multiple Vigor Routers OS Command Injection Vulnerability
DrayTek

DrayTek Vigor3900, Vigor2960, and Vigor300B devices contain an OS command injection vulnerability in cgi-bin/mainfunction.cgi/cvmcfgupload that allows for remote code execution via shell metacharacters in a filename when the text/x-python-script content type is used.

CWE-78 · OS command injection
Refsdraytek.comnvd.nist.gov
Federal remediation due 2024-10-21
CVE-2024-8190
2024-09-13
Ivanti Cloud Services Appliance OS Command Injection Vulnerability
Ivanti

Ivanti Cloud Services Appliance (CSA) contains an OS command injection vulnerability in the administrative console which can allow an authenticated attacker with application admin privileges to pass commands to the underlying OS.

CWE-78 · OS command injection
Refsforums.ivanti.comnvd.nist.gov
Federal remediation due 2024-10-04
CVE-2024-20399
2024-07-02
Cisco NX-OS Command Injection Vulnerability
Cisco

Cisco NX-OS contains a command injection vulnerability in the command line interface (CLI) that could allow an authenticated, local attacker to execute commands as root on the underlying operating system of an affected device.

CWE-78 · OS command injection
Refssec.cloudapps.cisco.comnvd.nist.gov
Federal remediation due 2024-07-23
CVE-2024-4577
2024-06-12
PHP-CGI OS Command Injection VulnerabilityRansomware
PHP Group

PHP, specifically Windows-based PHP used in CGI mode, contains an OS command injection vulnerability that allows for arbitrary code execution. This vulnerability is a patch bypass for CVE-2012-1823.

CWE-78 · OS command injection
RefsThis vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please seenvd.nist.gov
Federal remediation due 2024-07-03
CVE-2017-3506
2024-06-03
Oracle WebLogic Server OS Command Injection Vulnerability
Oracle

Oracle WebLogic Server, a product within the Fusion Middleware suite, contains an OS command injection vulnerability that allows an attacker to execute arbitrary code via a specially crafted HTTP request that includes a malicious XML document.

CWE-78 · OS command injection
Refsoracle.comnvd.nist.gov
Federal remediation due 2024-06-24
CVE-2019-7256
2024-03-25
Nice Linear eMerge E3-Series OS Command Injection Vulnerability
Nice

Nice Linear eMerge E3-Series contains an OS command injection vulnerability that allows an attacker to conduct remote code execution.

CWE-78 · OS command injection
Refslinear-solutions.comnvd.nist.gov
Federal remediation due 2024-04-15
CVE-2021-36380
2024-03-05
Sunhillo SureLine OS Command Injection Vulnerablity
Sunhillo

Sunhillo SureLine contains an OS command injection vulnerability that allows an attacker to cause a denial-of-service or utilize the device for persistence on the network via shell metacharacters in ipAddr or dnsAddr in /cgi/networkDiag.cgi.

CWE-78 · OS command injection
Refssunhillo.comnvd.nist.gov
Federal remediation due 2024-03-26
CVE-2023-49897
2023-12-21
FXC AE1021, AE1021PE OS Command Injection Vulnerability
FXC

FXC AE1021 and AE1021PE contain an OS command injection vulnerability that allows authenticated users to execute commands via a network.

CWE-78 · OS command injection
Refsfxc.jpnvd.nist.gov
Federal remediation due 2024-01-11
CVE-2023-47565
2023-12-21
QNAP VioStor NVR OS Command Injection Vulnerability
QNAP

QNAP VioStar NVR contains an OS command injection vulnerability that allows authenticated users to execute commands via a network.

CWE-78 · OS command injection
Refsqnap.comnvd.nist.gov
Federal remediation due 2024-01-11
CVE-2023-20273
2023-10-23
Cisco IOS XE Web UI Command Injection Vulnerability
Cisco

Cisco IOS XE contains a command injection vulnerability in the web user interface. When chained with CVE-2023-20198, the attacker can leverage the new local user to elevate privilege to root and write the implant to the file system. Cisco identified CVE-2023-20273 as the vulnerability exploited to deploy the implant. CVE-2021-1435, previously associated with the exploitation events, is no longer believed to be related to this activity.

CWE-78 · OS command injection
Refssec.cloudapps.cisco.comnvd.nist.gov
Federal remediation due 2023-10-27
CVE-2017-6884
2023-09-18
Zyxel EMG2926 Routers Command Injection VulnerabilityRansomware
Zyxel

Zyxel EMG2926 routers contain a command injection vulnerability located in the diagnostic tools, specifically the nslookup function. A malicious user may exploit numerous vectors to execute malicious commands on the router, such as the ping_ip parameter to the expert/maintenance/diagnostic/nslookup URI.

CWE-78 · OS command injection
Refszyxel.comnvd.nist.gov
Federal remediation due 2023-10-09
CVE-2017-18368
2023-08-07
Zyxel P660HN-T1A Routers Command Injection Vulnerability
Zyxel

Zyxel P660HN-T1A routers contain a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user and exploited via the remote_host parameter of the ViewLog.asp page.

CWE-78 · OS command injection
Refszyxel.comzyxel.comnvd.nist.gov
Federal remediation due 2023-08-28
CVE-2022-29303
2023-07-13
SolarView Compact Command Injection Vulnerability
SolarView

SolarView Compact contains a command injection vulnerability due to improper validation of input values on the send test mail console of the product's web server.

CWE-78 · OS command injection
Refsjvn.jpnvd.nist.gov
Federal remediation due 2023-08-03
CVE-2019-20500
2023-06-29
D-Link DWL-2600AP Access Point Command Injection Vulnerability
D-Link

D-Link DWL-2600AP access point contains an authenticated command injection vulnerability via the Save Configuration functionality in the Web interface, using shell metacharacters in the admin.cgi?action=config_save configBackup or downloadServerip parameter.

CWE-78 · OS command injection
Refssupportannouncement.us.dlink.comnvd.nist.gov
Federal remediation due 2023-07-20
Prev1 / 3Next