CWE-78
5,895 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CVEs (5,895)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Copeland 3Xweb 300d Pro Firmware Xweb 500b Pro FirmwareXweb 500d Pro FirmwareFeb 27, 2026 Feb 27, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into parameters of...Show more |
1Copeland 3Xweb 300d Pro Firmware Xweb 500b Pro FirmwareXweb 500d Pro FirmwareFeb 27, 2026 Feb 27, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by configuring a maliciously crafted LCD state whic...Show more |
1Copeland 3Xweb 300d Pro Firmware Xweb 500b Pro FirmwareXweb 500d Pro FirmwareFeb 27, 2026 Feb 27, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by supplying a crafted template file to the devices...Show more |
1Copeland 3Xweb 300d Pro Firmware Xweb 500b Pro FirmwareXweb 500d Pro FirmwareFeb 27, 2026 Feb 27, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by sending malicious input injected into the server...Show more |
1Copeland 3Xweb 300d Pro Firmware Xweb 500b Pro FirmwareXweb 500d Pro FirmwareFeb 27, 2026 Feb 27, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by providing malicious input via the device hostname...Show more |
1Copeland 3Xweb 300d Pro Firmware Xweb 500b Pro FirmwareXweb 500d Pro FirmwareMar 9, 2026 Feb 27, 2026 N/A· v4 6.6 MEDIUM· v3 N/A· v2 An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by supplying a crafted firmware update file via t...Show more |
1Copeland 3Xweb 300d Pro Firmware Xweb 500b Pro FirmwareXweb 500d Pro FirmwareMar 9, 2026 Feb 27, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into requests sent to t...Show more |
1Copeland 3Xweb 300d Pro Firmware Xweb 500b Pro FirmwareXweb 500d Pro FirmwareJun 4, 2026 Feb 27, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the devices fiel...Show more |
1Copeland 3Xweb 300d Pro Firmware Xweb 500b Pro FirmwareXweb 500d Pro FirmwareMar 9, 2026 Feb 27, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into OpenSSL argume...Show more |
1Copeland 3Xweb 300d Pro Firmware Xweb 500b Pro FirmwareXweb 500d Pro FirmwareMar 9, 2026 Feb 27, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the devices field...Show more |
1Copeland 3Xweb 300d Pro Firmware Xweb 500b Pro FirmwareXweb 500d Pro FirmwareMar 9, 2026 Feb 27, 2026 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an unauthenticated attacker to achieve remote code execution on the system by sending a crafted request to the libraries inst...Show more |
1Copeland 3Xweb 300d Pro Firmware Xweb 500b Pro FirmwareXweb 500d Pro FirmwareMar 9, 2026 Feb 27, 2026 N/A· v4 7.2 HIGH· v3 N/A· v2 An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into requests sent to...Show more |
1Copeland 3Xweb 300d Pro Firmware Xweb 500b Pro FirmwareXweb 500d Pro FirmwareFeb 27, 2026 Feb 27, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the request body s...Show more |
1Copeland 3Xweb 300d Pro Firmware Xweb 500b Pro FirmwareXweb 500d Pro FirmwareJun 4, 2026 Feb 27, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the devices field...Show more |
1Copeland 3Xweb 300d Pro Firmware Xweb 500b Pro FirmwareXweb 500d Pro FirmwareFeb 27, 2026 Feb 27, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into the map filenam...Show more |
1Copeland 3Xweb 300d Pro Firmware Xweb 500b Pro FirmwareXweb 500d Pro FirmwareFeb 27, 2026 Feb 27, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by injecting malicious input into requests sent to...Show more |
osctrl is an osquery management solution. Prior to version 0.5.0, an OS command injection vulnerability exists in the `osctrl-admin` environment configuration. An authenticated administrator can inject arbitrary shell co...Show more |
Kiteworks is a private data network (PDN). Prior to version 9.2.0, avulnerability in Kiteworks command execution functionality allows authenticated users to redirect command output to arbitrary file locations. This could...Show more |
Zen C is a systems programming language that compiles to human-readable GNU C/C11. Prior to version 0.4.2, a command injection vulnerability (CWE-78) in the Zen C compiler allows local attackers to execute arbitrary shel...Show more |
Vitess is a database clustering system for horizontal scaling of MySQL. Prior to versions 23.0.3 and 22.0.4, anyone with read/write access to the backup storage location (e.g. an S3 bucket) can manipulate backup manifest...Show more |