CWE-78
MITRE ↗Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)
PROLiNK PRC2402M 20190909 before 2021-06-13 allows live_api.cgi?page=satellite_list OS command injection via shell metac
WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, a critical Remote Code Execution (RCE) vulne
WWBN AVideo is an open source video platform. In versions up to and including 26.0, multiple vulnerabilities in AVideo's
The command auto-approval module in CodeRider-Kilo contains an OS Command Injection vulnerability, rendering its whiteli
PDF Export Module used in DHTMLX's products Gantt and Scheduler is vulnerable to Remote Code Execution due to lack of "d
CtrlPanel is open-source billing software for hosting providers. In versions 1.1.1 and prior, the web-based installer (p
Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is started
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote
MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17,
Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestr
Storage Concentrator (SC & SCVM) contains a command injection vulnerability in the ms_service.pl service, which listens
Storage Concentrator (SC & SCVM) contains a command injection vulnerability within the debug.pl script that is reachable
A shellcode injection in the mercurial handler of the obs tar_scm source service before version 0.12.4 could be used by
Ruflo is an agent meta-harness for Claude Code and Codex. Prior to 3.16.3, ruflo's default docker-compose deployment exp
9Router is an AI router & token saver. From 0.4.30 until 0.4.37, 9Router's src/proxy.js middleware did not protect /api/
Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the
VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privile
ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The vul
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Co
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Co
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0
A Command Injection vulnerability in Zoom Node Multimedia Routers (MMRs) before version 5.2.1716.0 may allow a meeting p
Dokploy is a free, self-hostable Platform as a Service (PaaS). In versions prior to 0.26.6, a critical command injection
Signal K Server is a server application that runs on a central hub in a boat. Prior to 1.5.0, a command injection vulner
n8n is an open source workflow automation platform. Prior to versions 1.123.10 and 2.5.0, vulnerabilities in the Git nod
OpenProject is an open-source, web-based project management software. Prior to versions 16.6.7 and 17.0.3, an arbitrary
Catalyst is a platform built for enterprise game server hosts, game communities, and billing panel integrations. Install
emp3r0r is a stealth-focused C2 designed by Linux users for Linux environments. Prior to 3.21.1, untrusted agent metadat
OliveTin gives access to predefined shell commands from a web interface. In versions up to and including 3000.10.0, Oliv
OneUptime is a solution for monitoring and managing online services. Prior to version 10.0.7, an OS command injection vu
Vitess is a database clustering system for horizontal scaling of MySQL. Prior to versions 23.0.3 and 22.0.4, anyone with
WeKnora is an LLM-powered framework designed for deep document understanding and semantic retrieval. From version 0.2.5
OneUptime is an open-source monitoring and observability platform. Prior to version 10.0.35, a low-privileged authentica
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, due to unsafe s
An os command injection vulnerability exists in the DdnsSetting.cgi functionality of GeoVision LPC2011/LPC2211 1.10. A s
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to v
Dokploy is a free, self-hostable Platform as a Service (PaaS). Versions 0.26.6 and below have OS command injection throu
Twenty is an open source CRM. From 1.7.7 through 1.16.7, a critical Remote Code Execution (RCE) vulnerability exists in
Exposed methods allow authenticated users to create and execute arbitrary JavaScript code on the server. The scripts exe
Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection
Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.7 and earlier, the schedule router does not enfor
Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.6 and earlier, Dokploy contains a command injecti
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to v
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, PO
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, th
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to be
Flowise before 3.1.2 contains multiple OS command injection vulnerabilities in the Custom MCP Server feature due to inco
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.
Wekan is open source kanban built with Meteor. Prior to 9.07, Wekan avatar upload functionality embeds user-supplied fil
Frequently Asked Questions
What is CWE-78?
CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-78?
There are 1,567 CVE records associated with CWE-78 in our database. Of these, 444 are critical severity, 731 are high severity, and 217 are medium severity.
How can I protect against CWE-78 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.
Detect CWE-78 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.
Get Started