Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)

1,941
CRITICAL
3,146
HIGH
963
MEDIUM
16
LOW
6,290 CVEs · Page 100/126
9.8
CVE-2020-5556

Shihonkanri Plus GOOUT Ver1.5.8 and Ver2.2.10 allows remote attackers to execute arbitrary OS commands via unspecified v

9.8
CVE-2020-5560

WL-Enq 1.11 and 1.12 allows remote attackers to execute arbitrary OS commands with the administrative privilege via unsp

9.8
CVE-2020-5561

Keijiban Tsumiki v1.15 allows remote attackers to execute arbitrary OS commands via unspecified vectors.

9.8
CVE-2020-10789

openITCOCKPIT before 3.7.3 has a web-based terminal that allows attackers to execute arbitrary OS commands via shell met

9.8
CVE-2020-10886

This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firm

9.8
CVE-2019-19606

X-Plane before 11.41 has multiple improper path validations that could allow reading and writing files from/to arbitrary

9.8
CVE-2020-7619

get-git-data through 1.3.1 is vulnerable to Command Injection. It is possible to inject arbitrary commands as part of th

9.8
CVE-2020-7620

pomelo-monitor through 0.3.7 is vulnerable to Command Injection.It allows injection of arbitrary commands as part of 'po

9.8
CVE-2020-7621

strong-nginx-controller through 1.0.2 is vulnerable to Command Injection. It allows execution of arbitrary command as pa

9.8
CVE-2020-7623

jscover through 1.0.0 is vulnerable to Command Injection. It allows execution of arbitrary command via the source argume

9.8
CVE-2020-7624

effect through 1.0.4 is vulnerable to Command Injection. It allows execution of arbitrary command via the options argume

9.8
CVE-2020-7625

op-browser through 1.0.6 is vulnerable to Command Injection. It allows execution of arbitrary commands via the url funct

9.8
CVE-2020-7626

karma-mojo through 1.0.1 is vulnerable to Command Injection. It allows execution of arbitrary commands via the config ar

9.8
CVE-2020-7627

node-key-sender through 1.0.11 is vulnerable to Command Injection. It allows execution of arbitrary commands via the 'ar

9.8
CVE-2020-7628

umount through 1.1.6 is vulnerable to Command Injection. The argument device can be controlled by users without any sani

9.8
CVE-2020-7629

install-package through 0.4.0 is vulnerable to Command Injection. It allows execution of arbitrary commands via the opti

9.8
CVE-2020-7630

git-add-remote through 1.0.0 is vulnerable to Command Injection. It allows execution of arbitrary commands via the name

9.8
CVE-2020-7631

diskusage-ng through 0.2.4 is vulnerable to Command Injection.It allows execution of arbitrary commands via the path arg

9.8
CVE-2020-7632

node-mpv through 1.4.3 is vulnerable to Command Injection. It allows execution of arbitrary commands via the options arg

9.8
CVE-2020-7633

apiconnect-cli-plugins through 6.0.1 is vulnerable to Command Injection.It allows execution of arbitrary commands via th

9.8
CVE-2020-7634

heroku-addonpool through 0.1.15 is vulnerable to Command Injection.

9.8
CVE-2020-7635

compass-compile through 0.0.1 is vulnerable to Command Injection.It allows execution of arbitrary commands via tha optio

9.8
CVE-2020-7636

adb-driver through 0.1.8 is vulnerable to Command Injection.It allows execution of arbitrary commands via the command fu

9.8
CVE-2020-7614

npm-programmatic through 0.0.12 is vulnerable to Command Injection.The packages and option properties are concatenated t

9.8
CVE-2020-10511

HGiga C&Cmail CCMAILQ before olln-base-6.0-418.i386.rpm and CCMAILN before olln-base-5.0-418.i386.rpm contains insecure

9.8
CVE-2020-11963

IQrouter through 3.3.1, when unconfigured, has multiple remote code execution vulnerabilities in the web-panel because o

9.8
CVE-2018-21162

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D6400 before 1.0.

9.8
CVE-2020-5868

In BIG-IQ 6.0.0-7.0.0, a remote access vulnerability has been discovered that may allow a remote user to execute shell c

9.8
CVE-2020-7640

pixl-class prior to 1.0.3 allows execution of arbitrary commands. The members argument of the create function can be con

9.8
CVE-2017-18858

Certain NETGEAR devices are affected by command execution. This affects M4200-10MG-POE+ 12.0.2.11 and earlier, M4300-28G

9.8
CVE-2016-11061

Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, and 7970i devices b

9.8
CVE-2019-5623

Accellion File Transfer Appliance version FTA_8_0_540 suffers from an instance of CWE-77: Improper Neutralization of Spe

9.8
CVE-2020-7645

All versions of chrome-launcher allow execution of arbitrary commands, by controlling the $HOME environment variable in

9.8
CVE-2020-12641 KEV

rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in

9.8
CVE-2020-7646

curlrequest through 1.0.1 allows reading any file by populating the file parameter with user input.

9.8
CVE-2020-7805

An issue was discovered on KT Slim egg IML500 (R7283, R8112, R8424) and IML520 (R8112, R8368, R8411) wifi device. This i

9.8
CVE-2020-13167

Netsweeper through 6.4.3 allows unauthenticated remote code execution because webadmin/tools/unixlogin.php (with certain

9.8
CVE-2020-13388

An exploitable vulnerability exists in the configuration-loading functionality of the jw.util package before 2.3 for Pyt

9.8
CVE-2020-8171

We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilitie

9.8
CVE-2014-7173

FarLinX X25 Gateway through 2014-09-25 allows command injection via shell metacharacters to sysSaveMonitorData.php, fsx2

9.8
CVE-2014-8945

admin.php?page=projects in Lexiglot through 2014-11-20 allows command injection via username and password fields.

9.8
CVE-2020-4469

IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to execute arbitrary code on the system. B

9.8
CVE-2020-13159

Artica Proxy before 4.30.000000 Community Edition allows OS command injection via the Netbios name, Server domain name,

9.8
CVE-2020-14072

An issue was discovered in MK-AUTH 19.01. It allows command execution as root via shell metacharacters to /auth admin sc

9.8
CVE-2020-15362

wifiscanner.js in thingsSDK WiFi Scanner 1.0.1 allows Code Injection because it can be used with options to overwrite th

9.8
CVE-2020-15415 KEV

On DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote

9.8
CVE-2020-13619

php/exec/escapeshellarg in Locutus PHP through 2.0.11 allows an attacker to achieve code execution.

9.8
CVE-2019-15310

An issue was discovered on various devices via the Linkplay firmware. There is WAN remote code execution without user in

9.8
CVE-2019-15311

An issue was discovered on Zolo Halo devices via the Linkplay firmware. There is Zolo Halo LAN remote code execution. Th

9.8
CVE-2020-15489

An issue was discovered on Wavlink WL-WN530HG4 M30HG4.V5030.191116 devices. Multiple shell metacharacter injection vulne

Frequently Asked Questions

What is CWE-78?

CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-78?

There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.

How can I protect against CWE-78 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.

Detect CWE-78 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.

Get Started