CWE-78
MITRE ↗Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)
Shihonkanri Plus GOOUT Ver1.5.8 and Ver2.2.10 allows remote attackers to execute arbitrary OS commands via unspecified v
WL-Enq 1.11 and 1.12 allows remote attackers to execute arbitrary OS commands with the administrative privilege via unsp
Keijiban Tsumiki v1.15 allows remote attackers to execute arbitrary OS commands via unspecified vectors.
openITCOCKPIT before 3.7.3 has a web-based terminal that allows attackers to execute arbitrary OS commands via shell met
This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firm
X-Plane before 11.41 has multiple improper path validations that could allow reading and writing files from/to arbitrary
get-git-data through 1.3.1 is vulnerable to Command Injection. It is possible to inject arbitrary commands as part of th
pomelo-monitor through 0.3.7 is vulnerable to Command Injection.It allows injection of arbitrary commands as part of 'po
strong-nginx-controller through 1.0.2 is vulnerable to Command Injection. It allows execution of arbitrary command as pa
jscover through 1.0.0 is vulnerable to Command Injection. It allows execution of arbitrary command via the source argume
effect through 1.0.4 is vulnerable to Command Injection. It allows execution of arbitrary command via the options argume
op-browser through 1.0.6 is vulnerable to Command Injection. It allows execution of arbitrary commands via the url funct
karma-mojo through 1.0.1 is vulnerable to Command Injection. It allows execution of arbitrary commands via the config ar
node-key-sender through 1.0.11 is vulnerable to Command Injection. It allows execution of arbitrary commands via the 'ar
umount through 1.1.6 is vulnerable to Command Injection. The argument device can be controlled by users without any sani
install-package through 0.4.0 is vulnerable to Command Injection. It allows execution of arbitrary commands via the opti
git-add-remote through 1.0.0 is vulnerable to Command Injection. It allows execution of arbitrary commands via the name
diskusage-ng through 0.2.4 is vulnerable to Command Injection.It allows execution of arbitrary commands via the path arg
node-mpv through 1.4.3 is vulnerable to Command Injection. It allows execution of arbitrary commands via the options arg
apiconnect-cli-plugins through 6.0.1 is vulnerable to Command Injection.It allows execution of arbitrary commands via th
heroku-addonpool through 0.1.15 is vulnerable to Command Injection.
compass-compile through 0.0.1 is vulnerable to Command Injection.It allows execution of arbitrary commands via tha optio
adb-driver through 0.1.8 is vulnerable to Command Injection.It allows execution of arbitrary commands via the command fu
npm-programmatic through 0.0.12 is vulnerable to Command Injection.The packages and option properties are concatenated t
HGiga C&Cmail CCMAILQ before olln-base-6.0-418.i386.rpm and CCMAILN before olln-base-5.0-418.i386.rpm contains insecure
IQrouter through 3.3.1, when unconfigured, has multiple remote code execution vulnerabilities in the web-panel because o
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D6400 before 1.0.
In BIG-IQ 6.0.0-7.0.0, a remote access vulnerability has been discovered that may allow a remote user to execute shell c
pixl-class prior to 1.0.3 allows execution of arbitrary commands. The members argument of the create function can be con
Certain NETGEAR devices are affected by command execution. This affects M4200-10MG-POE+ 12.0.2.11 and earlier, M4300-28G
Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, and 7970i devices b
Accellion File Transfer Appliance version FTA_8_0_540 suffers from an instance of CWE-77: Improper Neutralization of Spe
All versions of chrome-launcher allow execution of arbitrary commands, by controlling the $HOME environment variable in
rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in
curlrequest through 1.0.1 allows reading any file by populating the file parameter with user input.
An issue was discovered on KT Slim egg IML500 (R7283, R8112, R8424) and IML520 (R8112, R8368, R8411) wifi device. This i
Netsweeper through 6.4.3 allows unauthenticated remote code execution because webadmin/tools/unixlogin.php (with certain
An exploitable vulnerability exists in the configuration-loading functionality of the jw.util package before 2.3 for Pyt
We have recently released new version of AirMax AirOS firmware v6.3.0 for TI, XW and XM boards that fixes vulnerabilitie
FarLinX X25 Gateway through 2014-09-25 allows command injection via shell metacharacters to sysSaveMonitorData.php, fsx2
admin.php?page=projects in Lexiglot through 2014-11-20 allows command injection via username and password fields.
IBM Spectrum Protect Plus 10.1.0 through 10.1.5 could allow a remote attacker to execute arbitrary code on the system. B
Artica Proxy before 4.30.000000 Community Edition allows OS command injection via the Netbios name, Server domain name,
An issue was discovered in MK-AUTH 19.01. It allows command execution as root via shell metacharacters to /auth admin sc
wifiscanner.js in thingsSDK WiFi Scanner 1.0.1 allows Code Injection because it can be used with options to overwrite th
On DrayTek Vigor3900, Vigor2960, and Vigor300B devices before 1.5.1, cgi-bin/mainfunction.cgi/cvmcfgupload allows remote
php/exec/escapeshellarg in Locutus PHP through 2.0.11 allows an attacker to achieve code execution.
An issue was discovered on various devices via the Linkplay firmware. There is WAN remote code execution without user in
An issue was discovered on Zolo Halo devices via the Linkplay firmware. There is Zolo Halo LAN remote code execution. Th
An issue was discovered on Wavlink WL-WN530HG4 M30HG4.V5030.191116 devices. Multiple shell metacharacter injection vulne
Frequently Asked Questions
What is CWE-78?
CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-78?
There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.
How can I protect against CWE-78 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.
Detect CWE-78 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.
Get Started