CWE-78
MITRE ↗Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)
A command injection vulnerability in the `devcert` module may lead to remote code execution when users of the module pas
The goform/setUsbUnload endpoint of Tenda AC15 AC1900 version 15.03.05.19 allows remote attackers to execute arbitrary s
Similar to CVE-2020-1956, Kylin has one more restful API which concatenates the API inputs into OS commands and then exe
Insufficient input validation in npm package `jison` <= 0.4.18 may lead to OS command injection attacks.
An issue was found in Apache Airflow versions 1.10.10 and below. When using CeleryExecutor, if an attacker can connect t
Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via HTTP. An authe
Grandstream UCM6200 series firmware version 1.0.20.23 and below is vulnerable to OS command injection via SSH. An authen
HP nagios plugin for iLO (nagios-plugins-hpilo v1.50 and earlier) has a php code injection vulnerability.
An issue was discovered on D-Link DIR-816L devices 2.x before 1.10b04Beta02. Universal Plug and Play (UPnP) is enabled b
goform/AdvSetLanip endpoint on Tenda AC15 AC1900 15.03.05.19 devices allows remote attackers to execute arbitrary system
The WebControl in RaspberryTortoise through 2012-10-28 is vulnerable to remote code execution via shell metacharacters i
There is an OS Command Injection in Mida eFramework through 2.9.0 that allows an attacker to achieve Remote Code Executi
There is an OS Command Injection in Mida eFramework 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE)
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e
Aerospike Community Edition 4.9.0.5 allows for unauthenticated submission and execution of user-defined functions (UDFs)
Firejail through 0.9.62 mishandles shell metacharacters during use of the --output or --output-stderr option, which may
The Web portal of the WiFi module of VPNCrypt M10 2.6.5 allows command injection via a text field, which allow full cont
tz.pl on XoruX LPAR2RRD and STOR2RRD 2.70 virtual appliances allows cmd=set&tz=OS command injection via shell metacharac
SEOWON INTECH SLC-130 And SLR-120S devices allow Remote Code Execution via the ipAddr parameter to the system_log.cgi pa
The Kommbox component in Rangee GmbH RangeeOS 8.0.4 is vulnerable to Remote Code Execution due to untrusted user supplie
The administration console of the Moog EXO Series EXVF5C-2 and EXVP7C2-3 units features a 'statusbroadcast' command that
Rebar3 versions 3.0.0-beta.3 to 3.13.2 are vulnerable to OS command injection via URL parameter of dependency specificat
The package bestzip before 2.1.7 are vulnerable to Command Injection via the options param.
CGI implementation in Yaws web server versions 1.81 to 2.0.7 is vulnerable to OS command injection.
The login page in Telmat AccessLog <= 6.0 (TAL_20180415) allows an attacker to get root shell access via Unauthenticated
Frequently Asked Questions
What is CWE-78?
CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-78?
There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.
How can I protect against CWE-78 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.
Detect CWE-78 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.
Get Started