CWE-78
MITRE ↗Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)
A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511
A remote command-line injection vulnerability in the /cgi-bin/live_api.cgi endpoint of the WAVLINK WN530H4 M30H4.V5030.1
Addressed remote code execution vulnerability in reg_device.php due to insufficient validation of user input.in Western
Addressed remote code execution vulnerability in cgi_api.php that allowed escalation of privileges in Western Digital My
Addressed remote code execution vulnerability in DsdkProxy.php due to insufficient sanitization and insufficient validat
osCommerce Phoenix CE before 1.0.5.4 allows OS command injection remotely. Within admin/mail.php, a from POST parameter
Winston 1.5.4 devices are vulnerable to command injection via the API.
If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. QNAP has alre
An issue was discovered on Western Digital My Cloud NAS devices before 5.04.114. They allow remote code execution with r
If exploited, this command injection vulnerability could allow remote attackers to execute arbitrary commands. This issu
An issue was discovered in SaltStack Salt through 3002. Sending crafted web requests to the Salt API, with the SSH clien
tdpServer on TP-Link Archer A7 AC1750 devices before 201029 allows remote attackers to execute arbitrary code via the sl
Exposed Erlang Cookie could lead to Remote Command Execution (RCE) attack. Communication between Erlang nodes is done by
An issue was discovered on CDATA 72408A, 9008A, 9016A, 92408A, 92416A, 9288, 97016, 97024P, 97028P, 97042P, 97084P, 9716
An issue was discovered on V-SOL V1600D V2.03.69 and V2.03.57, V1600D4L V1.01.49, V1600D-MINI V1.01.48, V1600G1 V2.0.7 a
Zeroshell 3.9.3 contains a command injection vulnerability in the /cgi-bin/kerbynet StartSessionSubmit parameter that co
This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP h
iCMS 7 attackers to execute arbitrary OS commands via shell metacharacters in the DB_PREFIX parameter to install/install
iCMS 7.0.14 attackers to execute arbitrary OS commands via shell metacharacters in the DB_NAME parameter to install/inst
Ubilling v1.0.9 allows Remote Command Execution as Root user by executing a malicious command that is injected inside th
Network Analysis functionality in Askey AP5100W_Dual_SIG_1.01.097 and all prior versions allows remote attackers to exec
This affects all versions of package corenlp-js-prefab. The injection point is located in line 10 in 'index.js.' It depe
All versions of package corenlp-js-interface are vulnerable to Command Injection via the main function.
GateOne allows remote attackers to execute arbitrary commands via shell metacharacters in the port field when attempting
A remote code execution vulnerability occurs in OpenTSDB through 2.4.0 via command injection in the yrange parameter. Th
This affects the package connection-tester before 0.2.1. The injection point is located in line 15 in index.js. The foll
LogRhythm Platform Manager 7.4.9 allows Command Injection. To exploit this, an attacker can inject arbitrary program nam
A command injection vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2, with the improved pas
Xinuos (formerly SCO) Openserver v5 and v6 allows attackers to execute arbitrary commands via shell metacharacters in ou
An issue was discovered in URVE Build 24.03.2020. By using the _internal/pc/vpro.php?mac=0&ip=0&operation=0&usr=0&pass=0
An unauthenticated command-execution vulnerability exists in TerraMaster TOS through 4.2.06 via shell metacharacters in
Remote Command Execution (RCE) vulnerability in TerraMaster TOS <= 4.2.06 allow remote unauthenticated attackers to inje
Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote attackers to execute arbitrary commands or set a new passw
KLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter.
Cayin CMS suffers from an authenticated OS semi-blind command injection vulnerability using default credentials. This ca
The EasyCorp ZenTao Pro application suffers from an OS command injection vulnerability in its '/pro/repo-create.html' co
A vulnerability in the web-based management interface of Cisco DNA Spaces Connector could allow an unauthenticated, remo
In codecov (npm package) before version 3.7.1 the upload method has a command injection vulnerability. Clients of the co
In lookatme (python/pypi package) versions prior to 2.3.0, the package automatically loaded the built-in "terminal" and
IntelMQ Manager from version 1.1.0 and before version 2.1.1 has a vulnerability where the backend incorrectly handled me
IBM Data Risk Manager 2.0.1, 2.0.2, 2.0.3, and 2.0.4 could allow a remote authenticated attacker to execute arbitrary co
A high severity vulnerability was found in all active versions of Red Hat CloudForms before 5.11.7.0. The out of band OS
VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command i
SAP Business Warehouse, versions - 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 782, and SAP BW4HANA, versions
A OS Command Injection vulnerability in the bootstrap stage of Bitdefender BOX 2 allows the manipulation of the `get_ima
Bulb Security Smartphone Pentest Framework (SPF) before 0.1.3 allows remote attackers to execute arbitrary commands via
Access analysis CGI An-Analyzer released in 2019 June 24 and earlier allows remote authenticated attackers to execute ar
An issue was discovered in rConfig 3.9.3. A remote authenticated user can directly execute system commands by sending a
netflow_get_stats in functions_netflow.php in Pandora FMS 7.0NG allows remote authenticated users to execute arbitrary O
contentHostProperties.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows authenticated attackers t
Frequently Asked Questions
What is CWE-78?
CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-78?
There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.
How can I protect against CWE-78 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.
Detect CWE-78 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.
Get Started