CWE-78
MITRE ↗Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)
Jenkins Perfecto Plugin 1.17 and earlier executes a command on the Jenkins controller, allowing attackers with Job/Confi
Jenkins Selection tasks Plugin 1.0 and earlier executes a user-specified program on the Jenkins controller, allowing att
An issue was discovered in Titan SpamTitan 7.07. Improper validation of the parameter fname on the page certs-x.php woul
An issue was discovered on Gemtek WRTM-127ACN 01.01.02.141 and WRTM-127x9 01.01.02.127 devices. The Monitor Diagnostic n
D-Link DAP-1360U before 3.0.1 devices allow remote authenticated users to execute arbitrary commands via shell metachara
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microhard Bullet-LTE p
rConfig 3.9.4 and earlier allows authenticated code execution (of system commands) by sending a forged GET request to li
This affects the package systeminformation before 4.27.11. This package is vulnerable to Command Injection. The attacker
Ruckus through 1.5.1.0.21 is affected by remote command injection. An authenticated user can submit a query to the API (
An issue was discovered in EyesOfNetwork 5.3 through 5.3-8. An authenticated web user with sufficient privileges could a
MailGates and MailAudit products contain Command Injection flaw, which can be used to inject and execute system commands
A remote code execution vulnerability is identified in FruityWifi through 2.4. Due to improperly escaped shell metachara
An unprivileged Windows user on the VDA or an SMB user can perform arbitrary command execution as SYSTEM in CVAD version
Privilege escalation of an authenticated user to root in Citrix SD-WAN center versions before 11.2.2, 11.1.2b and 10.2.8
httpd on TP-Link TL-WPA4220 devices (versions 2 through 4) allows remote authenticated users to execute arbitrary OS com
TOTOLINK A3002RU-V2.0.0 B20190814.1034 allows authenticated remote users to modify the system's 'Run Command'. An attack
Aterm SA3500G firmware versions prior to Ver. 3.5.9 allows an attacker on the adjacent network to send a specially craft
A lack of input validation and access controls in Lua CGIs on D-Link DSR VPN routers may result in arbitrary input being
An issue was discovered on D-Link DSR-250 3.17 devices. Certain functionality in the Unified Services Router web interfa
An issue was discovered in SolarWinds N-Central 12.3.0.670. The sudo configuration has incorrect access control because
AdRem NetCrunch 10.6.0.4587 allows Remote Code Execution. In the NetCrunch web client, a read-only administrator can exe
Arbitrary command execution can occur in Webmin through 1.962. Any user authorized for the Package Updates module can ex
Belkin LINKSYS RE6500 devices before 1.0.11.001 allow remote authenticated users to execute arbitrary commands via gofor
Belkin LINKSYS RE6500 devices before 1.0.012.001 allow remote authenticated users to execute arbitrary commands via shel
This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP h
NETGEAR NMS300 devices before 1.6.0.27 are affected by command injection by an authenticated user.
DrayTek Vigor2960 1.5.1 allows remote command execution via shell metacharacters in a toLogin2FA action to mainfunction.
In the git-tag-annotation-action (open source GitHub Action) before version 1.0.1, an attacker can execute arbitrary (*)
The issue occurs because tagName user input is formatted inside the exec function is executed without any checks.
compile-sass prior to 1.0.5 allows execution of arbritary commands. The function "setupCleanupOnExit(cssPath)" within "d
D-Link DSL-7740C does not properly validate user input, which allows an authenticated LAN user to inject arbitrary comma
A command injection vulnerability has been discovered in the bootstrap stage of Bitdefender BOX 2, versions 2.1.47.42 an
A command execution issue was found in Apache SpamAssassin prior to 3.4.3. Carefully crafted nefarious rule configuratio
A command execution issue was found in Apache SpamAssassin prior to 3.4.3. Carefully crafted nefarious Configuration (.c
An issue was discovered in ASUSTOR exFAT Driver through 1.0.0.r20. When conducting license validation, exfat.cgi and exf
An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed
clamscan through 1.2.0 is vulnerable to Command Injection. It is possible to inject arbitrary commands as part of the `_
An OS Command Injection vulnerability in the PAN-OS GlobalProtect portal allows an unauthenticated network based attacke
This affects the package Gerapy from 0 and before 0.9.3. The input being passed to Popen, via the project_configure endp
npm package systeminformation before version 4.30.5 is vulnerable to Prototype Pollution leading to Command Injection. T
Command Injection in the CPE WAN Management Protocol (CWMP) registration in Amino Communications AK45x series, AK5xx ser
HGiga MailSherlock does not validate specific parameters properly. Attackers can use the vulnerability to launch Command
Aterm series (Aterm WF1200C firmware Ver1.2.1 and earlier, Aterm WG1200CR firmware Ver1.2.1 and earlier, Aterm WG2600HS
Aterm WG2600HS firmware Ver1.3.2 and earlier allows an authenticated attacker on the same network segment to execute arb
NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user.
NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user.
NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user.
A flaw was found in the CloudForms management engine version 5.10 and CloudForms management version 5.11, which triggere
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1
XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to ru
Frequently Asked Questions
What is CWE-78?
CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-78?
There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.
How can I protect against CWE-78 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.
Detect CWE-78 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.
Get Started