Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)

1,941
CRITICAL
3,146
HIGH
963
MEDIUM
16
LOW
6,290 CVEs · Page 108/126
7.2
CVE-2020-16148

The ping page of the administration panel in Telmat AccessLog <= 6.0 (TAL_20180415) allows an attacker to get root shell

7.2
CVE-2020-14144

The git hook feature in Gitea 1.1.0 through 1.12.5 might allow for authenticated remote code execution in customer envir

7.2
CVE-2020-5791

Improper neutralization of special elements used in an OS command in Nagios XI 5.7.3 allows a remote, authenticated admi

7.2
CVE-2020-2000

An OS command injection and memory corruption vulnerability in the PAN-OS management web interface that allows authentic

7.2
CVE-2020-2490

If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue

7.2
CVE-2020-2492

If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue

7.2
CVE-2020-28580

A command injection vulnerability in AddVLANItem of Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could a

7.2
CVE-2020-28581

A command injection vulnerability in ModifyVLANItem of Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 coul

7.1
CVE-2020-1602

When a device using Juniper Network's Dynamic Host Configuration Protocol Daemon (JDHCPD) process on Junos OS or Junos O

6.8
CVE-2019-20348

OKER G232V1 v1.03.02.20161129 devices provide a root terminal on a UART serial interface without proper access control.

6.8
CVE-2019-20050

Pandora FMS ≤ 7.42 suffers from a remote code execution vulnerability. To exploit the vulnerability, an authenticated us

6.8
CVE-2018-21103

NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user.

6.8
CVE-2018-21104

NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user.

6.8
CVE-2018-21105

NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user.

6.8
CVE-2018-21106

NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user.

6.8
CVE-2018-21107

NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user.

6.8
CVE-2018-21108

NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user.

6.8
CVE-2018-21109

NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user.

6.8
CVE-2018-21110

NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user.

6.8
CVE-2018-21098

NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user.

6.8
CVE-2018-21152

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.34,

6.8
CVE-2018-21154

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.34,

6.8
CVE-2018-21157

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.28,

6.8
CVE-2018-21225

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7000 before 1.0.1.60,

6.8
CVE-2020-3417

A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker to execute persistent code at boot

6.8
CVE-2020-12148

A command injection flaw identified in the nslookup API in Silver Peak Unity ECOSTM (ECOS) appliance software could allo

6.8
CVE-2020-12149

The configuration backup/restore function in Silver Peak Unity ECOSTM (ECOS) appliance software was found to directly in

6.8
CVE-2020-5636

Aterm SA3500G firmware versions prior to Ver. 3.5.9 allows an attacker with an administrative privilege to send a specia

6.8
CVE-2020-26259

XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, is vulnerable to

6.7
CVE-2020-3169

A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to execute arbitrary comm

6.7
CVE-2020-3176

A vulnerability in Cisco Remote PHY Device Software could allow an authenticated, local attacker to execute commands on

6.7
CVE-2019-15708

A system command injection vulnerability in the FortiAP-S/W2 6.2.1, 6.2.0, 6.0.5 and below, FortiAP 6.0.5 and below and

6.7
CVE-2020-8797

Juplink RX4-1500 v1.0.3 allows remote attackers to gain root access to the Linux subsystem via an unsanitized exec call

6.7
CVE-2020-3207

A vulnerability in the processing of boot options of specific Cisco IOS XE Software switches could allow an authenticate

6.7
CVE-2020-3210

A vulnerability in the CLI parsers of Cisco IOS Software for Cisco 809 and 829 Industrial Integrated Services Routers (I

6.7
CVE-2020-11733

An issue was discovered on Spirent TestCenter and Avalanche appliance admin interface firmware. An attacker, who already

6.7
CVE-2020-25859

The QCMAP_CLI utility in the Qualcomm QCMAP software suite prior to versions released in October 2020 uses a system() ca

6.7
CVE-2020-3457

A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to inject arbitrary comma

6.6
CVE-2020-7735

The package ng-packagr before 10.1.1 are vulnerable to Command Injection via the styleIncludePaths option.

6.4
CVE-2020-8130

There is an OS command injection vulnerability in Ruby Rake < 12.3.3 in Rake::FileList when supplying a filename that be

6.4
CVE-2020-7804

ActiveX Control(HShell.dll) in Handy Groupware 1.7.3.1 for Windows 7, 8, and 10 allows an attacker to execute arbitrary

6.4
CVE-2020-11084

In iPear, the manual execution of the eval() function can lead to command injection. Only PCs where commands are manuall

6.4
CVE-2020-26274

In systeminformation (npm package) before version 4.31.1 there is a command injection vulnerability. The problem was fix

6.3
CVE-2020-3377

A vulnerability in the Device Manager application of Cisco Data Center Network Manager (DCNM) could allow an authenticat

6.3
CVE-2020-3602

A vulnerability in the CLI of Cisco StarOS operating system for Cisco ASR 5000 Series Routers could allow an authenticat

6.3
CVE-2020-3371

A vulnerability in the web UI of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attac

6.1
CVE-2020-7350

Rapid7 Metasploit Framework versions before 5.0.85 suffers from an instance of CWE-78: OS Command Injection, wherein the

5.6
CVE-2020-7789

This affects the package node-notifier before 9.0.0. It allows an attacker to run arbitrary commands on Linux machines d

5.5
CVE-2020-24552

Atop Technology industrial 3G/4G gateway contains Command Injection vulnerability. Due to insufficient input validation,

5.3
CVE-2019-20807

In Vim before 8.1.0881, users can circumvent the rvim restricted mode and execute arbitrary OS commands via scripting in

Frequently Asked Questions

What is CWE-78?

CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-78?

There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.

How can I protect against CWE-78 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.

Detect CWE-78 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.

Get Started