Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)

1,941
CRITICAL
3,146
HIGH
963
MEDIUM
16
LOW
6,290 CVEs · Page 119/126
8.8
CVE-2018-5371

diag_ping.cmd on D-Link DSL-2640U devices with firmware IM_1.00 and ME_1.00, and DSL-2540U devices with firmware ME_1.00

8.8
CVE-2018-0099

A vulnerability in the web management GUI of the Cisco D9800 Network Transport Receiver could allow an authenticated, re

8.8
CVE-2016-10709

pfSense before 2.3 allows remote authenticated users to execute arbitrary OS commands via a '|' character in the status_

8.8
CVE-2017-16602

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of NetGain Systems Ente

8.8
CVE-2017-1000502

Users with permission to create or configure agents in Jenkins 1.37 and earlier could configure an EC2 agent to run arbi

8.8
CVE-2018-1000006

GitHub Electron versions 1.8.2-beta.3 and earlier, 1.7.10 and earlier, 1.6.15 and earlier has a vulnerability in the pro

8.8
CVE-2017-1000393

Jenkins 2.73.1 and earlier, 2.83 and earlier users with permission to create or configure agents in Jenkins could config

8.8
CVE-2018-6388

iBall iB-WRA150N 1.2.6 build 110401 Rel.47776n devices allow remote authenticated users to execute arbitrary OS commands

8.8
CVE-2018-1000019

OpenEMR version 5.0.0 contains a OS Command Injection vulnerability in fax_dispatch.php that can result in OS command in

8.8
CVE-2017-6229

Ruckus Networks Unleashed AP firmware releases before 200.6.10.1.x and Ruckus Networks Zone Director firmware releases 1

8.8
CVE-2017-6230

Ruckus Networks Solo APs firmware releases R110.x or before and Ruckus Networks SZ managed APs firmware releases R5.x or

8.8
CVE-2017-14535

trixbox 2.8.0.4 has OS command injection via shell metacharacters in the lang parameter to /maint/modules/home/index.php

8.8
CVE-2018-7187

The "go get" implementation in Go 1.9.4, when the -insecure command-line option is used, does not validate the import pa

8.8
CVE-2016-0291

IBM BigFix Platform 9.0, 9.1 before 9.1.8, and 9.2 before 9.2.8 allow remote authenticated users to execute arbitrary co

8.8
CVE-2015-4117

Vesta Control Panel before 0.9.8-14 allows remote authenticated users to execute arbitrary commands via shell metacharac

8.8
CVE-2018-1169

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Amazon Music Player

8.8
CVE-2018-1000118

Github Electron version Electron 1.8.2-beta.4 and earlier contains a Command Injection vulnerability in Protocol Handler

8.8
CVE-2018-0523

Buffalo WXR-1900DHP2 firmware Ver.2.48 and earlier allows an attacker to execute arbitrary OS commands via unspecified v

8.8
CVE-2018-0556

Buffalo WZR-1750DHP2 Ver.2.30 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.

8.8
CVE-2018-8735

Remote command execution (RCE) vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execut

8.8
CVE-2018-1167

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Spotify Music Player

8.8
CVE-2017-17020

On D-Link DCS-5009 devices with firmware 1.08.11 and earlier, DCS-5010 devices with firmware 1.14.09 and earlier, and DC

8.8
CVE-2018-8866

In Vecna VGo Robot versions prior to 3.0.3.52164, an attacker on an adjacent network could perform command injection.

8.8
CVE-2017-12120

An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 1703031

8.8
CVE-2017-12121

An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 1703031

8.8
CVE-2017-12125

An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 1703031

8.8
CVE-2017-14432

An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 1703031

8.8
CVE-2017-14433

An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 1703031

8.8
CVE-2017-14434

An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 1703031

8.8
CVE-2018-0279

A vulnerability in the Secure Copy Protocol (SCP) server of Cisco Enterprise NFV Infrastructure Software (NFVIS) could a

8.8
CVE-2018-10967

On D-Link DIR-550A and DIR-604M devices through v2.10KR, a malicious user can forge an HTTP request to inject operating

8.8
CVE-2018-10354

A command injection remote command execution vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a rem

8.8
CVE-2018-11132

In order to perform actions that require higher privileges, the Quest KACE System Management Appliance 8.0.318 relies on

8.8
CVE-2018-11139

The '/common/ajax_email_connection_test.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible

8.8
CVE-2018-11144

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 2 of 46).

8.8
CVE-2018-11145

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 3 of 46).

8.8
CVE-2018-11146

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 4 of 46).

8.8
CVE-2018-11147

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 5 of 46).

8.8
CVE-2018-11148

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 6 of 46).

8.8
CVE-2018-11149

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 7 of 46).

8.8
CVE-2018-11150

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 8 of 46).

8.8
CVE-2018-11152

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 10 of 46).

8.8
CVE-2018-11153

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 11 of 46).

8.8
CVE-2018-11154

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 12 of 46).

8.8
CVE-2018-11155

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 13 of 46).

8.8
CVE-2018-11156

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 14 of 46).

8.8
CVE-2018-11157

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 15 of 46).

8.8
CVE-2018-11158

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 16 of 46).

8.8
CVE-2018-11159

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 17 of 46).

8.8
CVE-2018-11160

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 18 of 46).

Frequently Asked Questions

What is CWE-78?

CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-78?

There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.

How can I protect against CWE-78 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.

Detect CWE-78 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.

Get Started