CWE-78
MITRE ↗Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)
diag_ping.cmd on D-Link DSL-2640U devices with firmware IM_1.00 and ME_1.00, and DSL-2540U devices with firmware ME_1.00
A vulnerability in the web management GUI of the Cisco D9800 Network Transport Receiver could allow an authenticated, re
pfSense before 2.3 allows remote authenticated users to execute arbitrary OS commands via a '|' character in the status_
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of NetGain Systems Ente
Users with permission to create or configure agents in Jenkins 1.37 and earlier could configure an EC2 agent to run arbi
GitHub Electron versions 1.8.2-beta.3 and earlier, 1.7.10 and earlier, 1.6.15 and earlier has a vulnerability in the pro
Jenkins 2.73.1 and earlier, 2.83 and earlier users with permission to create or configure agents in Jenkins could config
iBall iB-WRA150N 1.2.6 build 110401 Rel.47776n devices allow remote authenticated users to execute arbitrary OS commands
OpenEMR version 5.0.0 contains a OS Command Injection vulnerability in fax_dispatch.php that can result in OS command in
Ruckus Networks Unleashed AP firmware releases before 200.6.10.1.x and Ruckus Networks Zone Director firmware releases 1
Ruckus Networks Solo APs firmware releases R110.x or before and Ruckus Networks SZ managed APs firmware releases R5.x or
trixbox 2.8.0.4 has OS command injection via shell metacharacters in the lang parameter to /maint/modules/home/index.php
The "go get" implementation in Go 1.9.4, when the -insecure command-line option is used, does not validate the import pa
IBM BigFix Platform 9.0, 9.1 before 9.1.8, and 9.2 before 9.2.8 allow remote authenticated users to execute arbitrary co
Vesta Control Panel before 0.9.8-14 allows remote authenticated users to execute arbitrary commands via shell metacharac
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Amazon Music Player
Github Electron version Electron 1.8.2-beta.4 and earlier contains a Command Injection vulnerability in Protocol Handler
Buffalo WXR-1900DHP2 firmware Ver.2.48 and earlier allows an attacker to execute arbitrary OS commands via unspecified v
Buffalo WZR-1750DHP2 Ver.2.30 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.
Remote command execution (RCE) vulnerability in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker to execut
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Spotify Music Player
On D-Link DCS-5009 devices with firmware 1.08.11 and earlier, DCS-5010 devices with firmware 1.14.09 and earlier, and DC
In Vecna VGo Robot versions prior to 3.0.3.52164, an attacker on an adjacent network could perform command injection.
An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 1703031
An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 1703031
An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 1703031
An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 1703031
An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 1703031
An exploitable command injection vulnerability exists in the web server functionality of Moxa EDR-810 V4.1 build 1703031
A vulnerability in the Secure Copy Protocol (SCP) server of Cisco Enterprise NFV Infrastructure Software (NFVIS) could a
On D-Link DIR-550A and DIR-604M devices through v2.10KR, a malicious user can forge an HTTP request to inject operating
A command injection remote command execution vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a rem
In order to perform actions that require higher privileges, the Quest KACE System Management Appliance 8.0.318 relies on
The '/common/ajax_email_connection_test.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 2 of 46).
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 3 of 46).
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 4 of 46).
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 5 of 46).
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 6 of 46).
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 7 of 46).
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 8 of 46).
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 10 of 46).
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 11 of 46).
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 12 of 46).
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 13 of 46).
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 14 of 46).
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 15 of 46).
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 16 of 46).
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 17 of 46).
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 18 of 46).
Frequently Asked Questions
What is CWE-78?
CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-78?
There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.
How can I protect against CWE-78 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.
Detect CWE-78 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.
Get Started