CWE-78
MITRE ↗Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)
A security flaw has been discovered in Tenda HG3 2.0 300003070. This vulnerability affects the function formgponConf of
A vulnerability was detected in Tenda HG3 2.0. The impacted element is an unknown function of the file /boaform/formCoun
Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILG
HKUDS OpenHarness contains a remote code execution vulnerability in the /bridge slash command that allows remote senders
OS command injection vulnerability in the ping diagnostic handler in /bin/httpd_clientside in ALTICE LABS / SFR France G
OS command injection vulnerability in the traceroute diagnostic handler in /bin/httpd_clientside in ALTICE LABS / SFR Fr
NPM package node-ts-ocr 1.0.15 is vulnerable to OS Command Injection via the invokeImageOcr function in src/index.js.
GitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitP
OpenLearnX is an open-source, decentralized learning and assessment platform. Prior to version 2.0.3, a remote code exec
LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before vers
OS command injection (CWE-78) vulnerability in pgAdmin 4 Import/Export query export. User-supplied input was interpolat
** UNSUPPORTED WHEN ASSIGNED ** A command injection vulnerability in the CGI program of Zyxel WRE6505 v2 firmware versio
Session fixation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
A potential vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remote authentic
Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.233, Tabby registers itself as the ha
A command injection vulnerability exists in the /cgi-bin/tools/ajax_cmd endpoint of Panabit PAP-XM320 up to and includin
Tanium addressed an unauthorized code execution vulnerability in Connect.
@pensar/apex <= 0.0.58 is vulnerable to OS command injection via the smart_enumerate tool. The createSmartEnumerateTool(
BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.
BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.
pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, src/tmux.c reads the
Tanium addressed an unauthorized code execution vulnerability in Connect.
WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a classic shell-metacharacter injection. The
Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.0 and earlier, the deleteRegistry function in Dok
The system fails to evaluate instructional permissions over multiple internal operation codes (opcodes), permitting unau
HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API. An att
Markdown Preview Enhanced before 0.8.28 opens external files and links from the preview through a shell and does not val
OpenBullet2 through version 0.3.2 contains a remote code execution vulnerability that allows authenticated users to exec
A security flaw has been discovered in Tenda F451 1.0.0.7/1.0.0.9. Impacted is the function formWriteFacMac of the file
Versions of the package degit before 2.8.6, from 3.0.0 and before 3.3.1 are vulnerable to Command Injection due to impro
A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The application does not properly s
Hermes WebUI before version 0.51.311 contains a remote code execution vulnerability that allows authenticated attackers
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, PO
Due to incomplete input validation in Idira Privileged Session Manager for SSH (PSMP) versions prior to 15.0.2, 14.6.3,
Improper input validation in the SSH Elevate Shell feature allows an authenticated user with permission to create or mo
Due to the improper neutralization of special elements used in a name parameter a low privileged remote attacker can exp
Passing of unsanitized strings from DHCP replies into the wicked dhcp client before wicked 0.6.79 could be used by attac
NetComm NF20MESH routers running firmware R6B031 and earlier contain an authenticated remote code execution vulnerabilit
Warp is an agentic development environment. From 0.2023.03.21.08.02.stable_00 until 0.2026.05.06.15.42.stable_01, Warp c
Unraid Web Server FileUpload Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote att
Unraid Web Server ToggleState Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote at
Quest NetVault Backup NVBULogDaemon Command Injection Remote Code Execution Vulnerability. This vulnerability allows rem
OS Command Injection vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to execut
Cudy LT300 3.0 running firmware prior to version 2.5.12 contains an OS command injection vulnerability that allows authe
A vulnerability has been found in D-Link DCS-935L 1.10.01. This affects the function sub_400E40 of the file setconf.cgi
Claude Code is an agentic coding tool. From 2.1.38 until 2.1.163, Claude Code's worktree handling allowed creation of w
luci-app-tailscale-community contains a command injection vulnerability in the tailscale.do_login RPC method that allows
luci-proto-openvpn through 0.11.1, fixed in commit e4ff45e, contains a command injection vulnerability in the generateKe
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.
Frequently Asked Questions
What is CWE-78?
CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-78?
There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.
How can I protect against CWE-78 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.
Detect CWE-78 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.
Get Started