Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)

1,941
CRITICAL
3,146
HIGH
963
MEDIUM
16
LOW
6,290 CVEs · Page 120/126
8.8
CVE-2018-11161

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 19 of 46).

8.8
CVE-2018-11162

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 20 of 46).

8.8
CVE-2018-11164

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 22 of 46).

8.8
CVE-2018-11165

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 23 of 46).

8.8
CVE-2018-11166

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 24 of 46).

8.8
CVE-2018-11167

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 25 of 46).

8.8
CVE-2018-11168

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 26 of 46).

8.8
CVE-2018-11169

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 27 of 46).

8.8
CVE-2018-11170

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 28 of 46).

8.8
CVE-2018-11171

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 29 of 46).

8.8
CVE-2018-11172

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 30 of 46).

8.8
CVE-2018-11173

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 31 of 46).

8.8
CVE-2018-11174

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 32 of 46).

8.8
CVE-2018-11175

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 33 of 46).

8.8
CVE-2018-11176

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 34 of 46).

8.8
CVE-2018-11177

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 35 of 46).

8.8
CVE-2018-11178

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 36 of 46).

8.8
CVE-2018-11179

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 37 of 46).

8.8
CVE-2018-11180

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 38 of 46).

8.8
CVE-2018-11181

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 39 of 46).

8.8
CVE-2018-11182

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 40 of 46).

8.8
CVE-2018-11183

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 41 of 46).

8.8
CVE-2018-11185

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 43 of 46).

8.8
CVE-2018-11186

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 44 of 46).

8.8
CVE-2018-11187

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 45 of 46).

8.8
CVE-2018-11188

Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 46 of 46).

8.8
CVE-2018-11189

Quest DR Series Disk Backup software version before 4.0.3.1 allows privilege escalation (issue 1 of 6).

8.8
CVE-2018-0274

A vulnerability in the CLI parser of Cisco Network Services Orchestrator (NSO) could allow an authenticated, remote atta

8.8
CVE-2018-0293

A vulnerability in role-based access control (RBAC) for Cisco NX-OS Software could allow an authenticated, remote attack

8.8
CVE-2018-0330

A vulnerability in the NX-API management application programming interface (API) in devices running, or based on, Cisco

8.8
CVE-2018-12692

TP-Link TL-WA850RE Wi-Fi Range Extender with hardware version 5 allows remote authenticated users to execute arbitrary c

8.8
CVE-2018-0569

baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote authenticated attac

8.8
CVE-2018-12577

The Ping and Traceroute features on TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 180119 Rel.65243n devices al

8.8
CVE-2018-0341

A vulnerability in the web-based UI of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware before 11.

8.8
CVE-2018-0708

Command injection vulnerability in networking of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allo

8.8
CVE-2018-0709

Command injection vulnerability in date of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow auth

8.8
CVE-2018-0710

Command injection vulnerability in SSH of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authe

8.8
CVE-2018-12483

OCS Inventory 2.4.1 is prone to a remote command-execution vulnerability. Specifically, this issue occurs because the co

8.8
CVE-2018-15153

OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute a

8.8
CVE-2018-15154

OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute a

8.8
CVE-2018-15155

OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute a

8.8
CVE-2018-15156

OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute a

8.8
CVE-2018-0427

A vulnerability in the CronJob scheduler API of Cisco Digital Network Architecture (DNA) Center could allow an authentic

8.8
CVE-2018-15553

fileshare.cmd on Telus Actiontec T2200H T2200H-31.128L.03 devices allows OS Command Injection via shell metacharacters i

8.8
CVE-2018-15481

Improper input sanitization within the restricted administration shell on UCOPIA Wireless Appliance devices using firmwa

8.8
CVE-2018-15877

The Plainview Activity Monitor plugin before 20180826 for WordPress is vulnerable to OS command injection via shell meta

8.8
CVE-2018-15887

Main_Analysis_Content.asp in ASUS DSL-N12E_C1 1.1.2.3_345 is prone to Authenticated Remote Command Execution, which allo

8.8
CVE-2018-15529

A command injection vulnerability in maintenance.cgi in Mutiny "Monitoring Appliance" before 6.1.0-5263 allows authentic

8.8
CVE-2018-11616

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Tencent Foxmail 7.2.

8.8
CVE-2018-16334

An issue was discovered on Tenda AC9 V15.03.05.19(6318)_CN and AC10 V15.03.06.23_CN devices. The mac parameter in a POST

Frequently Asked Questions

What is CWE-78?

CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-78?

There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.

How can I protect against CWE-78 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.

Detect CWE-78 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.

Get Started