CWE-78
MITRE ↗Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)
An exploitable code execution vulnerability exists in the connect functionality of NordVPN 6.14.28.0. A specially crafte
Linksys Velop 1.1.2.187020 devices allow unauthenticated command injection, providing an attacker with full root access,
A command injection vulnerability in the web server functionality of Moxa EDR-810 V4.2 build 18041013 allows remote atta
LINK-NET LW-N605R devices with firmware 12.20.2.1486 allow Remote Code Execution via shell metacharacters in the HOST fi
An authenticated command injection vulnerability exists in status_interfaces.php via dhcp_relinquish_lease() in pfSense
A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless
A vulnerability in the error reporting feature of the Cisco SD-WAN Solution could allow an authenticated, remote attacke
An issue was discovered on D-Link DWR-116 through 1.06, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02
An authenticated command injection vulnerability exists in IPFire Firewall before 2.21 Core Update 124 in backup.cgi. Th
Nagios XI 5.5.6 allows remote authenticated attackers to execute arbitrary commands via a crafted HTTP request.
Nagios XI 5.5.6 allows remote authenticated attackers to reset and regenerate the API key of more privileged users. The
System command injection vulnerability in wifi_access in Xiaomi Mi Router 3 version 2.22.15 allows attackers to execute
A system command injection vulnerability in zyshclient in ZyXEL NSA325 V2 version 4.81 allows attackers to execute syste
System command injection in request_mitv in Xiaomi Mi Router 3 version 2.22.15 allows attackers to execute arbitrary sys
System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute commands via the
System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands v
System command injection in ajaxdata.php in TerraMaster TOS 3.1.03 allows attackers to execute system commands via the "
NUUO NVRMini2 version 3.9.1 is vulnerable to authenticated remote command injection. An attacker can send crafted reques
OS command injection in user.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root via th
OS command injection in user.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root via th
OS Command Injection in upload.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands by modifying
OS command injection in group.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root by mo
A Server-Side Template Injection issue was discovered in Crafter CMS 3.0.18. Attackers with developer privileges may exe
An issue was discovered in MISP 2.4.9x before 2.4.99. In app/Model/Event.php (the STIX 1 import code), an unescaped file
An exploitable authenticated command-injection vulnerability exists in the web server functionality of Moxa NPort W2x50A
An exploitable authenticated command-injection vulnerability exists in the web server functionality of Moxa NPort W2x50A
An issue was discovered in /bin/boa on D-Link DIR-619L Rev.B 2.06B1 and DIR-605L Rev.B 2.12B1 devices. goform/formSysCmd
A vulnerability in the Sourcefire tunnel control channel protocol in Cisco Firepower System Software running on Cisco Fi
In the web ui of the openbuildservice before 2.3.0 a code injection of the project rebuildtimes statistics could be used
VMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web U
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when joining a PersonalCloud setup, a
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when changing the name of a share, an
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when changing the name of a share, an
A command injection vulnerability in the setup API in the Neato Botvac Connected 2.2.0 allows network attackers to execu
The Logitech Harmony Hub before version 4.15.206 is vulnerable to OS command injection via the time update request. A re
The remote upgrade feature in Guardzilla GZ180 devices allow command injection via a crafted new firmware version parame
An exploitable code execution vulnerability exists in the cloud OTA setup functionality of Yi Home Camera 27US 1.8.7.0D.
Linux Dash up to version v2 is vulnerable to multiple command injection vulnerabilities in the way module names are pars
spice-vdagent up to and including 0.17.0 does not properly escape save directory before passing to shell, allowing local
The Python console in Electrum through 2.9.4 and 3.x through 3.0.5 supports arbitrary Python code without considering (1
A shell command injection in the obs-service-source_validator before 0.7 could be used to execute code as the packager w
Arbitrary logs location in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to change location of log fi
Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to gain
Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to gain
Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to inje
Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to inje
Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to inje
Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to inje
An exploitable command injection vulnerability exists in the gplotMakeOutput function of Leptonica 1.74.4. A specially c
Privilege Escalation vulnerability in McAfee Management of Native Encryption (MNE) before 4.1.4 allows local users to ga
Frequently Asked Questions
What is CWE-78?
CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-78?
There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.
How can I protect against CWE-78 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.
Detect CWE-78 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.
Get Started