CWE-78
MITRE ↗Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)
The set_version script as shipped with obs-service-set_version is a source validator for the Open Build Service (OBS). I
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to perform a command-inj
A vulnerability in the CLI parser of Cisco NX-OS Software could allow an authenticated, local attacker to perform a comm
CloudForms Management Engine (cfme) is vulnerable to an improper security setting in the dRuby component of CloudForms.
Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privilege escalation attac
In conference-scheduler-cli, a pickle.load call on imported data allows remote attackers to execute arbitrary code via a
An exploitable code execution vulnerability exists in the connect functionality of ProtonVPN VPN client 1.5.1. A special
An issue was discovered in mgetty before 1.2.1. In fax/faxq-helper.c, the function do_activate() does not properly sanit
An issue was discovered in mgetty before 1.2.1. In fax_notify_mail() in faxrec.c, the mail_to parameter is not sanitized
A vulnerability in the command-line interface (CLI) in the Cisco SD-WAN Solution could allow an authenticated, local att
A vulnerability in the update service of Cisco Webex Meetings Desktop App for Windows could allow an authenticated, loca
Nagios XI 5.5.6 allows local authenticated attackers to escalate privileges to root via Autodiscover_new.php.
Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS.
Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS.
Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS.
Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS.
The Sky Elite 6.0L+ Android device with a build fingerprint of SKY/x6069_trx_l601_sky/x6069_trx_l601_sky:6.0/MRA58K/1482
Remote code execution vulnerability in /cmsms-2.1.6-install.php/index.php in CMS Made Simple version 2.1.6 allows remote
Dell EMC ScaleIO versions prior to 2.5, contain a command injection vulnerability in the Light Installation Agent (LIA).
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in
An issue was discovered on Dongguan Diqee Diqee360 devices. The affected vacuum cleaner suffers from an authenticated re
In System Management Module (SMM) versions prior to 1.06, a field in the header of SMM firmware update images is insuffi
In System Management Module (SMM) versions prior to 1.06, the SMM certificate creation and parsing logic is vulnerable t
Silex SD-320AN version 2.01 and prior and GE MobileLink(GEH-SD-320AN) version GEH-1.1 and prior have a system call param
It was found that RHSA-2018:2918 did not fully fix CVE-2018-16509. An attacker could possibly exploit another variant of
In app/Controller/ServersController.php in MISP 2.4.87, a server setting permitted the override of a path variable on ce
Arbitrary code execution vulnerability in Kentico 9 through 11 allows remote authenticated users to execute arbitrary op
D-Link DIR-615 2.5.17 devices allow Remote Code Execution via shell metacharacters in the Host field of the System / Tra
Dell EMC Unity Operating Environment (OE) versions prior to 4.3.0.1522077968 are affected by multiple OS command injecti
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 9 of 46).
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 21 of 46).
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 42 of 46).
Ubiquiti Networks EdgeSwitch version 1.7.3 and prior suffer from an improperly neutralized element in an OS command due
On D-Link DIR-620 devices with a certain customized (by ISP) variant of firmware 1.0.3, 1.0.37, 1.3.1, 1.3.3, 1.3.7, 1.4
A vulnerability has been identified in SCALANCE M875 (All versions). An authenticated remote attacker with access to the
A vulnerability has been identified in SCALANCE M875 (All versions). An authenticated remote attacker with access to the
An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administra
The setSystemTime function in Foscam Cameras C1 Lite V3, and C1 V3 with firmware 2.82.2.33 and earlier, FI9800P V3, FI98
Command injection vulnerability in change password of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could
A vulnerability in the CLI of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to inject arbitrar
D-Link DIR-846 devices with firmware 100.26 allow remote attackers to execute arbitrary code as root via a SetNetworkTom
The web management console of Opsview Monitor 5.4.x before 5.4.2 provides functionality accessible by an authenticated a
An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Ca
The Port Forwarding functionality on DASAN H660GW devices allows remote attackers to execute arbitrary code via shell me
Pydio 4.2.1 through 8.2.1 has an authenticated remote code execution vulnerability in which an attacker with administrat
Devices in the Linksys ESeries line of routers (Linksys E1200 Firmware Version 2.0.09 and Linksys E2500 Firmware Version
Devices in the Linksys ESeries line of routers (Linksys E1200 Firmware Version 2.0.09 and Linksys E2500 Firmware Version
An exploitable operating system command injection exists in the Linksys ESeries line of routers (Linksys E1200 Firmware
NetGain Enterprise Manager (EM) is affected by OS Command Injection vulnerabilities in versions before 10.0.57. These vu
An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Optic
Frequently Asked Questions
What is CWE-78?
CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-78?
There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.
How can I protect against CWE-78 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.
Detect CWE-78 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.
Get Started