Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)

1,941
CRITICAL
3,146
HIGH
963
MEDIUM
16
LOW
6,290 CVEs · Page 14/126
8.8
CVE-2026-16906

IBM i 7.6, and 7.5 could allow a remote authenticated attacker to execute arbitrary commands with elevated privileges du

8.8
CVE-2026-17417

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper n

8.8
CVE-2026-17642

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper n

8.8
CVE-2026-73625

GitPython versions before 3.1.54 contain a remote code execution vulnerability in the check_unsafe_options guard that ca

8.8
CVE-2026-73667

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.0-rc.2, OpenChor

8.8
CVE-2026-19635

A local privilege escalation vulnerability exists in Security Center. An attacker with write access to a specific config

8.8
CVE-2026-19679

An input validation vulnerability exists in Security Center's file upload handling, where insufficient sanitization of u

8.8
CVE-2026-73680

Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration that allows authentica

8.8
CVE-2026-74997

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to r

8.8
CVE-2026-62982

Glances is an open-source system cross-platform monitoring tool. From 4.5.2 until 4.5.6, _sanitize_mustache_dict() in gl

8.8
CVE-2026-52876

Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to version 2.6.0, the op

8.8
CVE-2024-58376

Renovate versions 37.158.0 before 37.199.0 contain a command injection vulnerability in the helmv3 manager's registryAli

8.8
CVE-2026-54795

Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an

8.8
CVE-2026-49255

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.11.11, electerm con

8.8
CVE-2026-71961

Cudy WR3000 2.0 running firmware before 2.5.24 contains an OS command injection vulnerability that allows authenticated

8.8
CVE-2026-16842

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to imprope

8.8
CVE-2026-16844

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to imprope

8.8
CVE-2026-16848

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to imprope

8.8
CVE-2026-16865

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to command inj

8.8
CVE-2026-53542

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2

8.8
CVE-2026-16932

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary commands due to improper

8.8
CVE-2026-18264

NoMachine getstat Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to e

8.8
CVE-2026-47359

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Cloud

8.8
CVE-2026-50112

SSRF via Metalink Mirror URL Resolution: An authenticated tenant can register a template pointing to an attacker-contro

8.8
CVE-2026-65091

NVIDIA OpenShell for all platforms contains a vulnerability where a malicious gateway could cause OS command injection.

8.8
CVE-2026-19042

A command injection vulnerability in TeamViewer Full Client and Host for Linux prior to version 15.81.5 allows a remote

8.8
CVE-2026-68861

Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS

8.8
CVE-2026-74770

Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS

8.8
CVE-2026-76060

An authenticated OS command injection vulnerability exists in ZoneMinder's event export functionality. The exportFile HT

8.8
CVE-2026-78037

Xiiaozet LK100W is vulnerable to OS command injection through its web-based management interface. An authenticated atta

8.7
CVE-2026-34940

KubeAI is an AI inference operator for kubernetes. Prior to 0.23.2, the ollamaStartupProbeScript() function in internal/

8.7
CVE-2026-34176

When running in Appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iContro

8.7
CVE-2026-42924

An authenticated attacker with the Resource Administrator or Administrator role can create SNMP configuration objects th

8.6
CVE-2025-64091

This vulnerability allows authenticated attackers to execute commands via the NTP-configuration of the device.

8.6
CVE-2026-21267

Dreamweaver Desktop versions 21.6 and earlier are affected by an Improper Neutralization of Special Elements used in an

8.6
CVE-2026-44461

Zed is a code editor. Prior to 0.227.1, Zed builds SSH/WSL remote commands as a shell command string that starts with ex

8.6
CVE-2026-44463

Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed by prepending environment

8.6
CVE-2026-44465

Zed is a code editor. Prior to 0.227.1, Zed IDE executes arbitrary commands when opening a folder with a malicious .git/

8.6
CVE-2026-44466

Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed via bash arithmetic expans

8.6
CVE-2026-11527

Config::IniFiles versions before 3.001000 for Perl allow OS command injection and file overwrite via a 2-arg open() of t

8.6
CVE-2026-55441

mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.6.4, mise's trust feature gates config fil

8.6
CVE-2026-56389

GNU Bison allows for an execution of an arbitrary program during HTML report generation due to improper handling of gram

8.6
CVE-2026-44098

This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend via firewall-bypass to p

8.5
CVE-2026-17179

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to cause a denial of service due to c

8.4
CVE-2026-0507

Due to an OS Command Injection vulnerability in SAP Application Server for ABAP and SAP NetWeaver RFCSDK, an authenticat

8.4
CVE-2025-13444

OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker

8.4
CVE-2025-13447

OS Command Injection Remote Code Execution Vulnerability in API in Progress LoadMaster allows an authenticated attacker

8.4
CVE-2026-25593

OpenClaw is a personal AI assistant. Prior to 2026.1.20, an unauthenticated local client could use the Gateway WebSocket

8.4
CVE-2026-26280

systeminformation is a System and OS information library for node.js. In versions prior to 5.30.8, a command injection v

8.4
CVE-2026-28463

OpenClaw versions prior to 2026.2.14 contain an arbitrary file read vulnerability in the exec-approvals allowlist valida

Frequently Asked Questions

What is CWE-78?

CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-78?

There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.

How can I protect against CWE-78 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.

Detect CWE-78 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.

Get Started