Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)

1,941
CRITICAL
3,146
HIGH
963
MEDIUM
16
LOW
6,290 CVEs · Page 15/126
8.4
CVE-2026-43990

JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, plugin-shell's run_command wrapped

8.4
CVE-2026-43991

JunoClaw is an agentic AI platform built on Juno Network. Prior to 0.x.y-security-1, substring-based blocklist in plugin

8.4
CVE-2026-59686

An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection M

8.4
CVE-2026-59687

An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection M

8.4
CVE-2026-59688

An OS Command Injection vulnerability in Progress Software LoadMaster, ECS Connection Manager, Object Scale Connection M

8.4
CVE-2026-67180

Google Turbinia allows arbitrary command execution via worker tasks. An attacker with privileges to submit a processing

8.4
CVE-2026-18824

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands

8.4
CVE-2026-55581

mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, the default Do

8.4
CVE-2026-55582

mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, the default se

8.4
CVE-2026-81097

The execute_ruby tool is documented as a read-only Ruby sandbox and is enforced by a pattern denylist together with repl

8.3
CVE-2026-0980

A flaw was found in rubyipmi, a gem used in the Baseboard Management Controller (BMC) component of Red Hat Satellite. An

8.3
CVE-2026-45369

python-utcp is the python implementation of UTCP. Prior to 1.1.3, the _substitute_utcp_args method in cli_communication_

8.3
CVE-2026-55427

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7, 2.32.7,

8.3
CVE-2026-17497

NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with ar

8.3
CVE-2026-22621

Improper input validation in one of the session management interface of Eaton's Tripp Lite Series PADM firmware could al

8.3
CVE-2026-18235

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary Control Language commands

8.3
CVE-2026-19983

A vulnerability was detected in GL.iNet A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000 and XE3000 4.8.x. This iss

8.3
CVE-2026-38820

openNDS before 11.0.0 is susceptible to unauthenticated OS command execution via shell command injection through the fas

8.2
CVE-2026-34982

Vim is an open source, command line text editor. Prior to version 9.2.0276, a modeline sandbox bypass in Vim allows arbi

8.2
CVE-2026-5208

Command injection in alerts in CoolerControl/coolercontrold <4.0.0 allows authenticated attackers to execute arbitrary c

8.2
CVE-2026-35071

Dell PowerScale InsightIQ, versions 6.0.0 through 6.2.0, contains an improper neutralization of special elements used in

8.2
CVE-2026-44712

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, a crafted UUID such a

8.2
CVE-2026-41011

PackagePersister.validate_tgz builds "tar -tf #{tgz} 2>&1" where tgz = File.join(release_dir, 'packages', "#{name}.tgz")

8.2
CVE-2026-41010

ReleaseJob#unpack builds job_dir = File.join(@release_dir, 'jobs', name) and job_tgz = File.join(@release_dir, 'jobs', "

8.2
CVE-2025-69755

An issue in Neterbit NW-431F Router vNW-431F-20241014-IR03 allows a remote attacker to obtain sensitive information and

8.2
CVE-2026-49260

PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.5.1, `pontedilana/

8.2
CVE-2026-48345

Animate is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vul

8.2
CVE-2026-74801

SiYuan before 3.7.4 fails to properly escape workspace directory paths when constructing command-line arguments for the

8.1
CVE-2026-27190

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.6.8, a command injection vulnerability exists in D

8.1
CVE-2026-32260

Deno is a JavaScript, TypeScript, and WebAssembly runtime. From 2.7.0 to 2.7.1, A command injection vulnerability exist

8.1
CVE-2026-32034

OpenClaw versions prior to 2026.2.21 contain an authentication bypass vulnerability in the Control UI when allowInsecure

8.1
CVE-2026-33482

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `sanitizeFFmpegCommand()` functi

8.1
CVE-2026-28291

simple-git enables running native Git commands from JavaScript. Versions up to and including 3.31.1 allow execution of a

8.1
CVE-2026-41113

sagredo qmail before 2026.04.07 allows tls_quit remote code execution because of popen in notlshosts_auto in qmail-remot

8.1
CVE-2025-9661

OS command injection vulneravility in the management gui (maintenance utility) of Hitachi Virtual Storage Platform One B

8.1
CVE-2022-50994

DrayTek Vigor 2960 firmware versions prior to 1.5.1.4 contain an OS command injection vulnerability in the CGI login han

8.1
CVE-2026-30635

Command injection vulnerability in automagik-genie 2.5.27 MCP Server allows attackers to execute arbitrary commands via

8.1
CVE-2026-9277

shell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`. The

8.1
CVE-2026-48694

FastNetMon Community Edition through 1.2.9 contains a configuration injection vulnerability in the Juniper router integr

8.1
CVE-2026-48695

FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the MikroTik router integra

8.1
CVE-2026-50874

An OS command injection vulnerability in the /manage/features/media component of kanishka-linux Reminiscence v0.3.0 allo

8.1
CVE-2026-56379

ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows atta

8.1
CVE-2026-49402

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.10, Deno's node:child_process implementation pro

8.1
CVE-2026-44454

Coder allows organizations to provision remote development environments via Terraform. Prior to versions 2.29.7 and 2.30

8.1
CVE-2026-15427

An OS command injection vulnerability exists in the TR-069 / CWMP management interface of Archer VX1800v v1 due to insuf

8.1
CVE-2026-63304

AVideo through 29.0 contains an OS command injection vulnerability in plugin/API/standAlone/functions.php where the list

8.1
CVE-2026-63305

AVideo through 29.0 contains an OS command injection vulnerability in the ffmpeg.json.php endpoint where notifyCode and

8.1
CVE-2026-55173

WWBN AVideo is an open source video platform. Versions 29.0 and below remain vulnerable to OS command injection because

8.1
CVE-2026-53790

rsync before 3.5.0 contains multiple command and argument injection vulnerabilities that allow attackers to execute arbi

8.0
CVE-2026-24129

Runtipi is a Docker-based, personal homeserver orchestrator that facilitates multiple services on a single server. Versi

Frequently Asked Questions

What is CWE-78?

CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-78?

There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.

How can I protect against CWE-78 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.

Detect CWE-78 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.

Get Started