Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)

1,941
CRITICAL
3,146
HIGH
963
MEDIUM
16
LOW
6,290 CVEs · Page 18/126
7.8
CVE-2026-48800

Notepad++ is a free and open-source source code editor. Prior to 8.9.6.1, the <Command> tag text content inside <UserDef

7.8
CVE-2026-56137

RPG MAKER MV and MZ provided by Gotcha Gotcha Games Inc. contain an OS command injection vulnerability. If a user loads

7.8
CVE-2026-41857

A compromised or malicious BOSH Director can execute arbitrary shell commands on the operator's workstation when the ope

7.8
CVE-2026-58459

gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in gpsprof that allows

7.8
CVE-2026-46709

Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.234, Tabby inserts dropped file paths

7.8
CVE-2026-15895

OS command injection in the npm package loading component in AWS jsii-diff before 1.131.0 might allow context-dependent

7.8
CVE-2026-44190

A flaw was found in the Ansible Lightspeed Visual Studio Code extension. This Command Injection vulnerability (CWE-78) a

7.8
CVE-2026-44191

A flaw was found in the Visual Studio Code Ansible Lightspeed extension. This command injection vulnerability (CWE-78) a

7.8
CVE-2026-14881

When importing connections in Compass it is possible to override some connection options that are otherwise can't be cha

7.8
CVE-2026-16287

Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in TUBITAK BILG

7.8
CVE-2026-24252

NVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS command injection. A successful exploit of

7.8
CVE-2026-16524

A command injection flaw in PCP's linux_sockets PMDA allows malicious shell metacharacters via the network.persocket.fil

7.8
CVE-2026-44093

A local privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user t

7.8
CVE-2026-44095

A privilege escalation vulnerability in a script used for network configuration allows a low-privileged local user to ex

7.8
CVE-2026-44096

A privilege escalation vulnerability in udhcpc allows a local user "charx-web" to execute arbitrary commands as root, re

7.8
CVE-2026-44099

A privilege escalation vulnerability in the system configuration allows a low-privileged local user to execute arbitrary

7.8
CVE-2026-44106

A privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to exec

7.8
CVE-2026-16022

@oblique/cli 15.4.0 contains an OS command injection vulnerability in the project creation functionality. The CLI constr

7.8
CVE-2026-48097

NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Vers

7.8
CVE-2026-70335

Improper neutralization of special elements used in an os command ('os command injection') in GitHub Copilot and Visual

7.8
CVE-2026-16695

IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 could allow a local attacker to execute arbitrary code due to imp

7.8
CVE-2026-56686

Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Com

7.8
CVE-2026-59910

Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Com

7.8
CVE-2026-75056

In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible

7.8
CVE-2026-71551

Super Productivity is an advanced todo list app with integrated timeboxing and time tracking capabilities. Prior to 18.1

7.8
CVE-2026-55426

linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations, and Linuxfa

7.8
CVE-2026-16875

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary commands due to shell me

7.8
CVE-2026-61898

The Ubuntu-specific language helper scripts (save-to-pam-env, update-langlist) shipped with accountsservice before 23.13

7.8
CVE-2026-18284

Sony XAV-9500ES Crash Dump Handler Command Injection Local Privilege Escalation Vulnerability. This vulnerability allows

7.8
CVE-2026-41449

UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the _run_comman

7.8
CVE-2026-41450

UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the _command_co

7.8
CVE-2026-41451

UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the user substi

7.8
CVE-2026-57998

better-npm-audit through 3.11.0, and the 4.0.0-rc.2 prerelease, builds its npm audit command by interpolating the user-s

7.8
CVE-2026-59561

Sakura Editor provided by Sakura Editor Development Community contains an OS command injection vulnerability. If a victi

7.8
CVE-2026-79992

A flaw was found in Emacs TRAMP. A local attacker could exploit this vulnerability by processing maliciously crafted fil

7.8
CVE-2026-65089

NVIDIA NemoClaw for Linux contains a vulnerability in its status and logs plugin commands, where an attacker could cause

7.8
CVE-2026-65090

NVIDIA NemoClaw for Linux contains a vulnerability in its NIM management component, where an attacker could cause OS com

7.8
CVE-2026-65096

NVIDIA NemoClaw for Linux contains a vulnerability in the Telegram bridge component, where an attacker could cause an OS

7.8
CVE-2026-65099

NVIDIA NemoClaw for Linux contains a vulnerability in its command-line interface, where an attacker could cause OS comma

7.7
CVE-2026-22035

Greenshot is an open source Windows screenshot utility. Versions 1.3.310 and below arvulnerable to OS Command Injection

7.7
CVE-2026-25157

OpenClaw is a personal AI assistant. Prior to version 2026.1.29, there is an OS command injection vulnerability via the

7.7
CVE-2026-27938

WPGraphQL provides a GraphQL API for WordPress sites. Prior to version 2.9.1, the `wp-graphql/wp-graphql` repository con

7.7
CVE-2026-54699

Warp is an agentic development environment. From 0.2024.03.12.08.02.stable_01 until 0.2026.05.06.15.42.stable_01, Warp c

7.7
CVE-2026-8592

OS Command Injection vulnerability in the process_string action of Rapid7 InsightConnect AWK Plugin on Linux allows remo

7.7
CVE-2026-8660

OS Command Injection vulnerability in the ping action of Rapid7 InsightConnect Ping Plugin on Linux allows remote attack

7.7
CVE-2026-8665

OS Command Injection vulnerability in the TR action of Rapid7 InsightConnect Translate Plugin on Linux allows remote att

7.7
CVE-2026-8666

OS Command Injection vulnerability in the traceroute action of Rapid7 InsightConnect Traceroute Plugin on Linux allows r

7.7
CVE-2026-48347

Animate is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vul

7.7
CVE-2026-48385

ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

7.7
CVE-2026-71567

In openshift-metal3/fakefish there is a repeated pattern in some of the scripts where shell variables are injected with

Frequently Asked Questions

What is CWE-78?

CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-78?

There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.

How can I protect against CWE-78 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.

Detect CWE-78 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.

Get Started