CWE-78
MITRE ↗Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)
Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors runni
Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors runni
AP180 series with firmware versions prior to AP_RGOS 11.9(4)B1P8 contains an OS command injection vulnerability. If this
A vulnerability was detected in D-Link DIR-615 up to 4.10. This impacts an unknown function of the file /wiz_policy_3_ma
Insecure file operations in HPE Aruba Networking Fabric Composer’s backup functionality could allow authenticated atta
A vulnerability was found in D-Link DIR-615 4.10. This issue affects some unknown processing of the file /set_temp_nodes
A vulnerability was determined in D-Link DIR-615 4.10. Impacted is an unknown function of the file /adv_mac_filter.php o
Some Hikvision Wireless Access Points are vulnerable to authenticated command execution due to insufficient input valida
A command injection vulnerability may be exploited after the admin's authentication in the cloud communication interface
A command injection vulnerability may be exploited after the admin's authentication in the VPN Connection Service on the
A command injection vulnerability may be exploited after the admin's authentication in the VPN server configuration modu
A command injection vulnerability may be exploited after the admin's authentication via the configuration backup restora
A command injection vulnerability may be exploited after the admin's authentication via the import of a crafted VPN clie
n8n is an open source workflow automation platform. From version 0.187.0 to before 1.120.3, a command injection vulnerab
A post‑authentication command injection vulnerability in the Dynamic DNS (DDNS) configuration CLI command in Zyxel ATP s
A weakness has been identified in D-Link DIR-823X 250416. This impacts an unknown function of the file /goform/set_langu
A vulnerability was identified in D-Link DIR-823X 250416. This affects an unknown function of the file /goform/set_serve
A vulnerability was found in D-Link DIR-823X 250416. Affected by this issue is some unknown functionality of the file /g
A weakness has been identified in D-Link DIR-823X 250416. This vulnerability affects the function sub_420688 of the file
A security vulnerability has been detected in D-Link DIR-823X 250416. This issue affects some unknown processing of the
A vulnerability has been found in D-Link DIR-615 4.10. This affects an unknown part of the file adv_firewall.php of the
A vulnerability was found in D-Link DIR-615 4.10. This vulnerability affects unknown code of the file adv_routing.php of
A security flaw has been discovered in D-Link DIR-823X 250416. The affected element is the function sub_4208A0 of the fi
A security vulnerability has been detected in D-Link DIR-823X 250416. This affects the function sub_4175CC of the file /
A weakness has been identified in D-Link DIR-823X 250416. This vulnerability affects the function sub_420618 of the file
A vulnerability was determined in UTT 进取 521G 3.1.1-190816. The impacted element is the function sub_446B18 of the file
A vulnerability has been found in D-Link DIR-823X 250416. This affects the function sub_4211C8 of the file /goform/set_f
A vulnerability was found in D-Link DCS-931L up to 1.13.0. This affects an unknown part of the file /goform/setSysAdmin.
A vulnerability was identified in Advantech WISE-6610 1.2.1_20251110. Affected is an unknown function of the file /cgi-b
A security vulnerability has been detected in UTT HiPER 520 1.7.7-160105. This impacts the function sub_44D264 of the fi
A vulnerability was detected in UTT HiPER 520 1.7.7-160105. Affected is the function sub_44EFB4 of the file /goform/form
A vulnerability was found in a Moodle TeX filter administrative setting where insufficient sanitization of configuration
A post-authentication command injection vulnerability in the TR-369 certificate download CGI program of the Zyxel VMG362
Chamilo is a learning management system. Prior to version 1.11.30, there is an OS command Injection vulnerability in /pl
Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /ma
Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /pl
Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /pl
Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /ma
Cohesity TranZman Migration Appliance Release 4.0 Build 14614 was discovered to contain an authenticated command injecti
Multiple authenticated OS command injection vulnerabilities exist in the Cohesity (formerly Stone Ram) TranZman 4.0 Buil
API endpoint for user synchronization in 2N Access Commander version 3.4.1 did not have a sufficient input validation al
FreePBX is an open source IP PBX. From versions 16.0.17.2 to before 16.0.20 and from version 17.0.2.4 to before 17.0.5,
Idno is a social publishing platform. Prior to version 1.6.4, there is a remote code execution vulnerability via chained
Budibase is a low code platform for creating internal tools, workflows, and admin panels. In 3.23.22 and earlier, the Po
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet F
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet
A vulnerability in the command line interface of AOS-CX Switches could allow an authenticated remote attacker to execute
OpenLiteSpeed and LSWS Enterprise provided by LiteSpeed Technologies contain an OS command injection vulnerability. An a
Perle IOLAN STS/SCS terminal server models with firmware versions prior to 6.0 allow authenticated OS command injection
xiaoheiFS is a self-hosted financial and operational system for cloud service businesses. In versions up to and includin
Frequently Asked Questions
What is CWE-78?
CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-78?
There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.
How can I protect against CWE-78 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.
Detect CWE-78 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.
Get Started