Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)

1,941
CRITICAL
3,146
HIGH
963
MEDIUM
16
LOW
6,290 CVEs · Page 23/126
7.2
CVE-2026-9717

CWE-78 Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could

7.2
CVE-2026-55975

A vulnerability exists in H.View IP cameras that could allow an authenticated user to supply unsanitized XML fields to t

7.2
CVE-2026-56808

DGM3103SCT provided by AVTECH Security Corporation contains an OS command injection vulnerability, which may lead to arb

7.2
CVE-2026-50043

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in SkyBridge MB-

7.2
CVE-2026-49814

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r

7.2
CVE-2026-49815

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r

7.2
CVE-2026-53478

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r

7.2
CVE-2026-53479

Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r

7.2
CVE-2026-24697

An OS command injection vulnerability exists in the start_bonjour() function of the "rc" binary in Cisco RV130/RV130W wi

7.2
CVE-2026-24698

An OS command injection vulnerability exists in the save_syslog_to_file() function of the "httpd" binary in Cisco RV130/

7.2
CVE-2026-24699

An OS command injection vulnerability exists in the sub_34984() function of the "rc" binary in Cisco RV130/RV130W with f

7.2
CVE-2026-24700

An OS command injection vulnerability exists in the start_lltd() function of the "rc" binary in Cisco RV130/RV130W with

7.2
CVE-2026-59721

Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the updateInfraConfigs GraphQL mutation in ad

7.2
CVE-2026-0286

A command injection vulnerability in the management plane of Palo Alto Networks PAN-OS® software enables an authenticate

7.2
CVE-2026-14448

An high privileged remote attacker can exploit an authenticated OS command injection vulnerability in the system_certifi

7.2
CVE-2026-6952

A post-authentication command injection vulnerability in the "LogServer" field of the syslog component in Zyxel AX7501-B

7.2
CVE-2026-66138

In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code

7.2
CVE-2026-65711

sysPass through version 3.2.11 contains an OS command injection vulnerability that allows authenticated administrators t

7.2
CVE-2026-59764

ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in WebUI. If this vu

7.2
CVE-2026-61376

ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in Restore Settings.

7.2
CVE-2026-16843

Some Hikvision Networking Products are vulnerable to authenticated command execution due to insufficient input validatio

7.2
CVE-2026-67608

Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an OS command injecti

7.2
CVE-2026-67599

ClearOS 7.9 contains an OS command injection vulnerability in the Log Viewer component that allows authenticated attacke

7.2
CVE-2026-6837

A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions

7.2
CVE-2026-18900

A weakness has been identified in H3C NX15 V100R017. This impacts the function file.exec of the file /api/esps of the co

7.2
CVE-2026-71284

Fledge's backup-restore upload handler, upload_backup (python/fledge/services/core/api/backup_restore.py), takes the fir

7.2
CVE-2026-17625

IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1

7.2
CVE-2026-19034

A vulnerability was determined in Shibby Tomato 1.28.0000. Affected by this vulnerability is the function new_qoslimit_s

7.2
CVE-2026-19035

A vulnerability was identified in Shibby Tomato 1.28.0000. Affected by this issue is the function new_qoslimit_start of

7.2
CVE-2026-19036

A security flaw has been discovered in Shibby Tomato 1.28.0000. This affects the function sub_40F88C of the file /tmp/pp

7.2
CVE-2026-63725

sysPass's FileBackupService::doBackupFiles() in lib/SP/Services/Backup/FileBackupService.php around line 388 builds a ta

7.2
CVE-2026-12005

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Ident

7.2
CVE-2026-19771

A vulnerability was identified in Baicells EG3661M BaiCE_BQ6_2.0.5.3_NA. This impacts an unknown function of the file /c

7.2
CVE-2026-19628

A command injection vulnerability exists in Tenable Security Center. An authenticated administrator could modify applica

7.2
CVE-2026-54796

Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an

7.2
CVE-2026-23501

Dell RecoverPoint for VMs, versions 6.0.3 and 6.0.3.1, contains an Improper Neutralization of Special Elements used in a

7.2
CVE-2026-53804

OTRS Community Edition contains an authenticated OS command injection vulnerability in the PGP encryption module that al

7.2
CVE-2026-71904

Multiple DrayTek VigorAP models contain a command injection vulnerability in the tr069TestInform function. The vulnerabi

7.2
CVE-2026-71905

Multiple DrayTek VigorAP models contain a command injection vulnerability in the ExportSettings function. The vulnerabil

7.2
CVE-2026-71906

Multiple DrayTek VigorAP models contain a command injection vulnerability in the setLan function. The vulnerability is c

7.2
CVE-2026-71907

Multiple DrayTek VigorAP models contain a command injection vulnerability in the setcamset function. The vulnerability i

7.2
CVE-2026-71908

Multiple DrayTek VigorAP models contain a command injection vulnerability in the mesh_start_speed_test function. The vul

7.2
CVE-2026-71909

Multiple DrayTek VigorAP models contain a command injection vulnerability in the InquierTime function. The vulnerability

7.2
CVE-2026-71910

Multiple DrayTek VigorAP models contain a command injection vulnerability in the apautotest function. The vulnerability

7.2
CVE-2026-71913

Multiple DrayTek VigorAP models contain a command injection vulnerability in the upload_settings.cgi interface. The vuln

7.2
CVE-2026-71915

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the jsonstatus function. The vulnerabil

7.2
CVE-2026-71916

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the commandTable function. The vulnerab

7.2
CVE-2026-71917

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the pingtrace function. The vulnerabili

7.2
CVE-2026-71918

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the webBackupAction function. The vulne

7.2
CVE-2026-71919

Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the sysreboot function. The vulnerabili

Frequently Asked Questions

What is CWE-78?

CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-78?

There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.

How can I protect against CWE-78 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.

Detect CWE-78 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.

Get Started