CWE-78
MITRE ↗Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the auth_set function. The vulnerabilit
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the getVid function. The vulnerability
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the getDetail function. The vulnerabili
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevice function. The vulnerabili
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the rebDevice function. The vulnerabili
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the fdftDevice function. The vulnerabil
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevProto function. The vulnerabi
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setTime function. The vulnerability
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the tftp_upgrade function. The vulnerab
Multiple DrayTek VigorSwitch models contain a command injection vulnerability in the setDevNet function. The vulnerabili
Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an
PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenticated OS command injection vulnerability in /cgi-b
PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenticated OS command injection vulnerability in /cgi-b
PLANET GS-4210-16P2S firmware before 3.441b260626 contains an authenticated OS command injection vulnerability in /cgi-b
The VAPIX API mediaclip.cgi that did not have a sufficient input validation allowing for a possible remote code executio
OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in system.run exec analysis that fails to
OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in system.run that allows attackers to ex
OpenClaw versions prior to 2026.2.19 contain a local command injection vulnerability in Windows scheduled task script ge
OpenClaw versions prior to 2026.2.19 contain a command injection vulnerability in the Lobster extension tool execution t
e107 is a content management system (CMS). Versions 2.3.5 and earlier contain a command injection vulnerability in the
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to improper ne
Glances is an open-source system cross-platform monitoring tool. The Glances action system allows administrators to conf
Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.233, Tabby before 1.0.233 automatical
A command injection vulnerability was discovered in the `rpmuncompress` utility of RPM. When extracting certain archive
Kenwood DNR1007XR JKGenService Command Injection Local Privilege Escalation Vulnerability. This vulnerability allows loc
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9,
The VSCode extension for Spring CLI are vulnerable to command injection, resulting in command execution on the users mac
Arduino App Lab is a cross-platform IDE for developing Arduino Apps. Prior to 0.4.0, a vulnerability was identified in t
Deciso OPNsense diag_backup.php filename Command Injection Remote Code Execution Vulnerability. This vulnerability allow
A command injection vulnerability was identified in TP-Link TL-WR802N v4, TL-WR841N v14, and TL-WR840N v6 due to imprope
OpenClaw versions prior to 2026.2.22 contain an authorization bypass vulnerability in allow-always wrapper persistence t
A remote command execution (RCE) vulnerability in the /goform/formReleaseConnect component of UTT Aggressive 520W v3v1.7
A command injection vulnerability exists in the web server of specific firmware versions of Milesight cameras.
A post-authentication command injection vulnerability in the EasyMesh-related APIs of Zyxel DX3300-T0 firmware versions
Incoming VPN network profile settings fail to process special characters safely, enabling command injection via maliciou
Kenwood DNR1007XR startUpdateProcess Command Injection Vulnerability. This vulnerability allows physically present attac
NVIDIA OpenShell for Linux contains a vulnerability in its sandbox exec handler, where an attacker could cause an OS com
A vulnerability in the web-based management interface of Cisco FXOS Software and Cisco UCS Manager Software could a
OpenClaw versions prior to 2026.2.22 contain an allowlist bypass vulnerability in the safeBins configuration that allows
A command injection vulnerability has been reported to affect QuNetSwitch. If a local attacker gains an administrator ac
PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. PinchTab `v0.8.4` contai
FastMCP is the standard framework for building MCP applications. Prior to version 3.2.0, server names containing shell m
A Permissive List of Allowed Input vulnerability in the CLI of Juniper Networks Support Insights (JSI) Virtual Lightweig
An OS Command Injection vulnerability in the CLI processing of Juniper Networks Junos OS and Junos OS Evolved allows a l
Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release vers
Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release vers
Dell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release vers
Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain a command injection vulnerability. A high privileged att
Dell PowerProtect Data Domain, versions 8.5 through 8.6 contain(s) an Improper Neutralization of Special Elements used i
An improper neutralization of special elements used in an OS command ("OS Command Injection") vulnerability [CWE-78] vul
Frequently Asked Questions
What is CWE-78?
CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-78?
There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.
How can I protect against CWE-78 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.
Detect CWE-78 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.
Get Started