CWE-78
MITRE ↗Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)
A command injection vulnerability exists in nvm (Node Version Manager) versions 0.40.3 and below. The nvm_download() fun
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X60
In the endpoints "/cgi-bin/CliniNET.prd/utils/usrlogstat_simple.pl", "/cgi-bin/CliniNET.prd/utils/usrlogstat.pl", "/cgi-
An improper sanitization of the compression_algorithm parameter in Canonical LXD allows an authenticated, unprivileged u
Vulnerable endpoints accept user-controlled input through a URL in JSON format which enables command execution. The comm
Host and event action script input is validated with a regex (set by the administrator), but the validation runs in mult
Cato Networks’ Socket versions prior to 25 contain a command injection vulnerability that allows an authenticated attack
dbt enables data analysts and engineers to transform their data using the same practices that software engineers use to
3onedata modbus gateway device model GW1101-1D(RS-485)-TB-P (hardware version V2.2.0) allows authenticated users to exec
WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the wireless.cg
WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the internet.cg
WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the makeRequest
WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the adm.cgi bin
WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains an OS command injection vulnerability in the firewall.cg
efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, the elfinder_checkRisk function validates target and targe
HRConvert2 is a self-hosted, drag-and-drop & nosql file conversion server & share tool. Prior to 3.3.8, the sanitizeStri
Improper input validation in Delphix Continuous Data connectors allows an authenticated user to execute arbitrary operat
An OS Command Injection vulnerability exists in Aterm. If a malicious third person gains administrator access to the pro
This vulnerability exists in GX Earth ONT models due to improper handling of user-supplied input in multiple diagnostic
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, an OS command injection vu
HAX CMS helps manage microsite universe with PHP or NodeJs backends. The PHP version of HAX CMS prior to version 26.0.0
A command Injection vulnerability exists in the WireGuard client configuration of Archer MR600 v5 due to improper neutra
Logseq exposes an IPC handler that allows the renderer process to execute shell commands. While an allowlist restricts t
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic
An OS command injection vulnerability exists in the VPN module of TP-Link Archer AX12 v1, AX17 v1. AX18 v1, and AX1300 v
Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. Prior to version 1.7.1
Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.24.0 and prior to v
An OS Command Injection vulnerability exists in LMS (LAN Management System) before commit 9fcb4de due to an IP address p
OS command injection in the environment and tunnel configuration functionality in SIMA GmbH Bondix through version 1.25.
gin-vue-admin is an AI-assisted basic development platform. In version 2.9.1, an authenticated attacker with access to t
A command injection vulnerability has been identified in the DHCP option processing logic in multiple TP-Link router mod
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec
myVesta is affected by an authenticated remote code execution vulnerability. Low privileged users can insert arbitrary c
@cyclonedx/cyclonedx-npm creates CycloneDX Software Bill of Materials from npm projects. From 2.1.0 before 5.0.0, the CL
R-SOFT DMS is vulnerable to OS Command Injection in konwertujAction() function. The document converter executes shell co
R-SOFT DMS is vulnerable to OS Command Injection in the Optical Character Recognition (OCR) module. Multiple command exe
The OCPP DataTransfer message `ReserveLogin` is vulnerable to command injection. By manipulating the data value, arbitra
Privilege escalation in Checkmk versions 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49, and 2.2.0 (
MaaAssistantArknights is a one-click tool for daily Arknights tasks. In the current dev-v2 workflow, .github/workflows/r
The Lenovo XClarity Integrator for Windows Admin Center plugin version 5.1.1 and below running on the WAC Gateway is vul
Claude Code Action is a general-purpose GitHub action that runs Claude Code on GitHub pull requests and issues. Prior to
In egroupware version 26.0 and earlier, an authenticated administrator can achieve OS-level Remote Code Execution (RCE)
DbGate is cross-platform database manager. Versions 7.1.8 and prior are vulnerable to authenticated Remote Code Executio
Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain an Improper Neutralization of Special Elements vuln
Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to execut
PHP_CodeSniffer tokenizes PHP files and detects violations of a defined set of coding standards. Prior to versions 3.13.
Ruby LSP is an implementation of the language server protocol for Ruby. Several workspace-level settings in the Ruby LSP
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the buildRemoteDocker() function in pac
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, cloneGitRepository in packages/server/s
Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.8, the getRegistryCommands() function in pa
Frequently Asked Questions
What is CWE-78?
CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-78?
There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.
How can I protect against CWE-78 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.
Detect CWE-78 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.
Get Started