CWE-78
MITRE ↗Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)
Ajenti 2.1.36 contains a post-authenticated remote command execution vulnerability that allows remote attackers to execu
Tea LaTex 1.0 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary
aelsantex runcommand 2014-04-01, a plugin for DokuWiki, allows unauthenticated attackers to execute arbitrary system com
Sickbeard alpha contains a remote command injection vulnerability that allows unauthenticated attackers to execute arbit
Pinger 1.0 contains a remote code execution vulnerability that allows attackers to inject shell commands through the pin
Edimax EW-7438RPn-v3 Mini 1.27 contains a remote code execution vulnerability that allows unauthenticated attackers to e
Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, due to the insufficient patch for CVE-2024-
BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-auth
ZoneMinder v1.36.34 is vulnerable to Command Injection in web/views/image.php. The application passes unsanitized user i
MajorDoMo (aka Major Domestic Module) is vulnerable to unauthenticated OS command injection via rc/index.php. The $param
A security vulnerability has been detected in SECCN Dingcheng G10 3.1.0.181203. This impacts the function qq of the file
An unauthenticated attacker can inject OS commands when calling a server API endpoint in NesterSoft WorkTime. The server
RustFly 2.0.0 contains a command injection vulnerability in its remote UI control mechanism that accepts hex-encoded ins
A Remote Code Execution (RCE) vulnerability was found in Smanga 3.2.7 in the /php/path/rescan.php interface. The applica
thesystem 1.0 contains a command injection vulnerability that allows unauthenticated attackers to execute arbitrary syst
A command injection vulnerability in the UPnP function of the Zyxel EX3510-B0 firmware versions through 5.17(ABUP.15.1)C
All versions of InSAT MasterSCADA BUK-TS are susceptible to OS command injection through a field in its MMadmServ web in
Due to missing neutralization of special elements, OS commands can be injected via the handshake of a TLS-SRP connection
Due to missing neutralization of special elements, OS commands can be injected via the update functionality of a TLS-SRP
TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. A vulnerability in versions prior to 2.01 allows unau
A security flaw has been discovered in Totolink N300RH 6.1c.1353_B20190305. Affected by this vulnerability is the functi
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Johnson Cont
openDCIM version 23.04, through commit 4467e9c4, contains an OS command injection vulnerability in report_network_map.ph
An issue was discovered in goform/formSetIptv in Tenda AC15V1.0 V15.03.05.18_multi. When the condition is met, `s1_1` wi
A command injection vulnerability in the DHCP activation feature of Weintek cMT-3072XH2 easyweb Web Version v2.1.53, OS
A flaw has been found in D-Link DIR-868L 110b03. This affects the function sub_1BF84 of the component SSDP Service. This
SEPPmail Secure Email Gateway before version 15.0.1 insufficiently neutralizes the PDF encryption password, allowing OS
A shell command injection vulnerability in Mobvoi Tichome Mini smart speaker 012-18853 and 027-58389 allows remote attac
OpenClaw versions prior to 2026.2.2 fail to properly validate Windows cmd.exe metacharacters in allowlist-gated exec req
OpenClaw versions prior to 2026.2.2 contain an exec approvals (must be enabled) allowlist bypass vulnerability that allo
AVideo is a video-sharing Platform software. Prior to version 7.0, an unauthenticated attacker can execute arbitrary OS
XikeStor SKS8310-8X Network Switch firmware versions 1.04.B07 and prior contain an OS command injection vulnerability in
An issue pertaining to CWE-78: Improper Neutralization of Special Elements used in an OS Command was discovered in linag
An unauthenticated remote attacker can perform a command injection via Modbus-TCP or Modbus-RTU to gain read and write a
`simple-git`, an interface for running git commands in any node.js application, has an issue in versions 3.15.0 through
An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The host parameter of the TFTP client in the Filesystem Browse
An issue in Lantronix EDS3000PS v.3.1.0.0R2 allows an attacker to execute arbitrary code and obtain sensitive informatio
Cloud CLI (aka Claude Code UI) is a desktop and mobile UI for Claude Code, Cursor CLI, Codex, and Gemini-CLI. Prior to 1
claude-hovercraft executeClaudeCode Command Injection Remote Code Execution Vulnerability. This vulnerability allows rem
A weakness has been identified in Topsec TopACM 3.0. Affected by this vulnerability is an unknown functionality of the f
A command injection vulnerability exists in the web management interface of the WiFi Extender WDR201A (HW V2.1, FW LFMZX
Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Bing Images allo
A command injection vulnerability has been reported to affect QuNetSwitch. The remote attackers can then exploit the vul
A command injection vulnerability has been reported to affect QuNetSwitch. If a remote attacker gains a user account, th
Due to the improper neutralisation of special elements used in an OS command, an unauthenticated remote attacker can exp
A vulnerability has been found in Tiandy Easy7 Integrated Management Platform up to 7.17.0. This vulnerability affects u
textract through 2.5.0 is vulnerable to OS Command Injection via the file path parameter in multiple extractors. When pr
node-tesseract-ocr is an npm package that provides a Node.js wrapper for Tesseract OCR. In all versions through 2.2.1, t
thumbler through 1.1.2 allows OS command injection via the input, output, time, or size parameter in the thumbnail() fun
thingino-firmware versions up to the firmware-2026-03-16 release contains an unauthenticated os command injection vulner
Frequently Asked Questions
What is CWE-78?
CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-78?
There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.
How can I protect against CWE-78 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.
Detect CWE-78 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.
Get Started