Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)

1,941
CRITICAL
3,146
HIGH
963
MEDIUM
16
LOW
6,290 CVEs · Page 31/126
9.9
CVE-2025-44961

In RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build, OS command injection can occur via an IP address field provided b

9.9
CVE-2025-60957

OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.0

9.9
CVE-2025-54469

A vulnerability was identified in NeuVector, where the enforcer used environment variables CLUSTER_RPC_PORT and CLUSTER_

9.9
CVE-2025-67164

An authenticated arbitrary file upload vulnerability in the /storage/poc.php component of Pagekit CMS v1.0.18 allows att

9.9
CVE-2025-66209

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0

9.9
CVE-2025-66203

StreamVault is a video download integration solution. Prior to version 251126, a Remote Code Execution (RCE) vulnerabili

9.8
CVE-2024-9140

Moxa’s cellular routers, secure routers, and network security appliances are affected by a critical vulnerability, CVE-2

9.8
CVE-2024-57687

An OS Command Injection vulnerability was found in /landrecordsys/admin/dashboard.php in PHPGurukul Land Record System v

9.8
CVE-2024-12847

NETGEAR DGN1000 before 1.1.00.48 is vulnerable to an authentication bypass vulnerability. A remote and unauthenticated a

9.8
CVE-2025-0107

An OS command injection vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to run arbitr

9.8
CVE-2025-20055

OS command injection vulnerability exists in network storage servers STEALTHONE D220/D340 provided by Y'S corporation. A

9.8
CVE-2024-57595

DLINK DIR-825 REVB 2.03 devices have an OS command injection vulnerability in the CGl interface apc_client_pin.cgi, whic

9.8
CVE-2025-20014

mySCADA myPRO does not properly neutralize POST requests sent to a specific port with version information. This vulnerab

9.8
CVE-2025-20061

mySCADA myPRO does not properly neutralize POST requests sent to a specific port with email information. This vulnerabil

9.8
CVE-2025-0680

Affected products contain a vulnerability in the device cloud rpc command handling process that could allow remote attac

9.8
CVE-2024-53584

OpenPanel v0.3.4 was discovered to contain an OS command injection vulnerability via the timezone parameter.

9.8
CVE-2025-25067

mySCADA myPRO Manager is vulnerable to an OS command injection which could allow a remote attacker to execute arbitrar

9.8
CVE-2021-46686

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in acmailer CGI

9.8
CVE-2025-26613

WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. An OS Command Injection

9.8
CVE-2025-27140

WeGIA is a Web manager for charitable institutions. An OS Command Injection vulnerability was discovered in versions pri

9.8
CVE-2025-1316 KEV

Edimax IC-7100 does not properly neutralize requests. An attacker can create specially crafted requests to achieve remot

9.8
CVE-2024-50390

A command injection vulnerability has been reported to affect QHora. If exploited, the vulnerability could allow remote

9.8
CVE-2024-9053

vllm-project vllm version 0.6.0 contains a vulnerability in the AsyncEngineRPCServer() RPC server entrypoints. The core

9.8
CVE-2025-28138

The TOTOLINK A800R V4.1.2cu.5137_B20200730 were found to contain a pre-auth remote command execution vulnerability in th

9.8
CVE-2025-22398

Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('

9.8
CVE-2025-28219

Netgear DC112A V1.0.0.64 has an OS command injection vulnerability in the usb_adv.cgi, which allows remote attackers to

9.8
CVE-2025-28256

An issue in TOTOLINK A3100R V4.1.2cu.5247_B20211129 allows a remote attacker to execute arbitrary code via the setWebWla

9.8
CVE-2025-25579

TOTOLINK A3002R V4.0.0-B20230531.1404 is vulnerable to Command Injection in /bin/boa via bandstr.

9.8
CVE-2025-26817

Netwrix Password Secure 9.2.0.32454 allows OS command injection.

9.8
CVE-2025-3361

The web service of iSherlock from HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attac

9.8
CVE-2025-3362

The web service of iSherlock from HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attac

9.8
CVE-2025-3363

The web service of iSherlock from HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attac

9.8
CVE-2025-27797

OS command injection vulnerability in the specific service exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If exploited, a

9.8
CVE-2025-28137

The TOTOLINK A810R V4.1.2cu.5182_B20201026 were found to contain a pre-auth remote command execution vulnerability in th

9.8
CVE-2025-29040

An issue in dlink DIR 823x 240802 allows a remote attacker to execute arbitrary code via the target_addr key value and t

9.8
CVE-2025-29041

An issue in dlink DIR 823x 240802 allows a remote attacker to execute arbitrary code via the target_addr key value and t

9.8
CVE-2025-29042

An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the macaddr key value to the fu

9.8
CVE-2025-29043

An issue in dlink DIR 832x 240802 allows a remote attacker to execute arbitrary code via the function 0x417234

9.8
CVE-2025-28034

TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.51

9.8
CVE-2025-28037

TOTOLINK A810R V4.1.2cu.5182_B20201026 and A950RG V4.1.2cu.5161_B20200903 were found to contain a pre-auth remote comman

9.8
CVE-2025-28035

TOTOLINK A830R V4.1.2cu.5182_B20201102 was found to contain a pre-auth remote command execution vulnerability in the set

9.8
CVE-2025-28036

TOTOLINK A950RG V4.1.2cu.5161_B20200903 was found to contain a pre-auth remote command execution vulnerability in the se

9.8
CVE-2025-28038

TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the s

9.8
CVE-2025-28039

TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the s

9.8
CVE-2025-45042

Tenda AC9 v15.03.05.14 was discovered to contain a command injection vulnerability via the Telnet function.

9.8
CVE-2025-45491

Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.ddnsStatus DynDNS fun

9.8
CVE-2025-45858

TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability via the FUN_00459fdc f

9.8
CVE-2025-32002

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in I-O DATA netw

9.8
CVE-2025-44880

A command injection vulnerability in the component /cgi-bin/adm.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execu

9.8
CVE-2025-44882

A command injection vulnerability in the component /cgi-bin/firewall.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to

Frequently Asked Questions

What is CWE-78?

CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-78?

There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.

How can I protect against CWE-78 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.

Detect CWE-78 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.

Get Started