CWE-78
MITRE ↗Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)
For u-link Management API an unauthenticated remote attacker in a man-in-the-middle position can inject arbitrary comman
WeGIA is a web manager for charitable institutions. Prior to version 3.4.2, an OS Command Injection vulnerability was id
There are multiple unauthorized remote command execution vulnerabilities in the H3C ER2200G2, ERG2-450W, ERG2-1200W, ERG
An OS command injection vulnerability exists in MiniDVBLinux version 5.4 and earlier. The system’s web-based management
An OS command injection vulnerability exists in EnGenius EnShare Cloud Service version 1.4.11 and earlier. The usbintera
An OS command injection vulnerability exists in white-labeled DVRs manufactured by TVT, affecting a custom HTTP service
Multiple wireless router models from Sapido have an OS Command Injection vulnerability, allowing unauthenticated remote
WRH-733GBK and WRH-733GWH contain an improper neutralization of special elements used in an OS command ('OS Command Inje
WRH-733GBK and WRH-733GWH contain an improper neutralization of special elements used in an OS command ('OS Command Inje
Orkes Conductor v3.21.11 allows remote attackers to execute arbitrary OS commands through unrestricted access to Java cl
An OS command injection issue exists in Nimesa Backup and Recovery v2.3 and v2.4. If this vulnerability is exploited, an
The iSherlock developed by Hgiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to
An arbitrary file writing vulnerability in the Secure PDF eXchange (SPX) feature of Sophos Firewall versions older than
An issue was discovered in Eveo URVE Web Manager 27.02.2025. The application exposes a /_internal/pc/vpro.php localhost
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Calibre Web,
The WP Database Backup plugin for WordPress is vulnerable to OS Command Injection in versions before 5.2 via the mysqldu
Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.1
CodeIgniter is a PHP full-stack web framework. A command injection vulnerability present in versions prior to 4.6.2 affe
An OS command injection vulnerability exists in Russound MBX-PRE-D67F firmware version 3.1.6, allowing unauthenticated a
An OS command injection vulnerability exists in various legacy D-Link routers—including DIR-300 rev B and DIR-600 (firmw
TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a command injection vulnerability via the pin parameter
Claude Code is an agentic coding tool. In versions below 1.0.20, an error in command parsing makes it possible to bypass
The web interface of multiple D-Link routers, including DIR-600 rev B (≤2.14b01) and DIR-300 rev B (≤2.13), contains an
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] vul
Cherry Studio is a desktop client that supports for multiple LLM providers. From versions 1.2.5 to 1.5.1, Cherry Studio
An issue was discovered on KuWFi GC111 devices (Hardware Version: CPE-LM321_V3.2, Software Version: GC111-GL-LM321_V3.0_
Spreecommerce versions prior to 0.50.x contain a remote command execution vulnerability in the API's search functionalit
A remote unauthenticated attacker who has bypassed authentication could execute arbitrary OS commands to disclose, tamp
Multiple D-Link DIR-series routers, including DIR-110, DIR-412, DIR-600, DIR-610, DIR-615, DIR-645, and DIR-815 firmware
D-Link DIR-868L B1 router firmware version FW2.05WWB02 contains an unauthenticated OS command injection vulnerability in
TRENDnet TV-IP410 vA1.0R was discovered to contain an OS command injection vulnerability via the /server/cgi-bin/testser
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in SkyBridge BAS
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in TkEasyGUI ver
Roo Code is an AI-powered autonomous coding agent that lives in users' editors. In versions 3.26.6 and below, a Github w
Multiple CWE-78
Hoverfly is an open source API simulation tool. In versions 1.11.3 and prior, the middleware functionality in Hoverfly i
The cleanTcs mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-2025-59
The killProcesses mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-20
The cleanIptables mutation in Chaos Controller Manager is vulnerable to OS command injection. In conjunction with CVE-20
Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains an unauthenticated OS command injection vulnerability in the /ajax
Ilevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a vulnerability in its authentication mechanism. Unsanitized in
Certain models of Industrial Cellular Gateway developed by Planet Technology have an OS Command Injection vulnerability,
NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker c
HyperX NGENUITY software is potentially vulnerable to arbitrary code execution. HP is releasing updated software to addr
An issue in Datart v.1.0.0-rc.3 allows a remote attacker to execute arbitrary code via the INIT connection parameter.
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X60
ADB MCP Server is a MCP (Model Context Protocol) server for interacting with Android devices through ADB. In versions 0.
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X60
All versions of the package check-branches are vulnerable to Command Injection check-branches is a command-line tool tha
The Post By Email plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th
Frequently Asked Questions
What is CWE-78?
CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-78?
There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.
How can I protect against CWE-78 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.
Detect CWE-78 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.
Get Started