Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)

1,941
CRITICAL
3,146
HIGH
963
MEDIUM
16
LOW
6,290 CVEs · Page 33/126
9.8
CVE-2025-10659

The Telenium Online Web Application is vulnerable due to a PHP endpoint accessible to unauthenticated network users that

9.8
CVE-2025-61045

TOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability via the mac parameter i

9.8
CVE-2025-59735

Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe

9.8
CVE-2025-59736

Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe

9.8
CVE-2025-59737

Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe

9.8
CVE-2025-59738

Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe

9.8
CVE-2025-59739

Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe

9.8
CVE-2025-59740

Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe

9.8
CVE-2025-59741

Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe

9.8
CVE-2025-34513

Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an OS command injection vulnerability in mbus_build_from_

9.8
CVE-2025-11900

The iSherlock developed by HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to

9.8
CVE-2025-6542

An arbitrary OS command may be executed on the product by a remote unauthenticated attacker.

9.8
CVE-2016-15048

AMTT Hotel Broadband Operation System (HiBOS) contains an unauthenticated command injection vulnerability in the /manage

9.8
CVE-2025-60803

Antabot White-Jotter up to commit 9bcadc was discovered to contain an unauthenticated remote code execution (RCE) vulner

9.8
CVE-2018-25120

D-Link DNS-343 ShareCenter devices running firmware versions up to and including 1.05 contain a command injection vulner

9.8
CVE-2025-11202

win-cli-mcp-server resolveCommandPath Command Injection Remote Code Execution Vulnerability. This vulnerability allows r

9.8
CVE-2024-14003

Nagios XI versions prior to 2024R1.2 are vulnerable to remote code execution (RCE) through its NRDP (Nagios Remote Data

9.8
CVE-2025-11953 KEV

The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default

9.8
CVE-2025-61304

OS command injection vulnerability in Dynatrace ActiveGate ping extension up to 1.016 via crafted ip address.

9.8
CVE-2025-63334

PocketVJ CP PocketVJ-CP-v3 pvj version 3.9.1 contains an unauthenticated remote code execution vulnerability in the subm

9.8
CVE-2022-50596

D-Link DIR-1260 Wi-Fi router firmware versions up to and including v1.20B05 contain a command injection vulnerability wi

9.8
CVE-2025-13284

ThinPLUS developed by ThinPLUS has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to i

9.8
CVE-2025-60738

An issue in Ilevia EVE X1 Server Firmware Version v4.7.18.0.eden and before Logic Version v6.00 - 2025_07_21 and before

9.8
CVE-2025-64755

Claude Code is an agentic coding tool. Prior to version 2.0.31, due to an error in sed command parsing, it was possible

9.8
CVE-2025-66253

Unauthenticated OS Command Injection (start_upgrade.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitte

9.8
CVE-2025-66261

Unauthenticated OS Command Injection (restore_settings.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmi

9.8
CVE-2025-62354

Improper neutralization of special elements used in an OS command ('command injection') in Cursor allows an unauthorized

9.8
CVE-2025-66401

MCP Watch is a comprehensive security scanner for Model Context Protocol (MCP) servers. In 0.1.2 and earlier, the MCPSca

9.8
CVE-2025-66208

Collabora Online - Built-in CODE Server (richdocumentscode) provides a built-in server with all of the document editing

9.8
CVE-2025-29269

ALLNET ALL-RUT22GW v3.3.8 was discovered to contain an OS command injection vulnerability via the command parameter in t

9.8
CVE-2025-66576

Remote Keyboard Desktop 1.0.1 enables remote attackers to execute system commands via the rundll32.exe exported function

9.8
CVE-2025-65882

An issue was discovered in openmptcprouter thru 0.64 in file common/package/utils/sys-upgrade-helper/src/tools/sysupgrad

9.8
CVE-2021-47728

Selea Targa IP OCR-ANPR Camera contains an unauthenticated command injection vulnerability in utils.php that allows remo

9.8
CVE-2024-14010

Typora 1.7.4 contains a command injection vulnerability in the PDF export preferences that allows attackers to execute a

9.8
CVE-2023-53941

EasyPHP Webserver 14.1 contains an OS command injection vulnerability that allows unauthenticated attackers to execute a

9.8
CVE-2023-53948

Lilac-Reloaded for Nagios 2.0.8 contains a remote code execution vulnerability in the autodiscovery feature that allows

9.8
CVE-2023-53963

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated OS command injection vulnerability that allows remote att

9.8
CVE-2025-14500

IceWarp14 X-File-Operation Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attac

9.8
CVE-2022-50691

MiniDVBLinux 5.4 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbi

9.8
CVE-2022-50794

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated command injection vulnerability in the u

9.6
CVE-2025-5277

aws-mcp-server MCP server is vulnerable to command injection. An attacker can craft a prompt that once accessed by the M

9.6
CVE-2025-6514

mcp-remote is exposed to OS command injection when connecting to untrusted MCP servers due to crafted input from the aut

9.6
CVE-2025-54133

Cursor is a code editor built for programming with AI. In versions 1.17 through 1.2, there is a UI information disclosur

9.6
CVE-2025-54382

Cherry Studio is a desktop client that supports for multiple LLM providers. In version 1.5.1, a remote code execution (R

9.4
CVE-2025-54948 KEV

A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker

9.4
CVE-2025-54987

A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker

9.2
CVE-2025-43858

YoutubeDLSharp is a wrapper for the command-line video downloaders youtube-dl and yt-dlp. In versions starting from 1.0.

9.1
CVE-2025-22604

Cacti is an open source performance and fault management framework. Due to a flaw in multi-line SNMP result parser, auth

9.1
CVE-2024-51450

IBM Security Verify Directory 10.0.0 through 10.0.3 could allow a remote authenticated attacker to execute arbitrary com

9.1
CVE-2024-47908

OS command injection in the admin web console of Ivanti CSA before version 5.0.5 allows a remote authenticated attacker

Frequently Asked Questions

What is CWE-78?

CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-78?

There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.

How can I protect against CWE-78 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.

Detect CWE-78 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.

Get Started