CWE-78
MITRE ↗Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)
The Telenium Online Web Application is vulnerable due to a PHP endpoint accessible to unauthenticated network users that
TOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability via the mac parameter i
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe
Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe
Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an OS command injection vulnerability in mbus_build_from_
The iSherlock developed by HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to
An arbitrary OS command may be executed on the product by a remote unauthenticated attacker.
AMTT Hotel Broadband Operation System (HiBOS) contains an unauthenticated command injection vulnerability in the /manage
Antabot White-Jotter up to commit 9bcadc was discovered to contain an unauthenticated remote code execution (RCE) vulner
D-Link DNS-343 ShareCenter devices running firmware versions up to and including 1.05 contain a command injection vulner
win-cli-mcp-server resolveCommandPath Command Injection Remote Code Execution Vulnerability. This vulnerability allows r
Nagios XI versions prior to 2024R1.2 are vulnerable to remote code execution (RCE) through its NRDP (Nagios Remote Data
The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default
OS command injection vulnerability in Dynatrace ActiveGate ping extension up to 1.016 via crafted ip address.
PocketVJ CP PocketVJ-CP-v3 pvj version 3.9.1 contains an unauthenticated remote code execution vulnerability in the subm
D-Link DIR-1260 Wi-Fi router firmware versions up to and including v1.20B05 contain a command injection vulnerability wi
ThinPLUS developed by ThinPLUS has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to i
An issue in Ilevia EVE X1 Server Firmware Version v4.7.18.0.eden and before Logic Version v6.00 - 2025_07_21 and before
Claude Code is an agentic coding tool. Prior to version 2.0.31, due to an error in sed command parsing, it was possible
Unauthenticated OS Command Injection (start_upgrade.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitte
Unauthenticated OS Command Injection (restore_settings.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmi
Improper neutralization of special elements used in an OS command ('command injection') in Cursor allows an unauthorized
MCP Watch is a comprehensive security scanner for Model Context Protocol (MCP) servers. In 0.1.2 and earlier, the MCPSca
Collabora Online - Built-in CODE Server (richdocumentscode) provides a built-in server with all of the document editing
ALLNET ALL-RUT22GW v3.3.8 was discovered to contain an OS command injection vulnerability via the command parameter in t
Remote Keyboard Desktop 1.0.1 enables remote attackers to execute system commands via the rundll32.exe exported function
An issue was discovered in openmptcprouter thru 0.64 in file common/package/utils/sys-upgrade-helper/src/tools/sysupgrad
Selea Targa IP OCR-ANPR Camera contains an unauthenticated command injection vulnerability in utils.php that allows remo
Typora 1.7.4 contains a command injection vulnerability in the PDF export preferences that allows attackers to execute a
EasyPHP Webserver 14.1 contains an OS command injection vulnerability that allows unauthenticated attackers to execute a
Lilac-Reloaded for Nagios 2.0.8 contains a remote code execution vulnerability in the autodiscovery feature that allows
SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated OS command injection vulnerability that allows remote att
IceWarp14 X-File-Operation Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attac
MiniDVBLinux 5.4 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbi
SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated command injection vulnerability in the u
aws-mcp-server MCP server is vulnerable to command injection. An attacker can craft a prompt that once accessed by the M
mcp-remote is exposed to OS command injection when connecting to untrusted MCP servers due to crafted input from the aut
Cursor is a code editor built for programming with AI. In versions 1.17 through 1.2, there is a UI information disclosur
Cherry Studio is a desktop client that supports for multiple LLM providers. In version 1.5.1, a remote code execution (R
A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker
A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker
YoutubeDLSharp is a wrapper for the command-line video downloaders youtube-dl and yt-dlp. In versions starting from 1.0.
Cacti is an open source performance and fault management framework. Due to a flaw in multi-line SNMP result parser, auth
IBM Security Verify Directory 10.0.0 through 10.0.3 could allow a remote authenticated attacker to execute arbitrary com
OS command injection in the admin web console of Ivanti CSA before version 5.0.5 allows a remote authenticated attacker
Frequently Asked Questions
What is CWE-78?
CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-78?
There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.
How can I protect against CWE-78 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.
Detect CWE-78 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.
Get Started