Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)

1,941
CRITICAL
3,146
HIGH
963
MEDIUM
16
LOW
6,290 CVEs · Page 34/126
9.1
CVE-2025-24383

Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('

9.1
CVE-2024-41788

A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected de

9.1
CVE-2024-41789

A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected de

9.1
CVE-2024-41790

A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected de

9.1
CVE-2025-46271

UNI-NMS-Lite is vulnerable to a command injection attack that could allow an unauthenticated attacker to read or manipu

9.1
CVE-2025-46272

WGS-80HPT-V2 and WGS-4215-8T2S are vulnerable to a command injection attack that could allow an unauthenticated attacke

9.1
CVE-2025-43562

ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Neutralization of Special Elements

9.1
CVE-2025-3626

A remote attacker with administrator account can gain full control of the device due to improper neutralization of speci

9.1
CVE-2025-46117

An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDir

9.1
CVE-2025-54430

dedupe is a python library that uses machine learning to perform fuzzy matching, deduplication and entity resolution qui

9.1
CVE-2025-50989

OPNsense before 25.1.8 contains an authenticated command injection vulnerability in its Bridge Interface Edit endpoint (

9.1
CVE-2025-58059

Valtimo is a platform for Business Process Automation. In versions before 12.16.0.RELEASE, and from 13.0.0.RELEASE to be

9.1
CVE-2025-60964

OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.0

9.1
CVE-2025-60965

OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.0

9.1
CVE-2025-45378

Dell CloudLink, versions 8.0 through 8.1.2, contain vulnerability on restricted shell. A Privileged user with known pass

9.1
CVE-2025-35028

By providing a command-line argument starting with a semi-colon ; to an API endpoint created by the EnhancedCommandExecu

9.1
CVE-2025-68109

ChurchCRM is an open-source church management system. In versions prior to 6.5.3, the Database Restore functionality doe

9.0
CVE-2025-24936

The web application allows user input to pass unfiltered to a command executed on the underlying operating system. The v

9.0
CVE-2025-48703 KEV

CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell

9.0
CVE-2025-9976

An OS Command Injection vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE

8.8
CVE-2024-13129

A vulnerability was found in Roxy-WI up to 8.1.3. It has been declared as critical. Affected by this vulnerability is th

8.8
CVE-2024-43648

Command injection in the <redacted> parameter of a <redacted>.exe request leads to remote code execution as the root use

8.8
CVE-2024-43649

Authenticated command injection in the filename of a <redacted>.exe request leads to remote code execution as the root u

8.8
CVE-2024-43652

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Inje

8.8
CVE-2024-43653

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability  allows OS Command Inj

8.8
CVE-2024-43654

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Iocharger firmware

8.8
CVE-2024-43656

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Inje

8.8
CVE-2024-43657

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Inje

8.8
CVE-2024-27778

An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] vulnerability in Fortinet Fo

8.8
CVE-2024-57011

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "minute"

8.8
CVE-2024-57012

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "week" p

8.8
CVE-2024-57013

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "switch"

8.8
CVE-2024-57014

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "recHour

8.8
CVE-2024-57015

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "hour" p

8.8
CVE-2024-57016

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "user" p

8.8
CVE-2024-57017

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "pass" p

8.8
CVE-2024-57018

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "desc" p

8.8
CVE-2024-57019

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "limit"

8.8
CVE-2024-57020

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "sMinute

8.8
CVE-2024-57021

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "eHour"

8.8
CVE-2024-57022

TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "sHour"

8.8
CVE-2025-0457

The airPASS from NetVision Information has an OS Command Injection vulnerability, allowing remote attackers with regular

8.8
CVE-2024-57542

Linksys E8450 v1.2.00.360516 was discovered to contain a command injection vulnerability via the field id_email_check_bt

8.8
CVE-2024-40890 KEV

**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL

8.8
CVE-2024-40891 KEV

**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the le

8.8
CVE-2025-20029

Command injection vulnerability exists in iControl REST and BIG-IP TMOS Shell (tmsh) save command, which may allow an au

8.8
CVE-2025-1244

A command injection flaw was found in the text editor Emacs. It could allow a remote, unauthenticated attacker to execut

8.8
CVE-2025-27106

binance-trading-bot is an automated Binance trading bot with trailing buy/sell strategy. Authenticated users of binance-

8.8
CVE-2024-52961

An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] vulnerability in Fortinet Fo

8.8
CVE-2024-55590

Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE

Frequently Asked Questions

What is CWE-78?

CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-78?

There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.

How can I protect against CWE-78 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.

Detect CWE-78 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.

Get Started