CWE-78
MITRE ↗Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)
Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('
A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected de
A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected de
A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected de
UNI-NMS-Lite is vulnerable to a command injection attack that could allow an unauthenticated attacker to read or manipu
WGS-80HPT-V2 and WGS-4215-8T2S are vulnerable to a command injection attack that could allow an unauthenticated attacke
ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Neutralization of Special Elements
A remote attacker with administrator account can gain full control of the device due to improper neutralization of speci
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDir
dedupe is a python library that uses machine learning to perform fuzzy matching, deduplication and entity resolution qui
OPNsense before 25.1.8 contains an authenticated command injection vulnerability in its Bridge Interface Edit endpoint (
Valtimo is a platform for Business Process Automation. In versions before 12.16.0.RELEASE, and from 13.0.0.RELEASE to be
OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.0
OS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.0
Dell CloudLink, versions 8.0 through 8.1.2, contain vulnerability on restricted shell. A Privileged user with known pass
By providing a command-line argument starting with a semi-colon ; to an API endpoint created by the EnhancedCommandExecu
ChurchCRM is an open-source church management system. In versions prior to 6.5.3, the Database Restore functionality doe
The web application allows user input to pass unfiltered to a command executed on the underlying operating system. The v
CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell
An OS Command Injection vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE
A vulnerability was found in Roxy-WI up to 8.1.3. It has been declared as critical. Affected by this vulnerability is th
Command injection in the <redacted> parameter of a <redacted>.exe request leads to remote code execution as the root use
Authenticated command injection in the filename of a <redacted>.exe request leads to remote code execution as the root u
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Inje
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Inj
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Iocharger firmware
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Inje
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Inje
An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] vulnerability in Fortinet Fo
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "minute"
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "week" p
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "switch"
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "recHour
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "hour" p
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "user" p
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "pass" p
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "desc" p
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "limit"
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "sMinute
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "eHour"
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an OS command injection vulnerability via the "sHour"
The airPASS from NetVision Information has an OS Command Injection vulnerability, allowing remote attackers with regular
Linksys E8450 v1.2.00.360516 was discovered to contain a command injection vulnerability via the field id_email_check_bt
**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the CGI program of the legacy DSL
**UNSUPPORTED WHEN ASSIGNED** A post-authentication command injection vulnerability in the management commands of the le
Command injection vulnerability exists in iControl REST and BIG-IP TMOS Shell (tmsh) save command, which may allow an au
A command injection flaw was found in the text editor Emacs. It could allow a remote, unauthenticated attacker to execut
binance-trading-bot is an automated Binance trading bot with trailing buy/sell strategy. Authenticated users of binance-
An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] vulnerability in Fortinet Fo
Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE
Frequently Asked Questions
What is CWE-78?
CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-78?
There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.
How can I protect against CWE-78 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.
Detect CWE-78 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.
Get Started