CWE-78
MITRE ↗Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)
A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to execute arbitrary co
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in +F FS010M ver
Xorcom CompletePBX is vulnerable to command injection in the administrator Task Scheduler functionality, allowing for at
OS command injection vulnerability in the WEB UI (the setting page) exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If exp
A vulnerability in the “Remote Logging” functionality of the web application of ctrlX OS allows a remote authenticated (
A vulnerability in the web-based management interface of the Wireless LAN Controller feature of Cisco IOS XE Software co
The vCenter Server contains an authenticated command-execution vulnerability. A malicious actor with privileges to creat
eCharge Hardy Barth cPH2 check_req.php ntp Command Injection Remote Code Execution Vulnerability. This vulnerability all
eCharge Hardy Barth cPH2 nwcheckexec.php dest Command Injection Remote Code Execution Vulnerability. This vulnerability
eCharge Hardy Barth cPH2 index.php Command Injection Remote Code Execution Vulnerability. This vulnerability allows netw
File::Find::Rule through 0.34 for Perl is vulnerable to Arbitrary Code Execution when `grep()` encounters a crafted file
A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the
A vulnerability classified as critical was found in Wifi-soft UniBox Controller up to 20250506. Affected by this vulnera
A vulnerability, which was classified as critical, has been found in Wifi-soft UniBox Controller up to 20250506. Affecte
A vulnerability, which was classified as critical, was found in Wifi-soft UniBox Controller up to 20250506. This affects
An OS command injection vulnerability exists in the Edimax EW-7438RPn firmware version 1.13 and prior via the mp.asp for
An OS command injection vulnerability exists in the Edimax EW-7438RPn Mini firmware version 1.13 and prior via the syscm
An OS command injection vulnerability exists in the Blue Angel Software Suite running on embedded Linux devices via the
WRC-X3000GS, WRC-X3000GSA, and WRC-X3000GSN contain an improper neutralization of special elements used in an OS command
A user with specific node group editing permissions and a specially crafted class parameter could be used to execute com
Certain hybrid DVR models (HBF-09KD and HBF-16NK) from Hunt Electronic have an OS Command Injection vulnerability, allow
An authenticated command injection vulnerability exists in Pi-hole versions up to 3.3. When adding a domain to the allow
An authenticated remote code execution vulnerability exists in Pandora FMS version 7.0NG and earlier. The net_tools.php
Dokploy is a self-hostable Platform as a Service (PaaS) that simplifies the deployment and management of applications an
A command injection vulnerability in WebAdmin of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to adjac
An authenticated remote attacker can execute arbitrary commands with root privileges on affected devices due to lack of
An authenticated remote attacker can execute arbitrary commands with root privileges on affected devices due to lack of
An authenticated remote code execution vulnerability in PowerStick Wave Dual-Band Wifi Extender V1.0 allows an attacker
An OS command injection vulnerability exists in multiple D-Link routers (confirmed on DIR-300 rev A v1.05 and DIR-615 re
Nest is a framework for building scalable Node.js server-side applications. In versions 0.2.0 and below, a critical Remo
Kenwood DMX958XR ReadMVGImage Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-a
MiR software versions prior to version 3.0.0 are affected by a command injection vulnerability. A malicious HTTP reques
Improper Input Validation vulnerability in N-able N-central allows OS Command Injection.This issue affects N-central: be
Coolify versions prior to v4.0.0-beta.420.7 are vulnerable to a remote code execution vulnerability in the project deplo
A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attack
Cacti versions prior to 0.8.6-d contain a remote command execution vulnerability in the graph_view.php script. An authen
OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.11.
OS Command injection vulnerability in function OperateSSH in 1panel 2.0.8 allowing attackers to execute arbitrary comman
Certain models of NVR developed by Digiever has an OS Command Injection vulnerability, allowing authenticated remote att
FreePBX is an open-source web-based graphical user interface. From 17.0.19.11 to before 17.0.21, authenticated users of
Ilevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a misconfiguration in the sudoers file that allows passwordless
The N-Reporter, N-Cloud, and N-Probe developed by N-Partner has an OS Command Injection vulnerability, allowing authenti
git-commiters is a Node.js function module providing committers stats for their git repository. Prior to version 0.1.2,
Nagios XI < 2026R1 is vulnerable to an authenticated command injection vulnerability within the MongoDB Database, MySQL
IBM InfoSphere 11.7.0.0 through 11.7.1.6 Information Server could allow an authenticated user to execute arbitrary comma
Cursor is a code editor built for programming with AI. In versions 1.7 and below, when MCP uses OAuth authentication wit
Multiple OS command injection vulnerabilities exist in the swctrl functionality of Planet WGR-500 v1.3411b190912. A spec
Multiple OS command injection vulnerabilities exist in the swctrl functionality of Planet WGR-500 v1.3411b190912. A spec
Multiple OS command injection vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A
Multiple OS command injection vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A
Frequently Asked Questions
What is CWE-78?
CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-78?
There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.
How can I protect against CWE-78 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.
Detect CWE-78 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.
Get Started