CWE-78
MITRE ↗Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)
OS Command Injection vulnerability in Ruijie RG-YST EST, YSTAP_3.0(1)B11P280YST250F V1.xxV2.xx allowing attackers to exe
OS Command Injection vulnerability in Ruijie M18 EW_3.0(1)B11P226_M18_10223116 allowing attackers to execute arbitrary c
OS Command Injection vulnerability in Ruijie X30-PRO X30-PRO-V1_09241521 allowing attackers to execute arbitrary command
OS Command Injection vulnerability in Ruijie X60 PRO X60_10212014RG-X60 PRO V1.00/V2.00 allowing attackers to execute ar
OS Command Injection vulnerability in Ruijie X60 PRO X60_10212014RG-X60 PRO V1.00/V2.00 allowing attackers to execute ar
OS Command Injection vulnerability in Ruijie RG-EW1800GX PRO B11P226_EW1800GX-PRO_10223117 allowing attackers to execute
OS Command Injection vulnerability in Ruijie RG-EW1200G PRO RG-EW1200G PRO V1.00/V2.00/V3.00/V4.00 allowing attackers to
OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR600W allowing attackers to execute arbitrary commands via a cr
OS Command Injection vulnerability in Ruijie RG-BCR RG-BCR860 allowing attackers to execute arbitrary commands via a cra
OS Command Injection vulnerability in Ruijie RG-S1930 S1930SWITCH_3.0(1)B11P230 allowing attackers to execute arbitrary
IBM Aspera Orchestrator 4.0.0 through 4.1.0 could allow an authenticated user to execute arbitrary commands with elevate
reNgine 2.2.0 contains a command injection vulnerability in the nmap_cmd parameter of scan engine configuration that all
FreePBX 16 contains an authenticated remote code execution vulnerability in the API module that allows attackers with va
Atcom 100M IP Phones firmware version 2.7.x.x contains an authenticated command injection vulnerability in the web confi
BrainyCP 1.0 contains an authenticated remote code execution vulnerability that allows logged-in users to inject arbitra
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0
Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0
Microhard Systems IPn4G 1.1.0 contains a service vulnerability that allows authenticated users to enable a restricted SS
FaceSentry 6.4.8 contains an authenticated remote command injection vulnerability in pingTest.php and tcpPortTest.php sc
SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an authenticated command injection vulnerability in the www-data-handler.ph
VPN Firewall developed by QNO Technology has an OS Command Injection vulnerability, allowing authenticated remote attack
VPN Firewall developed by QNO Technology has an OS Command Injection vulnerability, allowing authenticated remote attack
Cypress Solutions CTM-200 2.7.1 contains an authenticated command injection vulnerability in the firmware upgrade script
meterN 1.2.3 contains an authenticated remote code execution vulnerability in admin_meter2.php and admin_indicator2.php
Gargoyle router management utility versions 1.5.x contain an authenticated OS command execution vulnerability in /utilit
RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions prior to 0.23.0, a low-privileged aut
When running in Appliance mode, a highly privileged authenticated attacker with access to SCP and SFTP may be able to by
Gitk is a Tcl/Tk based Git history browser. Starting with 2.41.0, a Git repository can be crafted in such a way that wit
Git GUI allows you to use the Git source control management tools via a GUI. A malicious repository can ship versions of
iTop is an web based IT Service Management tool. Prior to versions 2.7.12, 3.1.3, and 3.2.1, server code execution is po
HAX CMS PHP allows users to manage their microsite universe with a PHP backend. Prior to version 11.0.3, the `gitImportS
RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build allows OS command injection via a certain parameter in an API route.
Cursor is a code editor built for programming with AI. Cursor allows writing in-workspace files with no user approval in
squid/cachemgr.cgi in Webmin before 2.600 does not properly quote arguments. This is relevant if Webmin's Squid module a
Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection. Thi
An improper input validation vulnerability was discovered in the NTP server configuration field of the Network-M2 card.
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Neutralization of Special Elements
An unauthenticated local attacker can inject a command that is subsequently executed as root, leading to a privilege esc
The web application allows user input to pass unfiltered to a command executed on the underlying operating system. An at
A command injection vulnerability has been reported to affect HybridDesk Station. If an attacker gains local network acc
Figma Desktop for Windows version 125.6.5 contains a command injection vulnerability in the local plugin loader. An atta
EMCLI contains a high severity vulnerability where improper neutralization of special elements used in an OS command cou
Dell CloudLink, versions prior to 8.2, contain a vulnerability where a privileged user with known password can run comma
Dell CloudLink, versions prior to 8.2, contain a vulnerability where a privileged user with known password can run comma
OS Command Injection vulnerability in Revolution Pi version 2022-07-28-revpi-buster from KUNBUS GmbH. This vulnerability
Linksys E1000 devices through 2.1.02, E1200 devices before 2.0.05, and E3200 devices through 1.0.04 allow OS command inj
Hikvision CSMP (Comprehensive Security Management Platform) iSecure Center through 2024-08-01 allows execution of a comm
ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Neutralization of Special Elements
Frequently Asked Questions
What is CWE-78?
CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-78?
There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.
How can I protect against CWE-78 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.
Detect CWE-78 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.
Get Started