CWE-78
MITRE ↗Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)
Lite XL versions 2.1.8 and prior contain a vulnerability in the system.exec function, which allowed arbitrary command ex
OS command injection vulnerability exists in network storage servers STEALTHONE D220/D340/D440 provided by Y'S corporati
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet F
NEC Corporation Aterm WX1500HP Ver.1.4.2 and earlier and WX3600HP Ver.1.5.3 and earlier allows a attacker to execute arb
A vulnerability, which was classified as critical, has been found in Tenda AC8, AC10 and AC18 16.03.10.20. Affected by t
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in UD-LT2 firmwa
The end-of-life Netgear FVS336Gv2 and FVS336Gv3 are affected by a command injection vulnerability in the Telnet interfac
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in
An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb 7.4.0
IBM DevOps Deploy 8.0 through 8.0.1.4, 8.1 through 8.1.0.0 / IBM UrbanCode Deploy 7.0 through 7.0.5.25, 7.1 through 7.1.
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in UD-LT2 firmwa
A command injection vulnerability has been reported to affect QHora. If exploited, the vulnerability could allow remote
A post-authentication command injection vulnerability in the "DNSServer” parameter of the diagnostic function in the Zyx
A post-authentication command injection vulnerability in the "ZyEE" function of the Zyxel EX5601-T1 firmware version V5.
A post-authentication command injection vulnerability in the ”zyUtilMailSend” function of the Zyxel AX7501-B1 firmware v
A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0). Affected devices do
A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0). Affected devices do
A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0). Affected devices do
Multiple improper neutralization of special elements used in an OS Command vulnerabilities [CWE-78] in FortiSandbox befo
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in +F FS010M ver
HCL DevOps Deploy / HCL Launch could allow a remote privileged authenticated attacker to execute arbitrary commands on t
The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Remo
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in
BEC Technologies Multiple Routers sys ping Command Injection Remote Code Execution Vulnerability. This vulnerability all
A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN admin privileges can with admin privileges
The ImageMagick Engine ImageMagick Engine WordPress plugin before 1.7.11 for WordPress is vulnerable to OS Command Injec
An OS Command Injection issue exists in wivia 5 all versions. If this vulnerability is exploited, an arbitrary OS comman
An OS command injection vulnerability within the update functionality may allow an authenticated administrator to execut
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in
Some Hikvision Wireless Access Point are vulnerable to authenticated remote command execution due to insufficient input
An OS command injection issue exists in multiple versions of TB-eye network recorders and AHD recorders. If this vulnera
ThreatSonar Anti-Ransomware developed by TeamT5 has an OS Command Injection vulnerability, allowing remote attackers wit
OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2 allows a remote authenticated atta
OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2,12.4.0.3 and 12.3.0.3 allows a re
A high privileged remote attacker can execute arbitrary system commands via POST requests in the send_sms action due to
A high privileged remote attacker can execute arbitrary system commands via POST requests in the diagnostic action due t
A high privileged remote attacker can execute arbitrary system commands via GET requests in the cloud server communicati
WRC-BE36QS-B and WRC-W701-B contain an improper neutralization of special elements used in an OS command ('OS Command In
Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in DDNS Record
An authenticated OS command injection vulnerability exists in various D-Link routers (tested on DIR-615H1 running firmwa
An authenticated OS command injection vulnerability exists in Netgear routers (tested on the DGN2200B model) firmware ve
An authenticated OS command injection vulnerability exists in Netgear routers (tested on the DGN1000B model firmware ver
Cursor is a code editor built for programming with AI. In versions 1.2.4 and below, attackers can achieve remote and per
An improper neutralization of special elements used in an OS Command ("OS Command Injection") vulnerability [CWE-78] in
Multiple products provided by iND Co.,Ltd contain an OS command injection vulnerability. If exploited, an arbitrary OS c
A command injection vulnerability has been reported to affect QuRouter 2.5.1. If a remote attacker gains an administrato
The authenticated remote command execution (RCE) vulnerability exists in the Parental Control page on TP-Link Archer C7
Vacron Camera ping Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to
A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN Gateways Command Line Interface that allows remote
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in WN-7D36QR and
Frequently Asked Questions
What is CWE-78?
CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-78?
There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.
How can I protect against CWE-78 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.
Detect CWE-78 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.
Get Started