Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)

1,941
CRITICAL
3,146
HIGH
963
MEDIUM
16
LOW
6,290 CVEs · Page 40/126
7.3
CVE-2025-12121

Lite XL versions 2.1.8 and prior contain a vulnerability in the system.exec function, which allowed arbitrary command ex

7.2
CVE-2025-20016

OS command injection vulnerability exists in network storage servers STEALTHONE D220/D340/D440 provided by Y'S corporati

7.2
CVE-2024-50566

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet F

7.2
CVE-2025-0356

NEC Corporation Aterm WX1500HP Ver.1.4.2 and earlier and WX3600HP Ver.1.5.3 and earlier allows a attacker to execute arb

7.2
CVE-2025-0528

A vulnerability, which was classified as critical, has been found in Tenda AC8, AC10 and AC18 16.03.10.20. Affected by t

7.2
CVE-2025-20617

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in UD-LT2 firmwa

7.2
CVE-2024-23690

The end-of-life Netgear FVS336Gv2 and FVS336Gv3 are affected by a command injection vulnerability in the Telnet interfac

7.2
CVE-2024-40584

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in

7.2
CVE-2024-50567

An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb 7.4.0

7.2
CVE-2024-55904

IBM DevOps Deploy 8.0 through 8.0.1.4, 8.1 through 8.1.0.0 / IBM UrbanCode Deploy 7.0 through 7.0.5.25, 7.1 through 7.1.

7.2
CVE-2025-26856

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in UD-LT2 firmwa

7.2
CVE-2024-53700

A command injection vulnerability has been reported to affect QHora. If exploited, the vulnerability could allow remote

7.2
CVE-2024-11253

A post-authentication command injection vulnerability in the "DNSServer” parameter of the diagnostic function in the Zyx

7.2
CVE-2024-12009

A post-authentication command injection vulnerability in the "ZyEE" function of the Zyxel EX5601-T1 firmware version V5.

7.2
CVE-2024-12010

A post-authentication command injection vulnerability in the ”zyUtilMailSend” function of the Zyxel AX7501-B1 firmware v

7.2
CVE-2025-27392

A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0). Affected devices do

7.2
CVE-2025-27393

A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0). Affected devices do

7.2
CVE-2025-27394

A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0). Affected devices do

7.2
CVE-2024-54018

Multiple improper neutralization of special elements used in an OS Command vulnerabilities [CWE-78] in FortiSandbox befo

7.2
CVE-2025-24306

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in +F FS010M ver

7.2
CVE-2025-0255

HCL DevOps Deploy / HCL Launch could allow a remote privileged authenticated attacker to execute arbitrary commands on t

7.2
CVE-2025-2257

The Total Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid plugin for WordPress is vulnerable to Remo

7.2
CVE-2024-54024

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in

7.2
CVE-2025-2773

BEC Technologies Multiple Routers sys ping Command Injection Remote Code Execution Vulnerability. This vulnerability all

7.2
CVE-2025-32821

A vulnerability in SMA100 allows a remote authenticated attacker with SSLVPN admin privileges can with admin privileges

7.2
CVE-2024-6486

The ImageMagick Engine ImageMagick Engine WordPress plugin before 1.7.11 for WordPress is vulnerable to OS Command Injec

7.2
CVE-2025-41385

An OS Command Injection issue exists in wivia 5 all versions. If this vulnerability is exploited, an arbitrary OS comman

7.2
CVE-2024-13089

An OS command injection vulnerability within the update functionality may allow an authenticated administrator to execut

7.2
CVE-2025-31104

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in

7.2
CVE-2025-39240

Some Hikvision Wireless Access Point are vulnerable to authenticated remote command execution due to insufficient input

7.2
CVE-2025-36529

An OS command injection issue exists in multiple versions of TB-eye network recorders and AHD recorders. If this vulnera

7.2
CVE-2025-7145

ThreatSonar Anti-Ransomware developed by TeamT5 has an OS Command Injection vulnerability, allowing remote attackers wit

7.2
CVE-2025-6770

OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2 allows a remote authenticated atta

7.2
CVE-2025-6771

OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2,12.4.0.3 and 12.3.0.3 allows a re

7.2
CVE-2025-41673

A high privileged remote attacker can execute arbitrary system commands via POST requests in the send_sms action due to

7.2
CVE-2025-41674

A high privileged remote attacker can execute arbitrary system commands via POST requests in the diagnostic action due t

7.2
CVE-2025-41675

A high privileged remote attacker can execute arbitrary system commands via GET requests in the cloud server communicati

7.2
CVE-2025-53472

WRC-BE36QS-B and WRC-W701-B contain an improper neutralization of special elements used in an OS command ('OS Command In

7.2
CVE-2024-53286

Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in DDNS Record

7.2
CVE-2013-10059

An authenticated OS command injection vulnerability exists in various D-Link routers (tested on DIR-615H1 running firmwa

7.2
CVE-2013-10060

An authenticated OS command injection vulnerability exists in Netgear routers (tested on the DGN2200B model) firmware ve

7.2
CVE-2013-10061

An authenticated OS command injection vulnerability exists in Netgear routers (tested on the DGN1000B model firmware ver

7.2
CVE-2025-54136

Cursor is a code editor built for programming with AI. In versions 1.2.4 and below, attackers can achieve remote and per

7.2
CVE-2025-49813

An improper neutralization of special elements used in an OS Command ("OS Command Injection") vulnerability [CWE-78] in

7.2
CVE-2025-53508

Multiple products provided by iND Co.,Ltd contain an OS command injection vulnerability. If exploited, an arbitrary OS c

7.2
CVE-2025-29887

A command injection vulnerability has been reported to affect QuRouter 2.5.1. If a remote attacker gains an administrato

7.2
CVE-2025-9377 KEV

The authenticated remote command execution (RCE) vulnerability exists in the Parental Control page on TP-Link Archer C7

7.2
CVE-2025-8613

Vacron Camera ping Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to

7.2
CVE-2025-37126

A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN Gateways Command Line Interface that allows remote

7.2
CVE-2025-58116

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in WN-7D36QR and

Frequently Asked Questions

What is CWE-78?

CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-78?

There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.

How can I protect against CWE-78 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.

Detect CWE-78 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.

Get Started