CWE-78
MITRE ↗Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers
Kenwood DMX958XR JKWifiService Command Injection Remote Code Execution Vulnerability. This vulnerability allows physical
Kenwood DMX958XR libSystemLib Command Injection Remote Code Execution Vulnerability. This vulnerability allows physicall
Kenwood DMX958XR JKWifiService Command Injection Remote Code Execution Vulnerability. This vulnerability allows physical
Kenwood DMX958XR JKWifiService Command Injection Remote Code Execution Vulnerability. This vulnerability allows physical
Kenwood DMX958XR libSystemLib Command injection Remote Code Execution Vulnerability. This vulnerability allows physicall
Due to an OS Command Injection vulnerability in SAP Business Connector, an authenticated attacker with administrative ac
pgAdmin 4 versions up to 9.9 are affected by a command injection vulnerability on Windows systems. This issue is caused
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiAP-S 6.2 a
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in
An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiMail vers
Multiple improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiMan
A vulnerability in the `start_app_server` function of parisneo/lollms-webui V12 (Strawberry) allows for path traversal a
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in
Brocade Fabric OS versions starting with 9.1.0 have root access removed, however, a local user with admin privilege can
A command injection vulnerability has been reported to affect QHora. If an attacker gains local network access who have
In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), shell injection in the SSH connecti
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the CLI o
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in
A improper neutralization of special elements used in an os command ('os command injection') vulnerability [CWE-78] in F
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] i
A vulnerable feature in the command line interface of EdgeConnect SD-WAN could allow an authenticated attacker to exploi
Dell Cloud Disaster Recovery, version(s) prior to 19.20, contain(s) an Improper Neutralization of Special Elements used
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.
A command injection vulnerability exists in the AOS-CX Operating System. Successful exploitation could allow an authenti
A command injection vulnerability exists in the AOS-CX Operating System. Successful exploitation could allow an authenti
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in UD-LT2 firmwa
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb 7.0.0
Frequently Asked Questions
What is CWE-78?
CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-78?
There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.
How can I protect against CWE-78 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.
Detect CWE-78 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.
Get Started