Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)

1,941
CRITICAL
3,146
HIGH
963
MEDIUM
16
LOW
6,290 CVEs · Page 42/126
6.8
CVE-2025-8636

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers

6.8
CVE-2025-8637

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers

6.8
CVE-2025-8638

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers

6.8
CVE-2025-8639

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers

6.8
CVE-2025-8640

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers

6.8
CVE-2025-8641

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers

6.8
CVE-2025-8642

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers

6.8
CVE-2025-8643

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers

6.8
CVE-2025-8644

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers

6.8
CVE-2025-8645

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers

6.8
CVE-2025-8646

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers

6.8
CVE-2025-8647

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers

6.8
CVE-2025-8648

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers

6.8
CVE-2025-8649

Kenwood DMX958XR JKWifiService Command Injection Remote Code Execution Vulnerability. This vulnerability allows physical

6.8
CVE-2025-8650

Kenwood DMX958XR libSystemLib Command Injection Remote Code Execution Vulnerability. This vulnerability allows physicall

6.8
CVE-2025-8651

Kenwood DMX958XR JKWifiService Command Injection Remote Code Execution Vulnerability. This vulnerability allows physical

6.8
CVE-2025-8652

Kenwood DMX958XR JKWifiService Command Injection Remote Code Execution Vulnerability. This vulnerability allows physical

6.8
CVE-2025-8655

Kenwood DMX958XR libSystemLib Command injection Remote Code Execution Vulnerability. This vulnerability allows physicall

6.8
CVE-2025-42892

Due to an OS Command Injection vulnerability in SAP Business Connector, an authenticated attacker with administrative ac

6.8
CVE-2025-12763

pgAdmin 4 versions up to 9.9 are affected by a command injection vulnerability on Windows systems. This issue is caused

6.8
CVE-2025-55055

CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

6.7
CVE-2024-26012

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiAP-S 6.2 a

6.7
CVE-2024-40587

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in

6.7
CVE-2024-56497

An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiMail vers

6.7
CVE-2024-32123

Multiple improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiMan

6.7
CVE-2024-10019

A vulnerability in the `start_app_server` function of parisneo/lollms-webui V12 (Strawberry) allows for path traversal a

6.7
CVE-2024-54025

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in

6.7
CVE-2025-1976 KEV

Brocade Fabric OS versions starting with 9.1.0 have root access removed, however, a local user with admin privilege can

6.7
CVE-2024-13087

A command injection vulnerability has been reported to affect QHora. If an attacker gains local network access who have

6.7
CVE-2025-47228

In the Production Environment extension in Netmake ScriptCase through 9.12.006 (23), shell injection in the SSH connecti

6.7
CVE-2025-52988

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in the CLI o

6.7
CVE-2025-30096

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.

6.7
CVE-2025-30097

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.

6.7
CVE-2025-30098

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.

6.7
CVE-2025-27759

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in

6.7
CVE-2025-47857

A improper neutralization of special elements used in an os command ('os command injection') vulnerability [CWE-78] in F

6.7
CVE-2024-45325

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] i

6.7
CVE-2025-37129

A vulnerable feature in the command line interface of EdgeConnect SD-WAN could allow an authenticated attacker to exploi

6.7
CVE-2025-43943

Dell Cloud Disaster Recovery, version(s) prior to 19.20, contain(s) an Improper Neutralization of Special Elements used

6.7
CVE-2025-43890

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.

6.7
CVE-2025-43906

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.

6.7
CVE-2025-43911

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.

6.7
CVE-2025-36566

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.

6.7
CVE-2025-36567

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.

6.7
CVE-2025-36569

Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.

6.7
CVE-2025-37157

A command injection vulnerability exists in the AOS-CX Operating System. Successful exploitation could allow an authenti

6.7
CVE-2025-37158

A command injection vulnerability exists in the AOS-CX Operating System. Successful exploitation could allow an authenti

6.6
CVE-2024-48890

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in

6.6
CVE-2025-23237

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in UD-LT2 firmwa

6.6
CVE-2024-50569

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb 7.0.0

Frequently Asked Questions

What is CWE-78?

CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-78?

There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.

How can I protect against CWE-78 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.

Detect CWE-78 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.

Get Started