CWE-78
MITRE ↗Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)
The gix-transport crate before 0.36.1 for Rust allows command execution via the "gix clone 'ssh://-oProxyCommand=open$IF
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TUBITAK BILG
feiskyer mcp-kubernetes-server through 0.1.11 allows OS command injection, even in read-only mode, via /mcp/kubectl beca
Gitk is a Tcl/Tk based Git history browser. Starting with 1.7.0, when a user clones an untrusted repository and runs git
Thor before 1.4.0 can construct an unsafe shell command from library input. NOTE: this is disputed by the Supplier becau
A vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0). Affected devices do
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Iocharger firmware
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Inje
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability allows OS Command Inje
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Newtec/iDire
A Remote Code Execution Vulnerability exists in the product and version listed above. The vulnerability is due to lack o
DumpDrop is a stupid simple file upload application that provides an interface for dragging and dropping files. An OS Co
A command injection vulnerability in the Palo Alto Networks PAN-OS OpenConfig plugin enables an authenticated administra
Smartwares cameras CIP-37210AT and C724IP, as well as others which share the same firmware in versions up to 3.3.0, are
The authenticated firmware update capability of the firmware for Mennekes Smart / Premium Chargingpoints can be abused f
The authenticated time setting capability of the firmware for Mennekes Smart / Premium Chargingpoints can be abused for
The authenticated SCU firmware command of the firmware for Mennekes Smart / Premium Chargingpoints can be abused for com
A critical OS Command Injection vulnerability has been identified in the FAST LTA Silent Brick WebUI, allowing remote at
Os command injection vulnerability in e-solutions e-management. This vulnerability allows an attacker to execute arbitra
A remote attacker with web administrator privileges can exploit the device’s web interface to execute arbitrary system c
This vulnerability involves command injection in tcpdump within Moxa products, enabling an authenticated attacker with c
Stored Cross-Site Scripting (XSS) in DoWISP in versions prior to 1.16.2.50, which consists of an stored XSS through the
A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypas
A command injection vulnerability in the Palo Alto Networks Cortex XDR® Broker VM allows an authenticated user to execut
Web-Check is an all-in-one OSINT tool for analyzing any website. A command injection vulnerability exists in the screens
motionEye is an online interface for the software motion, a video surveillance program with motion detection. In version
On MOBOTIX P3 cameras before MX-V4.7.2.18 and Mx6 cameras before MX-V5.2.0.61, the tcpdump feature does not properly val
An authenticated user can perform command injection via unsanitized input to the NetFax Server’s ping functionality via
Atheos is a self-hosted browser-based cloud integrated development environment. Prior to version 6.0.4, improper use of
A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypas
An OS command injection vulnerability exists in sar2html version 3.2.2 and prior via the plot parameter in index.php. Th
Meridian Technique Materialise OrthoView through 7.5.1 allows OS Command Injection when servlet sharing is enabled.
Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 fail to sanitize user input prior to passing the inp
An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /h
An OS command injection vulnerability exists in the Chinese versions of Sangfor Endpoint Detection and Response (EDR) ma
An authenticated command injection vulnerability exists in the Beward N100 IP Camera firmware version M2.1.6.04C014 via
A remote command injection vulnerability exists in Vacron Network Video Recorder (NVR) devices v1.4 due to improper inpu
A remote command injection vulnerability exists in the confirm.php interface of the WIFISKY 7-layer Flow Control Router
An OS command injection vulnerability exists in the OptiLink ONT1GEW GPON router firmware version V2.1.11_X101 Build 112
An unauthenticated command injection vulnerability exists in AVTECH DVR devices via Search.cgi?action=cgi_query. The use
An OS command injection vulnerability exists in AVTECH DVR, NVR, and IP camera devices within the adcommand.cgi endpoint
An OS command injection vulnerability exists in AVTECH IP camera, DVR, and NVR devices via the PwdGrp.cgi endpoint, whic
RestDB's Codehooks.io MCP Server is an MCP server on the Codehooks.io platform. Prior to version 0.2.2, the MCP server i
An unauthenticated command injection vulnerability exists in stamparm/maltrail (Maltrail) versions <=0.54. A remote atta
A command injection vulnerability exists in IGEL OS versions prior to 11.04.270 within the Secure Terminal and Secure Sh
An authenticated command injection vulnerability exists in the Polycom HDX Series command shell interface accessible ove
An OS command injection vulnerability exists in Mako Server versions 2.5 and 2.6, specifically within the tutorial inter
An unauthenticated command injection vulnerability exists in VICIdial versions 2.9 RC1 through 2.13 RC1, within the vici
An unauthenticated command injection vulnerability exists in Serviio Media Server versions 1.4 through 1.8 on Windows, i
A remote code execution vulnerability exists in CryptoLog (PHP version, discontinued since 2009) due to a chained exploi
Frequently Asked Questions
What is CWE-78?
CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-78?
There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.
How can I protect against CWE-78 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.
Detect CWE-78 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.
Get Started