CWE-78
MITRE ↗Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)
A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exist
The Job Iteration API is an an extension for ActiveJob that make jobs interruptible and resumable Versions prior to 1.11
GitHub Kanban MCP Server is a Model Context Protocol (MCP) server for managing GitHub issues in Kanban board format and
An unauthenticated command injection vulnerability exists in WePresent WiPG-1000 firmware versions prior to 2.2.3.0, due
An authenticated multi-stage remote code execution vulnerability exists in Riverbed SteelCentral NetProfiler and NetExpr
An authenticated command injection vulnerability exists in Tiki Wiki CMS versions ≤14.1, ≤12.4 LTS, ≤9.10 LTS, and ≤6.14
An authenticated command injection vulnerability exists in OP5 Monitor through version 7.1.9 via the 'cmd_str' parameter
A remote command execution vulnerability exists in IPFire before version 2.19 Core Update 101 via the 'proxy.cgi' CGI in
A remote code execution vulnerability exists in multiple Netcore and Netis routers models with firmware released prior t
An unauthenticated command injection vulnerability exists in the cookie handling process of the lighttpd web server on D
A command injection vulnerability exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.0b60_
A command injection vulnerability exists in LILIN Digital Video Recorder (DVR) devices prior to firmware version 2.0b60_
An authentication bypass vulnerability exists in ETQ Reliance on the CG (legacy) platform. The application allowed login
A command injection vulnerability exists that can be exploited after authentication in VIGI NVR1104H-4P V1 and VIGI NVR2
An unauthenticated OS command injection vulnerability exists in VIGI NVR1104H-4P V1 and VIGI NVR2016H-16MP V2.This issue
An unauthenticated OS command injection vulnerability exists within Xdebug versions 2.5.5 and earlier, a PHP debugging e
Remote Control Server, maintained by Steppschuh, 3.1.1.12 allows unauthenticated remote code execution when authenticati
A command injection vulnerability exists in the eScan Web Management Console version 5.5-2. The application fails to pro
dag-factory is a library for Apache Airflow® to construct DAGs declaratively via configuration files. In versions 0.23.0
OS Command Injection in iSTAR Ultra products web application allows an authenticated attacker to gain even more privileg
An OS command injection vulnerability exists in WebTester version 5.x via the install2.php installation script. The para
A command injection vulnerability exists in GestioIP 3.0 commit ac67be and earlier in ip_checkhost.cgi. Crafted input to
An unauthenticated remote command execution vulnerability exists in Pandora FMS versions up to and including 5.0RC1 via
An OS command injection vulnerability exists in multiple Raidsonic NAS devices—specifically tested on IB-NAS5220 and IB-
A remote command execution vulnerability exists in ZPanel version 10.0.0.2 in its htpasswd module. When creating .htacce
An authenticated OS command injection vulnerability exists in various Linksys router models (tested on WRT160Nv2) runnin
An unauthenticated OS command injection vulnerability exists in the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model
The ICTBroadcast application unsafely passes session cookie data to shell processing, allowing an attacker to inject she
Netwin SurgeFTP version 23c8 and prior contains a vulnerability in its web-based administrative console that allows auth
Nagios XI Network Monitor prior to Graph Explorer component version 1.3 contains a command injection vulnerability in `v
Narcissus is vulnerable to remote code execution via improper input handling in its image configuration workflow. Specif
An unauthenticated OS command injection vulnerability exists in the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model
A command injection vulnerability affects the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) during WPA2 conf
The PPPoE configuration interface of the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) is vulnerable to comm
A command injection vulnerability exists in the 'passwd' parameter of the PPPoE setup process on the Shenzhen Aitemi M30
An unauthenticated OS command injection vulnerability exists in the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model
An unauthenticated remote command execution vulnerability exists in AjaXplorer (now known as Pydio Cells) versions prior
WAN Emulator v2.3 contains two unauthenticated command execution vulnerabilities. The result.php script calls shell_exec
The E-Mail Security Virtual Appliance (ESVA) (tested on version ESVA_2057) contains an unauthenticated command injection
PhpTax version 0.8 contains a remote code execution vulnerability in drawimage.php. The pfilez GET parameter is unsafely
ZEN Load Balancer versions 2.0 and 3.0-rc1 contain a command injection vulnerability in content2-2.cgi. The filelog para
Openfiler v2.x contains a command injection vulnerability in the system.html page. The device parameter is used to insta
Snort Report versions < 1.3.2 contains a remote command execution vulnerability in the nmap.php and nbtscan.php scripts.
Dolibarr ERP/CRM versions <= 3.1.1 and <= 3.2.0 contain a post-authenticated OS command injection vulnerability in its d
FreeNAS 0.7.2 prior to revision 5543 includes an unauthenticated command‐execution backdoor in its web interface. The ex
The StrongDM Windows service incorrectly handled input validation. Authenticated attackers could potentially exploit thi
The StrongDM macOS client incorrectly processed JSON-formatted messages. Attackers could potentially modify macOS system
A command injection vulnerability in Dahua EIMS versions prior to 2240008 allows unauthenticated remote attackers to exe
AnyShare contains a critical unauthenticated remote code execution vulnerability in the ServiceAgent API exposed on port
LSTM-Kirigaya's openmcp-client is a vscode plugin for mcp developer. Prior to version 0.1.12, when users on a Windows pl
Frequently Asked Questions
What is CWE-78?
CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-78?
There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.
How can I protect against CWE-78 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.
Detect CWE-78 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.
Get Started