CWE-78
MITRE ↗Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)
Dogfood CRM version 2.0.10 contains a remote command execution vulnerability in the spell.php script used by its mail su
ContentKeeper Web Appliance (now maintained by Impero Software) versions prior to 125.10 are vulnerable to remote comman
StreamVault is a multi-platform video parsing and downloading tool. Prior to version 250822, after logging into the Stre
The ns_backup extension through 13.0.2 for TYPO3 allows command injection.
@akoskm/create-mcp-server-stdio is an MCP server starter kit that uses the StdioServerTransport. Prior to version 0.0.13
OS Command ('OS Command Injection') vulnerability in Calix GigaCenter ONT (Quantenna SoC modules) allows authenticated a
CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists
CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists
Zabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get parameters, allowing an attacker to inject unex
An OS command injection vulnerability has been discovered in the Vitogate 300, which can be exploited by malicious users
SonarQube Server and Cloud is a static analysis solution for continuous code quality and security inspection. A command
An OS command injection vulnerability in user interface in Western Digital My Cloud firmware prior to 5.31.108 on NAS pl
AVTECH devices that include the CloudSetup.cgi management endpoint are vulnerable to authenticated OS command injection.
The FreePBX Endpoint Manager module includes a Network Scanning feature that provides web-based access to nmap functiona
Ruijie RG-UAC Application Management Gateway contains a command injection vulnerability via the 'nmc_sync.php' interface
BYTEVALUE Intelligent Flow Control Router contains a command injection vulnerability via the /goform/webRead/open endpoi
GeoVision embedded IP devices, confirmed on GV-BX1500 and GV-MFD1501, contain a remote command injection vulnerability v
Kottster is a self hosted Node.js admin panel. From versions 3.2.0 to before 3.3.2, Kottster contains a pre-authenticati
Command injection vulnerability exists in the “Logging” page of the web-based configuration utility. An authenticated us
The “Diagnostics Tools” page of the web-based configuration utility does not properly validate user-controlled input, al
CLUSTERPRO X for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2 and EXPRESSCLUSTER X for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2, C
IPCop versions up to and including 2.1.9 contain an authenticated remote code execution vulnerability within the web-bas
TG8 Firewall contains a pre-authentication remote code execution vulnerability in the runphpcmd.php endpoint. The syscmd
Shenzhen TVT Digital Technology Co., Ltd. NVMS-9000 firmware (used by many white-labeled DVR/NVR/IPC products) contains
A Looker user with a Developer role could cause Looker to execute a malicious command, due to insecure processing of Ter
An authentication-bypass vulnerability exists in AiCloud. This vulnerability can be triggered by an unintended side effe
A command injection vulnerability has been identified in bwdpi. A remote, authenticated attacker could leverage this vul
Firmware in SDMC NE6037 routers prior to version 7.1.12.2.44 has a network diagnostics tool vulnerable to a shell comman
TOTOLINK N300RT wireless router firmware versions prior to V3.4.0-B20250430 (discovered in V2.1.8-B20201030.1539) contai
perl2exe <= V30.10C contains an arbitrary code execution vulnerability that allows local authenticated attackers to exec
Loaded Commerce 6.6 contains a client-side template injection vulnerability via the search parameter that allows unauthe
ReQuest Serious Play F3 Media Server 7.0.3 contains an unauthenticated remote code execution vulnerability that allows a
dizqueTV 1.5.3 contains a remote code execution vulnerability that allows attackers to inject arbitrary commands through
Wp2Fac 1.0 contains an OS command injection vulnerability in the send.php endpoint that allows remote attackers to execu
Successful exploitation of these vulnerabilities could allow an attacker to modify firmware and gain full access to the
In WODESYS WD-R608U router (also known as WDR122B V2.0 and WDR28) due to lack of validation in the langGet parameter in
Under certain circumstances a successful exploitation could result in access to the device.
Under certain circumstances a successful exploitation could result in access to the device.
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet
Unauthenticated remote attackers can access the system through the LoadMaster management interface, enabling arbitrary s
NextcloudPi is a ready to use image for Virtual Machines, Raspberry Pi, Odroid HC1, Rock64 and other boards. A command i
In Flowmon versions prior to 11.1.14 and 12.3.5, an operating system command injection vulnerability has been identified
Rust is a programming language. The Rust Security Response WG was notified that the Rust standard library prior to versi
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited,
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in ZkTeco-base
Improper Input Validation vulnerability in Progress LoadMaster allows OS Command Injection.This issue affects: * LoadMa
The postjournal service in Zimbra Collaboration (ZCS) before 8.8.15 Patch 46, 9 before 9.0.0 Patch 41, 10 before 10.0.9,
A vulnerability has been identified in InterMesh 7177 Hybrid 2.0 Subscriber (All versions < V8.2.12), InterMesh 7707 Fir
getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers t
Frequently Asked Questions
What is CWE-78?
CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-78?
There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.
How can I protect against CWE-78 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.
Detect CWE-78 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.
Get Started