CWE-78
MITRE ↗Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)
Elsight – CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Elsight – CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
SECOM WRTR-304GN-304TW-UPSC does not properly filter user input in the specific functionality. Unauthenticated remote at
The wireless router WRTM326 from SECOM does not properly validate a specific parameter. An unauthenticated remote attack
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary comman
Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Special Elements used in a Command
The pwrstudio web application of EV Charger (in the server in Circontrol Raption through 5.6.2) is vulnerable to OS comm
EnGenius EWS356-FIT devices through 1.1.30 allow blind OS command injection. This allows an attacker to execute arbitrar
A Python command injection vulnerability exists in the `SagemakerLLM` class's `complete()` method within `./private_gpt/
Certain EOL GeoVision devices have an OS Command Injection vulnerability. Unauthenticated remote attackers can exploit t
A remote command execution vulnerability exists in gogs/gogs versions <=0.12.7 when deployed on a Windows server. The vu
Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Task Manager
D-Link DI-8200 16.07.26A1 is vulnerable to remote command execution in the msp_info_htm function via the flag parameter
An OS command injection vulnerability exists in the name parameter of GoCast 1.1.3. A specially crafted HTTP request can
An OS command injection vulnerability exists in the NAT parameter of GoCast 1.1.3. A specially crafted HTTP request can
An OS command injection vulnerability has been reported to affect several product versions. If exploited, the vulnerabil
In TOTOLINK X6000R V9.4.0cu.1041_B20240224 in the shttpd file, the Uci_Set Str function is used without strict parameter
Cohesive Networks VNS3 Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers
Cohesive Networks VNS3 Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered aff
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered aff
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered aff
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered aff
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered aff
A CWE-306 "Missing Authentication for Critical Function" was discovered affecting the following devices manufactured by
A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API and enables remote code exe
IBM Security Verify Access Appliance 10.0.0 through 10.0.8 could allow a remote authenticated attacker to execute arbitr
A command injection vulnerability has been reported to affect License Center. If exploited, the vulnerability could allo
An OS command injection vulnerability has been reported to affect HBS 3 Hybrid Backup Sync. If exploited, the vulnerabil
A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the
The affected product is vulnerable to a command injection. An unauthenticated attacker could send commands through a mal
Tiki Wiki CMS – CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
PaddlePaddle before 2.6.0 has a command injection in get_online_pass_interval. This resulted in the ability to execute a
PaddlePaddle before 2.6.0 has a command injection in _wget_download. This resulted in the ability to execute arbitrary c
PaddlePaddle before 2.6.0 has a command injection in convert_shape_compare. This resulted in the ability to execute arbi
Atril is a simple multi-page document viewer. Atril is vulnerable to a critical Command Injection Vulnerability. This vu
Waybox Enel X web management application could be used to execute arbitrary OS commands and provide administrator’s priv
An OS Command Injection vulnerability affecting documentation server on 3DEXPERIENCE from Release 3DEXPERIENCE R2022x th
Adobe Commerce versions 2.4.6-p3, 2.4.5-p5, 2.4.4-p6 and earlier are affected by an Improper Neutralization of Special E
A command injection vulnerability exists in the processAnalyticsReport method from the com.webos.service.cloudupload ser
A command injection vulnerability exists in the getAudioMetadata method from the com.webos.service.attachedstoragemanage
A command injection vulnerability exists in the com.webos.service.connectionmanager/tv/setVlanStaticAddress endpoint on
Command injection vulnerability in the operating system. Improper neutralisation of special elements in Active Directory
An OS command injection vulnerability exists in the web interface mac2name functionality of Peplink Smart Reader v1.2.0
IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a remote authenticated attacker to execute arbitrary comman
A command injection vulnerability exists in the gradio-app/gradio repository, specifically within the 'test-functional.y
SysAid - CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The function "generate_app_certificates" in lib/app_certificates.js of FIWARE Keyrock <= 8.4 does not neutralize special
The function "generate_app_certificates" in controllers/saml2/saml2.js of FIWARE Keyrock <= 8.4 does not neutralize spec
pyLoad is a free and open-source Download Manager. The folder `/.pyload/scripts` has scripts which are run when certain
Frequently Asked Questions
What is CWE-78?
CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-78?
There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.
How can I protect against CWE-78 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.
Detect CWE-78 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.
Get Started