CWE-78
MITRE ↗Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)
D-Link DIR_823G 1.0.2B05 was discovered to contain a command injection vulnerability via the HostName parameter in the S
Netgear XR300 v1.0.3.78 was discovered to contain a command injection vulnerability in the system_name parameter at geni
Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the wan_gateway parameter at gen
Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the wan_gateway parameter at wiz
Netgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the wan_gateway parameter at bsw
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Mesh Wi-Fi ro
A security agent manual scan command injection vulnerability in the Trend Micro Deep Security 20 Agent could allow an at
OS command injection vulnerability exists in AIPHONE IX SYSTEM and IXG SYSTEM. A network-adjacent authenticated attacker
EnGenius EWS356-FIR 1.1.30 and earlier devices allow a remote attacker to execute arbitrary OS commands via the Controll
An Authenticated Remote Code Execution (RCE) vulnerability affects the TP-Link Archer router series. A vulnerability exi
Multiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially c
Multiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially c
Multiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially c
Multiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially c
Multiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially c
Multiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially c
Dell Unity, versions prior to 5.4, contain an OS Command Injection Vulnerability in its svc_topstats utility. An authen
Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_acldb_dump utility. An aut
Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_tcpdump utility. An authen
Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in the svc_topstats utility. An authe
Dell Unity, versions prior to 5.4, contains a Command Injection Vulnerability in svc_oscheck utility. An authenticated
Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_cava utility. An authentic
Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability within its svc_udoctor utility. An au
Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability within its svc_cbr utility. An authen
Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_nas utility. An authentica
Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_supportassist utility. An
Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_dc utility. An authenticat
Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_cifssupport utility. An au
close_altfile in filename.c in less before 606 omits shell_quote calls for LESSCLOSE.
Command injection vulnerability in Movistar 4G router affecting version ES_WLD71-T1_v2.0.201820. This vulnerability allo
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in openEuler ga
Control Web Panel wloggui Command Injection Local Privilege Escalation Vulnerability. This vulnerability allows local at
sagemaker-python-sdk is a library for training and deploying machine learning models on Amazon SageMaker. In affected ve
Dreamweaver Desktop versions 21.3 and earlier are affected by an Improper Neutralization of Special Elements used in an
A vulnerability in the ConfD CLI and the Cisco Crosswork Network Services Orchestrator CLI could allow an authenticated
An OS command injection vulnerability exists in the MacOS Text-To-Speech class MacOSTTS of the significant-gravitas/auto
An Improper Neutralization of Special Elements vulnerability in Juniper Networks Junos OS Evolved commands allows a loca
An Improper Neutralization of Special Elements vulnerability in Juniper Networks Junos OS Evolved commands allows a loca
An Improper Neutralization of Special Elements vulnerability in Juniper Networks Junos OS Evolved commands allows a loca
An Improper Neutralization of Special Elements vulnerability in Juniper Networks Junos OS Evolved commands allows a loca
An Improper Neutralization of Special Elements vulnerability in Juniper Networks Junos OS Evolved commands allows a loca
Local privilege escalation due to OS command injection vulnerability. The following products are affected: Acronis True
ProtonVPN before 3.2.10 on Windows mishandles the drive installer path, which should use this: '"' + ExpandConstant('{au
In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited,
EnGenius ENH1350EXT A8J-ENH1350EXT devices through 3.9.3.2_c1.9.51 allow (blind) OS Command Injection via shell metachar
Qualys discovered that needrestart, before version 3.8, passes unsanitized data to a library (Modules::ScanDeps) which e
A command injection vulnerability in Brocade Fabric OS before 9.2.0c, and 9.2.1 through 9.2.1a on IP extension platforms
An OS command injection vulnerability has been reported to affect several product versions. If exploited, the vulnerabil
virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic templ
Frequently Asked Questions
What is CWE-78?
CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-78?
There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.
How can I protect against CWE-78 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.
Detect CWE-78 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.
Get Started