CWE-78
MITRE ↗Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)
A vulnerability, which was classified as critical, has been found in HuangDou UTCMS V9. Affected by this issue is some u
A command execution vulnerability exists in the AX2 Pro home router produced by Shenzhen Tenda Technology Co., Ltd. (Jix
A CWE-79 "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" was discovered affecting
An unauthenticated attacker with network access to the affected device's web interface can execute any system command vi
A vulnerability, which was classified as critical, has been found in DrayTek Vigor2960 and Vigor300B 1.5.1.3/1.5.1.4. Th
A vulnerability, which was classified as critical, was found in DrayTek Vigor2960 and Vigor300B 1.5.1.4. Affected is an
Anomali Match before 4.6.2 allows OS Command Injection. An authenticated admin user can inject and execute operating sys
NVIDIA Bluefield 2 and Bluefield 3 DPU BMC contains a vulnerability in ipmitool, where a root user may cause code injec
A vulnerability was found in TRENDnet TEW-800MB 1.0.1.0 and classified as critical. Affected by this issue is some unkno
Command injection in the ping utility on Buffalo LS210D 1.78-0.03 allows a remote authenticated attacker to inject arbit
The post-authentication command injection vulnerability in Zyxel NAS326 firmware versions through V5.21(AAZF.15)C0 and N
A post-authentication command injection vulnerability exists in the PPTP client functionality of Tp-Link ER7206 Omada Gi
A post authentication command injection vulnerability exists when setting up the PPTP global configuration of Tp-Link ER
A command execution vulnerability exists in the guest resource functionality of Tp-Link ER7206 Omada Gigabit VPN Router
A post authentication command injection vulnerability exists when configuring the wireguard VPN functionality of Tp-Lin
A post authentication command injection vulnerability exists in the GRE policy functionality of Tp-Link ER7206 Omada Gig
A post authentication command injection vulnerability exists in the ipsec policy functionality of Tp-Link ER7206 Omada G
A post authentication command injection vulnerability exists when configuring the web group member of Tp-Link ER7206 Oma
A post authentication command execution vulnerability exists in the web filtering functionality of Tp-Link ER7206 Omada
Dell PowerProtect Data Manager, version 19.15 and prior versions, contain an OS command injection vulnerability. A remo
A command injection vulnerability exists where an authenticated, remote attacker with administrator privileges on the S
Dell RecoverPoint for Virtual Machines 5.3.x, 6.0.SP1 contains an OS Command injection vulnerability. An unauthenticated
Loomio version 2.22.0 allows executing arbitrary commands on the server. This is possible because the application is vu
A post-authentication command injection vulnerability in the file upload binary in Zyxel ATP series firmware versions fr
SOY CMS is an open source CMS (content management system) that allows you to build blogs and online shops. SOY CMS versi
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in openEuler ao
Dell vApp Manager, versions prior to 9.2.4.9 contain a Command Injection Vulnerability. An authorized attacker could pot
Dell vApp Manager, versions prior to 9.2.4.9 contain a Command Injection Vulnerability. An authorized attacker could pot
SVR-116 firmware version 1.6.0.30028871 allows a remote authenticated attacker with an administrative privilege to execu
A command injection vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user with elevat
A command injection vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user with elevat
The email search interface of HGiga iSherlock (including MailSherlock, SpamSherock, AuditSherlock) fails to filter speci
The system configuration interface of HGiga iSherlock (including MailSherlock, SpamSherock, AuditSherlock) fails to filt
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to command inj
Multiple authenticated command injection vulnerabilities exist in the command line interface. Successful exploitation of
Multiple authenticated command injection vulnerabilities exist in the command line interface. Successful exploitation of
A command injection vulnerability exists in the IOCTL that manages OTA updates. A specially crafted command can lead to
ASUS routers supporting custom OpenVPN profiles are vulnerable to a code execution vulnerability. An authenticated and r
ILIAS 7 before 7.30 and ILIAS 8 before 8.11 as well as ILIAS 9.0 allow remote authenticated attackers with administrativ
Openfind Mail2000 does not properly filter parameters of specific API. Remote attackers with administrative privileges c
ASKEY 5G NR Small Cell fails to properly filter user input for certain functionality, allowing remote attackers with adm
The specific function parameter of ASUS Download Master does not properly filter user input. An unauthenticated remote a
A vulnerability regarding improper neutralization of special elements used in an OS command ('OS Command Injection') is
A vulnerability regarding improper neutralization of special elements used in an OS command ('OS Command Injection') is
A high privileged remote attacker can execute arbitrary system commands via GET requests due to improper neutralization
Three os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11.
Three os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11.
Three os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11.
A remote attacker with high privileges may use a reading file function to inject OS commands.
A remote attacker with high privileges may use a writing file function to inject OS commands.
Frequently Asked Questions
What is CWE-78?
CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-78?
There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.
How can I protect against CWE-78 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.
Detect CWE-78 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.
Get Started