Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)

1,941
CRITICAL
3,146
HIGH
963
MEDIUM
16
LOW
6,290 CVEs · Page 60/126
7.2
CVE-2024-28750

A remote attacker with high privileges may use a deleting file function to inject OS commands.

7.2
CVE-2024-39345

AdTran 834-5 HDC17600021F1 (SmartOS 11.1.1.1) devices enable the SSH service by default and have a hidden, undocumented,

7.2
CVE-2024-38508

A privilege escalation vulnerability was discovered in the web interface or SSH captive command shell interface of XCC t

7.2
CVE-2024-38510

A privilege escalation vulnerability was discovered in the SSH captive command shell interface that could allow an authe

7.2
CVE-2024-38511

A privilege escalation vulnerability was discovered in an upload processing functionality of XCC that could allow an aut

7.2
CVE-2024-38512

A privilege escalation vulnerability was discovered in XCC that could allow an authenticated XCC user with elevated priv

7.2
CVE-2024-33896

Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are vulnerable to code injection due

7.2
CVE-2024-3659

Firmware in KAON AR2140 routers, prior to versions 3.2.50 and 4.2.16, is vulnerable to a shell command injection via sen

7.2
CVE-2024-21880

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability via the url parameter

7.2
CVE-2024-7728

The specific CGI of the CAYIN Technology CMS does not properly validate user input, allowing a remote attacker with admi

7.2
CVE-2024-42059

A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V5.00 through V5.38, US

7.2
CVE-2024-42060

A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.32 through V5.38, US

7.2
CVE-2024-7203

A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.60 through V5.38 and

7.2
CVE-2023-39300

An OS command injection vulnerability has been reported to affect legacy QTS. If exploited, the vulnerability could allo

7.2
CVE-2024-8190 KEV

An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remo

7.2
CVE-2024-20483

Multiple vulnerabilities in Cisco Routed PON Controller Software, which runs as a docker container on hardware that is s

7.2
CVE-2024-8686

A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass

7.2
CVE-2024-8278

A privilege escalation vulnerability was discovered in XCC that could allow a valid, authenticated XCC user with elevate

7.2
CVE-2024-8279

A privilege escalation vulnerability was discovered in XCC that could allow a valid, authenticated XCC user with elevate

7.2
CVE-2024-8280

An input validation weakness was discovered in XCC that could allow a valid, authenticated XCC user with elevated privil

7.2
CVE-2024-8281

An input validation weakness was discovered in XCC that could allow a valid, authenticated XCC user with elevated privil

7.2
CVE-2024-42502

Authenticated command injection vulnerability exists in the ArubaOS command line interface. Successful exploitation of t

7.2
CVE-2024-42503

Authenticated command execution vulnerability exist in the ArubaOS command line interface (CLI). Successful exploitatio

7.2
CVE-2024-8957 KEV

PTZOptics PT30X-SDI/NDI-xx before firmware 6.3.40 is vulnerable to an OS command injection issue. The camera does not su

7.2
CVE-2024-9380 KEV

An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authen

7.2
CVE-2024-9139

The affected product permits OS command injection through improperly restricted commands, potentially allowing attackers

7.2
CVE-2024-6333

Authenticated Remote Code Execution in Altalink, Versalink & WorkCentre Products.

7.2
CVE-2024-37845

MangoOS before 5.2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the Active

7.2
CVE-2024-41153

Command injection vulnerability in the Edge Computing UI for the TRO600 series radios that allows for the execution of a

7.2
CVE-2024-10653

IDExpert from CHANGING Information Technology does not properly validate a specific parameter in the administrator inter

7.2
CVE-2024-11062

The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privil

7.2
CVE-2024-11063

The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privil

7.2
CVE-2024-11064

The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privil

7.2
CVE-2024-11065

The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privil

7.2
CVE-2024-11066

The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privil

7.2
CVE-2024-9474 KEV

A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to

7.2
CVE-2024-21786

An OS command injection vulnerability exists in the web interface configuration upload functionality of MC Technologies

7.2
CVE-2024-28025

Three OS command injection vulnerabilities exist in the web interface I/O configuration functionality of MC Technologies

7.2
CVE-2024-28026

Three OS command injection vulnerabilities exist in the web interface I/O configuration functionality of MC Technologies

7.2
CVE-2024-28027

Three OS command injection vulnerabilities exist in the web interface I/O configuration functionality of MC Technologies

7.2
CVE-2024-50359

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered aff

7.2
CVE-2024-50360

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered aff

7.2
CVE-2024-50361

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered aff

7.2
CVE-2024-50362

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered aff

7.2
CVE-2024-50363

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered aff

7.2
CVE-2024-50364

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered aff

7.2
CVE-2024-50365

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered aff

7.2
CVE-2024-50366

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered aff

7.2
CVE-2024-50367

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered aff

7.2
CVE-2024-50368

A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered aff

Frequently Asked Questions

What is CWE-78?

CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-78?

There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.

How can I protect against CWE-78 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.

Detect CWE-78 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.

Get Started