CWE-78
MITRE ↗Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)
An unauthenticated Denial-of-Service (DoS) vulnerability exists in the ANSI escape code service accessed via the PAPI pr
Cross Site Scripting vulnerability in Hangzhou Meisoft Information Technology Co., Ltd. Finesoft v.8.0 and before allows
All versions of the package git-shallow-clone are vulnerable to Command injection due to missing sanitization or mitigat
Qualys discovered that if unsanitized input was used with the library Modules::ScanDeps, before version 1.36 a local att
Dell RecoverPoint for Virtual Machines 6.0.x contains a OS Command Injection vulnerability. An Low privileged remote att
A vulnerability classified as critical has been found in TOTOLINK A720R 4.1.5. Affected is the function exportOvpn. The
A vulnerability has been found in D-Link DIR-816 A2 1.10CNB04 and classified as critical. Affected by this vulnerability
A vulnerability was found in Issabel PBX 4.0.0. It has been rated as critical. This issue affects some unknown processin
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited,
A vulnerability, which was classified as critical, has been found in Ruijie RG-UAC up to 20240419. This issue affects so
A vulnerability was found in Ruijie RG-UAC up to 20240428. It has been rated as critical. This issue affects some unknow
A vulnerability classified as critical has been found in Ruijie RG-UAC up to 20240428. Affected is an unknown function o
A vulnerability classified as critical was found in Ruijie RG-UAC up to 20240428. Affected by this vulnerability is an u
A vulnerability, which was classified as critical, has been found in Ruijie RG-UAC up to 20240428. Affected by this issu
A vulnerability, which was classified as critical, was found in Ruijie RG-UAC up to 20240428. This affects an unknown pa
A vulnerability has been found in Ruijie RG-UAC up to 20240428 and classified as critical. This vulnerability affects un
A vulnerability was found in Ruijie RG-UAC up to 20240428 and classified as critical. This issue affects some unknown pr
A vulnerability was found in Ruijie RG-UAC up to 20240428. It has been classified as critical. Affected is an unknown fu
A vulnerability was found in Ruijie RG-UAC up to 20240428. It has been declared as critical. Affected by this vulnerabil
A vulnerability was found in Ruijie RG-UAC up to 20240428. It has been rated as critical. Affected by this issue is some
A vulnerability was found in Huashi Private Cloud CDN Live Streaming Acceleration Server up to 20240520. It has been cla
A vulnerability has been found in Ruijie RG-UAC up to 20240516 and classified as critical. This vulnerability affects th
A vulnerability was found in Ruijie RG-UAC up to 20240516 and classified as critical. This issue affects some unknown pr
A vulnerability was found in Ruijie RG-UAC up to 20240516. It has been classified as critical. Affected is an unknown fu
A vulnerability was found in Ruijie RG-UAC up to 20240516. It has been declared as critical. Affected by this vulnerabil
A vulnerability was found in Ruijie RG-UAC up to 20240516. It has been rated as critical. Affected by this issue is some
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited,
A vulnerability was found in DedeCMS up to 5.7.115. It has been rated as critical. This issue affects some unknown proce
A vulnerability, which was classified as critical, was found in MitraStar GPT-2541GNAC BR_g5.6_1.11(WVK.0)b26. Affected
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, low-privileged, local attacker to execu
OS command injection vulnerability in BUFFALO wireless LAN routers allows a logged-in user to execute arbitrary OS comma
An issue was discovered in Italtel Embrace 1.6.4. The Web application does not properly check the parameters sent as inp
Fluid is an open source Kubernetes-native Distributed Dataset Orchestrator and Accelerator for data-intensive applicatio
A remote code execution vulnerability exists in the create_conda_env function of the parisneo/lollms repository, version
Missing input validation and OS command integration of the input in the utnserver Pro, utnserver ProMAX, INU-100 web-int
Insecure handling of GET header parameter file included in requests being sent to an instance of the open-source project
Insecure handling of POST header parameter body included in requests being sent to an instance of the open-source projec
The device enables an unauthorized attacker to execute system commands with elevated privileges. This exploit is facilit
Zoraxy is a general purpose HTTP reverse proxy and forwarding tool. A command injection vulnerability in the Web SSH fea
unzip-bot is a Telegram bot to extract various types of archives. Users could exploit unsanitized inputs to inject malic
Versions of INEA ME RTU firmware prior to 3.36 are vulnerable to OS command injection, which could allow an attacker to
OS Command Injection in GitHub repository sbs20/scanservjs prior to v2.27.0.
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote, unauthenticated attacker may use an
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet
An OS command injection vulnerability exists in the httpd iperfrun.cgi functionality of FreshTomato 2023.3. A specially
A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1). The web based management of affected devi
IBM Security Guardium 10.6, 11.3, 11.4, and 11.5 could allow a remote authenticated attacker to execute arbitrary comman
Versions of INEA ME RTU firmware 3.36b and prior are vulnerable to operating system (OS) command injection, which could
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execut
The jokob-sk/Pi.Alert fork (before 22.12.20) of Pi.Alert allows Remote Code Execution via nmap_scan.php (scan parameter)
Frequently Asked Questions
What is CWE-78?
CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-78?
There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.
How can I protect against CWE-78 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.
Detect CWE-78 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.
Get Started