Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)

1,941
CRITICAL
3,146
HIGH
963
MEDIUM
16
LOW
6,290 CVEs · Page 64/126
5.3
CVE-2024-31482

An unauthenticated Denial-of-Service (DoS) vulnerability exists in the ANSI escape code service accessed via the PAPI pr

5.3
CVE-2024-37678

Cross Site Scripting vulnerability in Hangzhou Meisoft Information Technology Co., Ltd. Finesoft v.8.0 and before allows

5.3
CVE-2024-21531

All versions of the package git-shallow-clone are vulnerable to Command injection due to missing sanitization or mitigat

5.3
CVE-2024-10224

Qualys discovered that if unsanitized input was used with the library Modules::ScanDeps, before version 1.36 a local att

5.3
CVE-2024-48008

Dell RecoverPoint for Virtual Machines 6.0.x contains a OS Command Injection vulnerability. An Low privileged remote att

5.0
CVE-2024-8869

A vulnerability classified as critical has been found in TOTOLINK A720R 4.1.5. Affected is the function exportOvpn. The

4.7
CVE-2024-0921

A vulnerability has been found in D-Link DIR-816 A2 1.10CNB04 and classified as critical. Affected by this vulnerability

4.7
CVE-2024-0986

A vulnerability was found in Issabel PBX 4.0.0. It has been rated as critical. This issue affects some unknown processin

4.7
CVE-2023-47567

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited,

4.7
CVE-2024-4255

A vulnerability, which was classified as critical, has been found in Ruijie RG-UAC up to 20240419. This issue affects so

4.7
CVE-2024-4501

A vulnerability was found in Ruijie RG-UAC up to 20240428. It has been rated as critical. This issue affects some unknow

4.7
CVE-2024-4502

A vulnerability classified as critical has been found in Ruijie RG-UAC up to 20240428. Affected is an unknown function o

4.7
CVE-2024-4503

A vulnerability classified as critical was found in Ruijie RG-UAC up to 20240428. Affected by this vulnerability is an u

4.7
CVE-2024-4504

A vulnerability, which was classified as critical, has been found in Ruijie RG-UAC up to 20240428. Affected by this issu

4.7
CVE-2024-4505

A vulnerability, which was classified as critical, was found in Ruijie RG-UAC up to 20240428. This affects an unknown pa

4.7
CVE-2024-4506

A vulnerability has been found in Ruijie RG-UAC up to 20240428 and classified as critical. This vulnerability affects un

4.7
CVE-2024-4507

A vulnerability was found in Ruijie RG-UAC up to 20240428 and classified as critical. This issue affects some unknown pr

4.7
CVE-2024-4508

A vulnerability was found in Ruijie RG-UAC up to 20240428. It has been classified as critical. Affected is an unknown fu

4.7
CVE-2024-4509

A vulnerability was found in Ruijie RG-UAC up to 20240428. It has been declared as critical. Affected by this vulnerabil

4.7
CVE-2024-4510

A vulnerability was found in Ruijie RG-UAC up to 20240428. It has been rated as critical. Affected by this issue is some

4.7
CVE-2024-5241

A vulnerability was found in Huashi Private Cloud CDN Live Streaming Acceleration Server up to 20240520. It has been cla

4.7
CVE-2024-5336

A vulnerability has been found in Ruijie RG-UAC up to 20240516 and classified as critical. This vulnerability affects th

4.7
CVE-2024-5337

A vulnerability was found in Ruijie RG-UAC up to 20240516 and classified as critical. This issue affects some unknown pr

4.7
CVE-2024-5338

A vulnerability was found in Ruijie RG-UAC up to 20240516. It has been classified as critical. Affected is an unknown fu

4.7
CVE-2024-5339

A vulnerability was found in Ruijie RG-UAC up to 20240516. It has been declared as critical. Affected by this vulnerabil

4.7
CVE-2024-5340

A vulnerability was found in Ruijie RG-UAC up to 20240516. It has been rated as critical. Affected by this issue is some

4.7
CVE-2024-21906

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited,

4.7
CVE-2024-9076

A vulnerability was found in DedeCMS up to 5.7.115. It has been rated as critical. This issue affects some unknown proce

4.7
CVE-2024-9977

A vulnerability, which was classified as critical, was found in MitraStar GPT-2541GNAC BR_g5.6_1.11(WVK.0)b26. Affected

4.4
CVE-2024-20289

A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, low-privileged, local attacker to execu

4.2
CVE-2024-26023

OS command injection vulnerability in BUFFALO wireless LAN routers allows a logged-in user to execute arbitrary OS comma

4.1
CVE-2024-31843

An issue was discovered in Italtel Embrace 1.6.4. The Web application does not properly check the parameters sent as inp

4.0
CVE-2023-51699

Fluid is an open source Kubernetes-native Distributed Dataset Orchestrator and Accelerator for data-intensive applicatio

3.3
CVE-2024-3121

A remote code execution vulnerability exists in the create_conda_env function of the parisneo/lollms repository, version

CVE-2024-5421

Missing input validation and OS command integration of the input in the utnserver Pro, utnserver ProMAX, INU-100 web-int

CVE-2024-3798

Insecure handling of GET header parameter file included in requests being sent to an instance of the open-source project

CVE-2024-3799

Insecure handling of POST header parameter body included in requests being sent to an instance of the open-source projec

CVE-2024-9166

The device enables an unauthorized attacker to execute system commands with elevated privileges. This exploit is facilit

CVE-2024-52010

Zoraxy is a general purpose HTTP reverse proxy and forwarding tool. A command injection vulnerability in the Web SSH fea

CVE-2024-53992

unzip-bot is a Telegram bot to extract various types of archives. Users could exploit unsanitized inputs to inject malic

10.0
CVE-2023-2131

Versions of INEA ME RTU firmware prior to 3.36 are vulnerable to OS command injection, which could allow an attacker to

10.0
CVE-2023-2564

OS Command Injection in GitHub repository sbs20/scanservjs prior to v2.27.0.

10.0
CVE-2023-3572

In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote, unauthenticated attacker may use an

10.0
CVE-2023-34992

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet

10.0
CVE-2023-3991

An OS command injection vulnerability exists in the httpd iperfrun.cgi functionality of FreshTomato 2023.3. A specially

9.9
CVE-2023-27407

A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1). The web based management of affected devi

9.9
CVE-2023-35893

IBM Security Guardium 10.6, 11.3, 11.4, and 11.5 could allow a remote authenticated attacker to execute arbitrary comman

9.9
CVE-2023-35762

Versions of INEA ME RTU firmware 3.36b and prior are vulnerable to operating system (OS) command injection, which could

9.8
CVE-2022-44877 KEV

login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execut

9.8
CVE-2022-48252

The jokob-sk/Pi.Alert fork (before 22.12.20) of Pi.Alert allows Remote Code Execution via nmap_scan.php (scan parameter)

Frequently Asked Questions

What is CWE-78?

CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-78?

There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.

How can I protect against CWE-78 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.

Detect CWE-78 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.

Get Started