CWE-78
MITRE ↗Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)
Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 does not properly valida
Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 does not properly valida
A command execution vulnerability exists in the access control functionality of Netgear Orbi Router RBR750 4.6.8.5. A sp
An authenticated administrator is allowed to remotely execute arbitrary shell commands via the API. POC http://<IP_ADDR
Due to programming error in function module and report, IS-OIL component in SAP ECC and SAP S/4HANA allows an authentica
Adobe Commerce versions 2.4.6-p1 (and earlier), 2.4.5-p3 (and earlier) and 2.4.4-p4 (and earlier) are affected by an Imp
When adding a remote backup location, an authenticated user can pass arbitrary OS commands through the username field. T
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Inj
An arbitrary code execution flaw was found in Foreman. This flaw allows an admin user to bypass safe mode in templates a
GoSecure on behalf of Genetec Inc. has found a flaw that allows for a remote code execution during the installation of A
SAP Business Object (Adaptive Job Server) - versions 420, 430, allows remote execution of arbitrary commands on Unix, wh
Nextcloud server is an open source home cloud implementation. In affected versions a missing scope validation allowed us
A vulnerability exists that can be exploited by an authenticated client that is connected to the same network segment as
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited,
ChangingTec ServiSign component has insufficient filtering for special characters in the connection response parameter.
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiADC versio
The web service on Nexxt Amp300 ARN02304U8 42.103.1.5095 and 80.103.2.5045 devices allows remote OS command execution by
Zoom Rooms for macOS clients before version 5.11.3 contain a local privilege escalation vulnerability. A local low-privi
Autolab is a course management service, initially developed by a team of students at Carnegie Mellon University, that en
OrangeScrum version 2.0.11 allows an authenticated external attacker to execute arbitrary commands on the server. This i
jc21 NGINX Proxy Manager through 2.9.19 allows OS command injection. When creating an access list, the backend builds an
The management portal component of JetNexus/EdgeNexus ADC 4.2.8 was discovered to contain a command injection vulnerabil
This vulnerability allows network-adjacent attackers to execute arbitrary commands on affected installations of D-Link D
This vulnerability allows network-adjacent attackers to execute arbitrary commands on affected installations of D-Link D
A sandbox bypass vulnerability involving map constructors in Jenkins Script Security Plugin 1228.vd93135a_2fb_25 and ear
An OS command injection vulnerability exists in the httpd SNMP functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-1410
An OS command injection vulnerability exists in the httpd txt/restore.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-
An os command injection vulnerability exists in the httpd delfile.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-2107
Dell EMC prior to version DDOS 7.9 contain(s) an OS command injection Vulnerability. An authenticated non admin attacke
D-Link DIR-846 Firmware FW100A53DBR was discovered to contain a remote command execution (RCE) vulnerability via the lan
Command Injection vulnerability in Edimax Technology Co., Ltd. Wireless Router N300 Firmware BR428nS v3 allows attacker
Acemanager in ALEOS before version 4.16 allows a user with valid credentials to manipulate the IP logging operation to e
Dell Unisphere for PowerMax vApp, VASA Provider vApp, and Solution Enabler vApp version 9.2.3.x contain a command execu
An improper neutralization of special elements used in an os command ('OS Command Injection') [CWE-78] in FortiWeb 7.0.0
An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface
Sme.UP ERP TOKYO V6R1M220406 was discovered to contain an OS command injection vulnerability via calls made to the XMSer
HGiga PowerStation remote management function has insufficient filtering for user input. An authenticated remote attacke
This vulnerability allows network-adjacent attackers to execute arbitrary commands on affected installations of D-Link D
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-8
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-8
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-8
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-8
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-8
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-8
OS command injection vulnerability in CONPROSYS IoT Gateway products allows a remote authenticated attacker who can acce
SeowonIntech SWC 5100W WIMAX Bootloader 1.18.19.0, HW 0.0.7.0, and FW 1.11.0.1, 1.9.9.4 are vulnerable to OS Command Inj
An issue found in D-Link DSL-3782 v.1.03 allows remote authenticated users to execute arbitrary code as root via the net
WFS-SR03 v1.0.3 was discovered to contain a command injection vulnerability via the sys_smb_pwdmod function.
Linksys AX3200 1.1.00 is vulnerable to OS command injection by authenticated users via shell metacharacters to the diagn
An OS Command Injection vulnerability in gRPC Network Operations Interface (gNOI) server module of Juniper Networks Juno
Frequently Asked Questions
What is CWE-78?
CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-78?
There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.
How can I protect against CWE-78 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.
Detect CWE-78 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.
Get Started