CWE-78
MITRE ↗Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)
A SQL injection vulnerability exists in the vendor_country parameter of the “vendor print report” feature of the Science
A SQL injection vulnerability exists in the “topology data service” feature of the ScienceLogic SL1 that takes unsanitiz
A SQL injection vulnerability exists in the “ticket watchers email” feature of the ScienceLogic SL1 that takes unsanitiz
A SQL injection vulnerability exists in the “ticket template watchers” feature of the ScienceLogic SL1 that takes unsani
A SQL injection vulnerability exists in the “ticket queue watchers” feature of the ScienceLogic SL1 that takes unsanitiz
A SQL injection vulnerability exists in the “ticket event report” feature of the ScienceLogic SL1 that takes unsanitized
A SQL injection vulnerability exists in the “reporter events type date” feature of the ScienceLogic SL1 that takes unsan
A SQL injection vulnerability exists in the “reporter events type” feature of the ScienceLogic SL1 that takes unsanitize
A SQL injection vulnerability exists in the “notes view” feature of the ScienceLogic SL1 that takes unsanitized user‐con
A SQL injection vulnerability exists in the “network print report” feature of the ScienceLogic SL1 that takes unsanitize
A SQL injection vulnerability exists in the “message viewer print” feature of the ScienceLogic SL1 that takes unsanitize
A SQL injection vulnerability exists in the “message viewer iframe” feature of the ScienceLogic SL1 that takes unsanitiz
A SQL injection vulnerability exists in the “logging export” feature of the ScienceLogic SL1 that takes unsanitized user
Improper neutralization of active check command arguments in Checkmk < 2.1.0p32, < 2.0.0p38, < 2.2.0p4 leads to arbitrar
A post-authentication command injection vulnerability in the NTP feature of Zyxel NBG6604 firmware version V1.01(ABIR.1)
TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to
TN-5900 Series firmware versions v3.3 and prior are vulnerable to command-injection vulnerability. This vulnerability st
OS command injection vulnerability in ELECOM wireless LAN routers allows an authenticated user to execute an arbitrary O
OS command injection vulnerability in WRC-F1167ACF all versions, and WRC-1750GHBK all versions allows an attacker who ca
OS command injection vulnerability in ELECOM wireless LAN access point devices allows an authenticated user to execute a
OS command injection vulnerability in the CBC products allows a remote authenticated attacker to execute an arbitrary OS
Infoblox NIOS through 8.5.1 has a faulty component that accepts malicious input without sanitization, resulting in shell
An OS Command Injection vulnerability exists in SIMULIA 3DOrchestrate from Release 3DEXPERIENCE R2021x through Release 3
Multiple TP-LINK products allow a network-adjacent unauthenticated attacker to execute arbitrary OS commands. Affected p
Archer C1200 firmware versions prior to 'Archer C1200(JP)_V2_230508' and Archer C9 firmware versions prior to 'Archer C9
Archer A10 firmware versions prior to 'Archer A10(JP)_V2_230504' allows a network-adjacent unauthenticated attacker to e
ASUS RT-AC86U Adaptive QoS - Web History function has insufficient filtering of special character. A remote attacker wi
ASUS RT-AC86U AiProtection security- related function has insufficient filtering of special character. A remote attacke
ASUS RT-AC86U unused Traffic Analyzer legacy Statistic function has insufficient filtering of special character. A remo
ASUS RT-AC86U Traffic Analyzer - Statistic function has insufficient filtering of special character. A remote attacker
ASUS RT-AC86U Traffic Analyzer - Apps analysis function has insufficient filtering of special character. A remote attac
On ASUS RT-AX55 3.0.0.4.386.51598 devices, authenticated attackers can perform OS command injection via the /start_apply
An OS command injection vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerabilit
A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to perform an injec
Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability in the diagnostic tools page. This vu
OS command injection vulnerability in FURUNO SYSTEMS wireless LAN access point devices allows an authenticated user to e
Atos Unify OpenScape Session Border Controller through V10 R3.01.03 allows execution of OS commands as root user by low-
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM versio
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM versio
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM versio
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM versio
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM versio
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM versio
An issue in YeaLinkSIP-T19P-E2 v.53.84.0.15 allows a remote privileged attacker to execute arbitrary code via a crafted
In Weintek's cMT3000 HMI Web CGI device, an anonymous attacker can execute arbitrary commands after login to th
An OS command injection vulnerability has been reported to affect QUSBCam2. If exploited, the vulnerability could allow
reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform sc
A vulnerability in a specific Cisco ISE CLI command could allow an authenticated, local attacker to perform command inje
ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters withi
ASUS RT-AX55’s authentication-related function has a vulnerability of insufficient filtering of special characters withi
Frequently Asked Questions
What is CWE-78?
CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-78?
There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.
How can I protect against CWE-78 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.
Detect CWE-78 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.
Get Started