CWE-78
MITRE ↗Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)
Multiple improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE
OS Command injection vulnerability in sleuthkit fls tool 4.11.1 allows attackers to execute arbitrary commands via a cra
Phicomm K2 v22.6.534.263 was discovered to contain a command injection vulnerability via the autoUpTime parameter in the
Phicomm K2G v22.6.3.20 was discovered to contain a command injection vulnerability via the autoUpTime parameter in the a
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiADC versio
A vulnerability, which was classified as critical, was found in kylin-system-updater up to 1.4.20kord on Ubuntu Kylin. A
emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to shell command injections through a crafted mailto:
DrayTek Vigor2960 v1.5.1.4 allows an authenticated attacker with network access to the web management interface to injec
org-babel-execute:latex in ob-latex.el in Org Mode through 9.6.1 for GNU Emacs allows attackers to execute arbitrary com
An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiADC 5.x all versions
A vulnerability classified as critical was found in KylinSoft youker-assistant on KylinOS. Affected by this vulnerabilit
A CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability
An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiADC 7.2.0, 7.1.0 thr
All versions of the package n158 are vulnerable to Command Injection due to improper input sanitization in the 'module.e
Multiple improper neutralization of special elements used in an os command ('OS Command Injection') vulnerabilties [CWE-
KioWare for Windows through v8.33 was discovered to contain an incomplete blacklist filter for blocked dialog boxes on W
An OS common injection vulnerability exists in the ESM certificate API, whereby incorrectly neutralized special element
OS Command Injection in GitHub repository mlflow/mlflow prior to 2.6.0.
A vulnerability in the fosexec command of Brocade Fabric OS after Brocade Fabric OS v9.1.0 and, before Brocade Fabric OS
An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface
Dell SmartFabric Storage Software v1.4 (and earlier) contains an OS Command Injection Vulnerability in the restricted s
Dell SmartFabric Storage Software v1.4 (and earlier) contain(s) an OS Command Injection Vulnerability in the CLI. An au
Dell SmartFabric Storage Software v1.4 (and earlier) contains an OS Command Injection Vulnerability in the CLI use of t
An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78 ] in
An improper neutralization of special elements used in an os command ('OS Command Injection') vulnerability [CWE-78] in
Dell PowerProtect DD, versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an OS command injecti
Shell Injection vulnerability GL.iNet A1300 v4.4.6, AX1800 v4.4.6, AXT1800 v4.4.6, MT3000 v4.4.6, MT2500 v4.4.6, MT6000
A Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in SUSE Ranch
The GLPI Agent is a generic management agent. Prior to version 1.5, if glpi-agent is running remoteinventory task agains
A flaw in the input validation in TOBY-L2 allows a user to execute arbitrary operating system commands using specificall
Totolink A830R V4.1.2cu.5182 was discovered to contain a command injection vulnerability via the QUERY_STRING parameter.
A Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in wrangler o
Panasonic AiSEG2 versions 2.80F through 2.93A allows remote attackers to execute arbitrary OS commands.
SRS is a real-time video server supporting RTMP, WebRTC, HLS, HTTP-FLV, SRT, MPEG-DASH, and GB28181. Prior to versions 5
The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier contains a buffer overflow vulnerability in th
Versions of the package window-control before 1.4.5 are vulnerable to Command Injection via the sendKeys function, due t
Versions of the package exec-local-bin before 1.2.0 are vulnerable to Command Injection via the theProcess() functionali
All versions of the package wifey are vulnerable to Command Injection via the connect() function due to improper input s
Versions of the package global-modules-path before 3.0.0 are vulnerable to Command Injection due to missing input saniti
All versions of the package smartctl are vulnerable to Command Injection via the info method due to improper input sanit
All versions of the package puppet-facter are vulnerable to Command Injection via the getFact function due to improper
All versions of the package create-choo-electron are vulnerable to Command Injection via the devInstall function due to
All versions of the package vagrant.js are vulnerable to Command Injection via the boxAdd function due to improper input
Versions of the package nemo-appium before 0.0.9 are vulnerable to Command Injection due to improper input sanitization
All versions of the package is-http2 are vulnerable to Command Injection due to missing input sanitization or other chec
Versions of the package mt7688-wiscan before 0.8.3 are vulnerable to Command Injection due to improper input sanitizatio
All versions of the package semver-tags are vulnerable to Command Injection via the getGitTagsRemote function due to imp
All versions of the package create-choo-app3 are vulnerable to Command Injection via the devInstall function due to impr
This affects versions of the package pydash before 6.0.0. A number of pydash methods such as pydash.objects.invoke() and
Softnext Mail SQR Expert is an email management platform, it has insufficient filtering for a special character within a
Frequently Asked Questions
What is CWE-78?
CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-78?
There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.
How can I protect against CWE-78 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.
Detect CWE-78 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.
Get Started