CWE-78
MITRE ↗Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)
mailcow is a dockerized email package, with multiple containers linked in one bridged network. The Sync Job feature - wh
All versions of the package node-qpdf are vulnerable to Command Injection such that the package-exported method encrypt(
A vulnerability, which was classified as critical, was found in codelyfe Stupid Simple CMS up to 1.2.3. This affects an
Realtek GPON router has insufficient filtering for special characters. A remote attacker authenticated as an administrat
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run a
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run a
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run a
An arbitrary code exection vulnerability exists in Linksys WUMC710 Wireless-AC Universal Media Connector with firmware <
An arbitrary code execution vulnerability exisits in Linksys WRT54GL Wireless-G Broadband Router with firmware <= 4.30.1
InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-S-V2.3.0.r
NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can inject arbitrary shell commands, w
NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can inject arbitrary shell commands, w
NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can inject arbitrary shell commands, w
MAHO-PBX NetDevancer Lite/Uni/Pro/Cloud prior to Ver.1.11.00, MAHO-PBX NetDevancer VSG Lite/Uni prior to Ver.1.11.00, an
A post-authentication command injection vulnerability in the CLI command of Zyxel ZyWALL/USG series firmware versions 4.
PowerPath Management Appliance with versions 3.3 & 3.2*, 3.1 & 3.0* contains OS Command Injection vulnerability. An aut
A vulnerability in the Cisco IOx application hosting environment could allow an authenticated, remote attacker to execut
NetModule NSRW web administration interface executes an OS command constructed with unsanitized user input. A successful
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiExtender 7
On Barracuda CloudGen WAN Private Edge Gateway devices before 8 webui-sdwan-1089-8.3.1-174141891, an OS command injectio
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb versio
HGiga MailSherlock query function for connection log has a vulnerability of insufficient filtering for user input. An au
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN
NVIDIA DGX-1 BMC contains a vulnerability in the SPX REST API, where an attacker with the appropriate level of authoriza
When DNS is provisioned, an authenticated remote command execution vulnerability exists in DNS iQuery mesh. Note:
An issue was discovered in Veritas InfoScale Operations Manager (VIOM) before 7.4.2.800 and 8.x before 8.0.410. The VIOM
Wi-Fi AP UNIT AC-PD-WAPU v1.05_B04 and earlier, AC-PD-WAPUM v1.05_B04 and earlier, AC-PD-WAPU-P v1.05_B04P and earlier,
An OS Command Injection vulnerability in Parks Fiberlink 210 firmware version V2.1.14_X000 was found via the /boaform/ad
The post-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.13)C0
Hitron CODA-5310 has insufficient filtering for specific parameters in the connection test function. A remote attacker a
A command injection vulnerability was found in the ping functionality of the MitraStar GPT-2741GNAC router (firmware ver
AMI BMC contains a vulnerability in the SPX REST API, where an attacker with the required privileges can inject arbitrar
AMI BMC contains a vulnerability in the SPX REST API, where an attacker with the required privileges can inject arbitrar
OS command injection vulnerability exists in Wi-Fi AP UNIT allows. If this vulnerability is exploited, a remote authenti
IBM Security Directory Suite VA 8.0.1 through 8.0.1.19 could allow a remote authenticated attacker to execute arbitrary
A vulnerability in GL.iNET GL-E750 Mudi before firmware v3.216 allows authenticated attackers to execute arbitrary code
A valid, authenticated LXCA user with elevated privileges may be able to execute command injections through crafted call
Improper Neutralization of Special Elements used in an OS Command vulnerability in NEC Corporation Aterm WG2600HP2, WG26
Improper neutralization of special elements in WL-WN531AX2 firmware versions prior to 2023526 allows an attacker with an
The websocket configuration endpoint of the Loxone Miniserver Go Gen.2 before 14.1.5.9 allows remote authenticated admin
An OS command injection vulnerability exists in the ys_thirdparty check_system_user functionality of Milesight UR32L v32
An os command injection vulnerability exists in the libzebra.so change_hostname functionality of Milesight UR32L v32.3.0
An OS command injection vulnerability exists in the ys_thirdparty user_delete functionality of Milesight UR32L v32.3.0.5
An OS command injection vulnerability exists in the ys_thirdparty system_user_script functionality of Milesight UR32L v3
Two OS command injection vulnerabilities exist in the zebra vlan_name functionality of Milesight UR32L v32.3.0.5. A spec
Two OS command injection vulnerabilities exist in the zebra vlan_name functionality of Milesight UR32L v32.3.0.5. A spec
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in
1Panel is an open source Linux server operation and maintenance management panel. An OS command injection vulnerability
Improper Neutralization of commands allowed to be executed via OTRS System Configuration e.g. SchedulerCronTaskModule us
Frequently Asked Questions
What is CWE-78?
CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-78?
There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.
How can I protect against CWE-78 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.
Detect CWE-78 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.
Get Started