CWE-78
MITRE ↗Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1
PAX A930 device with PayDroid_7.1.1_Virgo_V04.5.02_20220722 can allow the execution of arbitrary commands by using the e
An issue was discovered on Connectize AC21000 G6 641.139.1.1256 allows attackers to run arbitrary commands via use of a
OS command injection vulnerability in WRC-X3000GSN v1.0.2, WRC-X3000GS v1.0.24 and earlier, and WRC-X3000GSA v1.0.24 and
VR-S1000 firmware Ver. 2.37 and earlier allows an attacker with access to the product's web management page to execute a
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb versio
A command injection vulnerability exists in the administrative web portal in TP-Link Archer VR1600V devices running firm
Dell VxRail, versions prior to 7.0.450, contains an OS command injection Vulnerability in DCManager command-line utilit
An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiADC CLI 7.1.0, 7.0.0
An issue was discovered in hwclock.13-v2.27 allows attackers to gain escalated privlidges or execute arbitrary commands
An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiIsolator v
An Improper Input Validation vulnerability in Zscaler Client Connector on Linux allows Privilege Escalation. This issue
An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the command line interpr
Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain an OS command injec
An OS command injection vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerabilit
An OS command injection vulnerability has been reported to affect Container Station. If exploited, the vulnerability cou
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited,
A vulnerability in the management CLI of Cisco access point (AP) software could allow an authenticated, local attacker t
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform comman
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform comman
Multiple vulnerabilities in Cisco Intersight Private Virtual Appliance could allow an authenticated, remote attacker to
Multiple vulnerabilities in Cisco Intersight Private Virtual Appliance could allow an authenticated, remote attacker to
In ssh in OpenSSH before 9.6, OS command injection might occur if a user name or host name has shell metacharacters, and
A Huawei data communication product has a command injection vulnerability. Successful exploitation of this vulnerability
A vulnerability in the web-based management interface of Cisco Identity Services Engine could allow an authenticated, re
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in libzypp-p
A vulnerability classified as critical has been found in EasyNAS 1.1.0. Affected is the function system of the file /bac
A vulnerability was found in DolphinPHP up to 1.5.1. It has been declared as critical. Affected by this vulnerability is
A vulnerability was found in liferea. It has been rated as critical. Affected by this issue is the function update_job_r
Enphase Envoy versions D7.0.88 is vulnerable to a command injection exploit that may allow an attacker to execute root
A vulnerability was found in TamronOS up to 20230703. It has been classified as critical. This affects an unknown part o
A vulnerability, which was classified as critical, was found in TOTOLINK EX1200L EN_V9.3.5u.6146_B20201023. This affects
A vulnerability has been found in TOTOLINK EX1200L EN_V9.3.5u.6146_B20201023 and classified as critical. This vulnerabil
A vulnerability was found in TOTOLINK EX1200L EN_V9.3.5u.6146_B20201023 and classified as critical. This issue affects t
A vulnerability was found in D-Link DAR-8000-10 up to 20230809. It has been classified as critical. This affects an unkn
A vulnerability, which was classified as critical, was found in Byzoro Smart S45F Multi-Service Secure Gateway Intellige
A vulnerability was found in Byzoro Smart S45F Multi-Service Secure Gateway Intelligent Management Platform up to 202309
A vulnerability was found in Byzoro Smart S85F Management Platform up to 20231010 and classified as critical. This issue
A vulnerability was found in Hikvision Intercom Broadcasting System 3.0.3_20201113_RELEASE(HIK). It has been declared as
IBM Informix JDBC Driver 4.10 and 4.50 is susceptible to remote code execution attack via JNDI injection when passing an
A vulnerability, which was classified as critical, has been found in WeiYe-Jing datax-web 2.1.2. Affected by this issue
A command injection vulnerability in the DDNS service configuration of Western Digital My Cloud OS 5 devices running fir
Post-authentication remote command injection vulnerability in Western Digital My Cloud OS 5 devices that could allow an
A vulnerability in Cisco IOS XE Software for Cisco Catalyst 9300 Series Switches could allow an authenticated, local att
A vulnerability in the CLI of Cisco Firepower 4100 Series, Cisco Firepower 9300 Security Appliances, and Cisco UCS 6200,
Vulnerability in the CLI of Cisco Secure Email Gateway could allow an authenticated, remote attacker to execute arbitrar
Frequently Asked Questions
What is CWE-78?
CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-78?
There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.
How can I protect against CWE-78 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.
Detect CWE-78 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.
Get Started