Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)

1,941
CRITICAL
3,146
HIGH
963
MEDIUM
16
LOW
6,290 CVEs · Page 8/126
9.8
CVE-2026-71947

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command inj

9.8
CVE-2026-71948

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command inj

9.8
CVE-2026-71949

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command inj

9.8
CVE-2026-71950

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command inj

9.8
CVE-2026-71951

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command inj

9.8
CVE-2026-71952

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command inj

9.8
CVE-2026-71953

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command inj

9.8
CVE-2026-71954

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command inj

9.8
CVE-2026-71955

D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection

9.8
CVE-2026-71956

D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection

9.8
CVE-2026-71983

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the wps.cgi interface th

9.8
CVE-2026-71984

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the urlfilter function t

9.8
CVE-2026-71985

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the accesscontrol functi

9.8
CVE-2026-71986

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the dmz function that al

9.8
CVE-2026-71987

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the alg function that al

9.8
CVE-2026-71988

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the portFw function that

9.8
CVE-2026-71989

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the porTrigger function

9.8
CVE-2026-71990

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function u

9.8
CVE-2026-71991

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function u

9.8
CVE-2026-71992

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the macfilter function t

9.8
CVE-2026-71993

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the openvpn function tha

9.8
CVE-2026-72580

An OS command injection vulnerability in duhow/xiaoai-patch through commit fb07049 allows a remote attacker to execute a

9.8
CVE-2026-72589

An OS command injection vulnerability in alseambusher/crontab-ui through 0.4.2 allows an unauthenticated remote attacker

9.8
CVE-2026-13206

Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Zyxel Networ

9.8
CVE-2026-16956

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary commands due to improper neutr

9.8
CVE-2026-49819

UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-esc

9.8
CVE-2026-67965

An issue in Tneda W20E v.16.01.0.6(2782) allows a remote attacker to execute arbitrary code via the url_need_login funct

9.8
CVE-2026-16882

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to imprope

9.8
CVE-2026-53545

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2

9.8
CVE-2026-18482

Neo.mjs contains a command injection vulnerability within the FileSystemService.mjs component of the ai/mcp/server/file-

9.8
CVE-2026-78211

4MOSAn GCB Doctor developed by 4MOSAn Security Technology has a OS Command Injection vulnerability. Unauthenticated remo

9.8
CVE-2026-71914

Multiple DrayTek VigorAP models contain a command injection vulnerability in the dray_apm component. The vulnerability i

9.8
CVE-2026-71921

Multiple DrayTek VigorSwitch models contain a pre-authentication command injection vulnerability in the setget.cgi inter

9.8
CVE-2026-63586

The web-based management interface uses a modified uhttpd server with CGI shell scripts. The HTTP Basic Authentication u

9.8
CVE-2026-45018

Chainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0,

9.8
CVE-2026-80138

ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passing it to s

9.8
CVE-2026-74233

Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE242

9.8
CVE-2026-82082

NUMail developed by Green-Computing has an OS Command Injection vulnerability. Unauthenticated remote attackers can inje

9.8
CVE-2026-37751

An OS command injection vulnerability in the killSessionSync function (lib/agent-runtime.ts) of 23blocks-OS ai-maestro v

9.6
CVE-2025-66398

Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.19.0, an unauthenticate

9.6
CVE-2026-25130

Cybersecurity AI (CAI) is a framework for AI Security. In versions up to and including 0.5.10, the CAI (Cybersecurity AI

9.6
CVE-2026-40088

PraisonAI is a multi-agent teams system. Prior to 4.5.121, the execute_command function and workflow shell execution are

9.6
CVE-2026-35906

An undocumented debug CGI endpoint in T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03 allows unauthenticated at

9.6
CVE-2026-55743

The shell tool command allowlist in the SecurityPolicy of OpenHuman desktop agent through 0.54.0 (default Supervised sec

9.6
CVE-2026-72877

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the dockerImage field is interpolated w

9.6
CVE-2026-72878

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy's backup and restore pipeline c

9.6
CVE-2026-49481

UpSnap is a wake on lan web app. Versions prior to 5.4.0 have an OS command injection vulnerability in the UpSnap’s devi

9.3
CVE-2026-41064

WWBN AVideo is an open source video platform. In versions up to and including 29.0, an incomplete fix for AVideo's `test

9.3
CVE-2026-44590

Sherlock hunts down social media accounts by username across social networks. Prior to 0.16.1, the GitHub Actions workfl

9.2
CVE-2026-27208

bleon-ethical/api-gateway-deploy provides API gateway deployment. Version 1.0.0 is vulnerable to an attack chain involvi

Frequently Asked Questions

What is CWE-78?

CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-78?

There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.

How can I protect against CWE-78 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.

Detect CWE-78 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.

Get Started