CWE-78
MITRE ↗Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)
The c_rehash script does not properly sanitise shell metacharacters to prevent command injection. This script is distrib
In addition to the c_rehash shell command injection identified in CVE-2022-1292, further circumstances where the c_rehas
A potential vulnerability was reported in Lenovo PCManager prior to version 5.0.10.4191 that may allow code execution wh
A vulnerability has been found in Teledyne FLIR AX8 up to 1.46.16. Affected by this issue is some unknown functionality
The files_antivirus component before 1.0.0 for ownCloud allows OS Command Injection via the administration settings.
Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authenticated remote code execution vulnerability. A r
Dell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authenticated remote code execution vulnerability. A r
Liferay Portal Server tested on 7.3.5 GA6, 7.2.0 GA1 is affected by OS Command Injection. An administrator user can inje
Liferay Portal Server tested on 7.3.5 GA6, 7.2.0 GA1 is affected by OS Command Injection. An administrator user can inje
An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136
An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136
An OS command injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136
An OScommand injection vulnerability exists in the device network settings functionality of reolink RLC-410W v3.0.0.136_
OS Command Injection in Packagist microweber/microweber prior to 1.2.11.
Multiple improper neutralization of special elements used in an OS command vulnerabilities (CWE-78) in the Web GUI of Fo
An issue was discovered in Galleon NTS-6002-GPS 4.14.103-Galleon-NTS-6002.V12 4. An authenticated attacker can perform c
An OS command injection vulnerability exists in the console factory functionality of InHand Networks InRouter302 V3.5.4.
A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10
A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10
A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10
A Command Injection vulnerability in httpd web server (setup.cgi) in SerComm h500s, FW: lowi-h500s-v3.4.22 allows logged
An issue was discovered in Poly EagleEye Director II before 2.2.2.1. os.system command injection can be achieved by an a
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiManager ve
Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in task managem
This affects all versions of package s3-kilatstorage.
Improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in webapi compo
OS command injection vulnerability in Nintendo Wi-Fi Network Adaptor WAP-001 All versions allows an attacker with an adm
A privileged attacker in GeoNetwork before 3.12.0 and 4.x before 4.0.4 can use the directory harvester before-script to
OS Command Injection vulnerability in Hitachi RAID Manager Storage Replication Adapter allows remote authenticated users
Authenticated command injection vulnerabilities exist in the AOS-CX Network Analytics Engine via NAE scripts. Successful
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in
TOTOLINK-720R v4.1.5cu.374 was discovered to contain a remote code execution (RCE) vulnerability via the setdiagnosicfg
TOTOLINK-720R v4.1.5cu.374 was discovered to contain a remote code execution (RCE) vulnerability via the setTracerouteCf
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run a
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run a
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run a
RAVA certificate validation system has insufficient filtering for special parameter of the web page input field. A remot
An OS command injection vulnerability exists in the web_server /action/import_authorized_keys/ functionality of Robustel
SolarWinds Platform was susceptible to Command Injection. This vulnerability allows a remote adversary with complete con
An OS command injection vulnerability allows admins to execute code via SSL VPN configuration uploads in Sophos Firewall
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of
Vulnerabilities in the Aruba EdgeConnect Enterprise command line interface allow remote authenticated users to run arbit
Tenda W20E V16.01.0.6(3392) is vulnerable to Command injection via cmd_get_ping_output.
Delta Electronics DX-2100-L1-CN 2.42 is vulnerable to Command Injection via lform/net_diagnose.
An improper input validation vulnerability in FortiClient for Linux 6.4.x before 6.4.3, FortiClient for Linux 6.2.x befo
Frequently Asked Questions
What is CWE-78?
CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-78?
There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.
How can I protect against CWE-78 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.
Detect CWE-78 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.
Get Started