CWE-78
MITRE ↗Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)
cnMaestro is vulnerable to a local privilege escalation. By default, a user does not have root privileges. However, a us
IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.2.0 could allow a remote authenticated attacker to execute arbit
Arr-pm is an RPM reader/writer library written in Ruby. Versions prior to 0.0.12 are subject to OS command injection res
Zoho ManageEngine ADSelfService Plus before build 6122 allows a remote authenticated administrator to execute arbitrary
Addressed a remote code execution vulnerability by resolving a command injection vulnerability and closing an AWS S3 buc
IBM CICS TX 11.1 could allow allow an attacker with physical access to the system to execute code due using a back and r
An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] i
gl-inet GL-MT300N-V2 Mango v3.212 and GL-AX1800 Flint v3.214 were discovered to contain multiple command injection vulne
PAX A930 device with PayDroid_7.1.1_Virgo_V04.3.26T1_20210419 can allow the execution of specific command injections on
OS command injection vulnerability in Buffalo network devices allows a network-adjacent attacker with an administrative
Arbitrary Command Injection in GitHub repository strapi/strapi prior to 4.1.0.
An improper neutralization of special elements used in an OS command vulnerability in the command line interpreter of Fo
The Check Point Gaia Portal's GUI Clients allowed authenticated administrators with permission for the GUI Clients setti
Improper Input Validation vulnerability in a particular configuration setting field of Hitachi Energy TXpert Hub CoreTec
A vulnerability in the CLI of Cisco FXOS Software could allow an authenticated, local attacker to inject arbitrary comma
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to overwrite and possib
An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface
Dell PowerScale OneFS, versions 8.2.2-9.3.0, contain an OS command injection vulnerability. A privileged local malicious
All versions of package git are vulnerable to Remote Code Execution (RCE) due to missing sanitization in the Git.git met
sharp is an application for Node.js image processing. Prior to version 0.30.5, there is a possible vulnerability in logi
PROSCEND - PROSCEND / ADVICE .Ltd - G/5G Industrial Cellular Router (with GPS)4 Unauthenticated OS Command Injection Pro
Multiple command injection vulnerabilities in GL.iNet GoodCloud IoT Device Management System Version 1.00.220412.00 via
Specially crafted string in OTRS system configuration can allow the execution of any system command.
Dell VNX2 for File version 8.1.21.266 and earlier, contain a privilege escalation vulnerability. A local malicious admin
Dell EMC PowerStore versions 2.0.0.x, 2.0.1.x, and 2.1.0.x are vulnerable to a command injection flaw. An authenticated
Dell PowerStore, versions prior to 3.0.0.0, contains an OS Command Injection vulnerability in PowerStore T environment.
In Lens prior to 5.3.4, custom helm chart configuration creates helm commands from string concatenation of provided argu
A vulnerability was found in OpenNetAdmin 18.1.1. It has been rated as critical. Affected by this issue is some unknown
A vulnerability has been found in ajenti 2.1.31 and classified as critical. This vulnerability affects unknown code of t
Michlol - rashim web interface Insecure direct object references (IDOR). First of all, the attacker needs to login. Afte
A vulnerability classified as critical was found in SourceCodester Human Resource Management System 1.0. This vulnerabil
A vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Software could allow an a
A vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Software could allow an a
A vulnerability was found in Sapido BR270n, BRC76n, GR297 and RB1732 and classified as critical. Affected by this issue
A vulnerability was found in C-DATA Web Management System. It has been rated as critical. This issue affects some unknow
A vulnerability was found in docconv up to 1.2.0. It has been declared as critical. This vulnerability affects the funct
Shescape is a shell escape package for JavaScript. An issue in versions 1.4.0 to 1.5.1 allows for exposure of the home d
Dell EMC Unity, Dell EMC UnityVSA and Dell EMC Unity XT versions prior to 5.1.2.0.5.007 contain an operating system (OS)
Dell EMC PowerStore, contains an OS command injection Vulnerability. A locally authenticated attacker could potentially
A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software and Cisco FXOS Software could allow an authe
The package snyk before 1.1064.0 are vulnerable to Code Injection when analyzing a project. An attacker who can convince
The affected On-Premise cnMaestro is vulnerable to an arbitrary file-write through improper limitation of a pathname to
Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an att
A vulnerability in the web-based management interface of Cisco Secure Network Analytics, formerly Cisco Stealthwatch Ent
A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to perform
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache Airfl
ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk. Moodle 3.10
"IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed
The GitOps Tools Extension for VSCode relies on kubeconfigs in order to communicate with Kubernetes clusters. A speciall
The bash_completion script for fscrypt allows injection of commands via crafted mountpoint paths, allowing privilege esc
Frequently Asked Questions
What is CWE-78?
CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-78?
There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.
How can I protect against CWE-78 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.
Detect CWE-78 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.
Get Started