CWE-78
MITRE ↗Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)
A flaw was found in WebSVN 2.3.2. Without prior authentication, if the 'allowDownload' option is enabled in config.php,
An issue was discovered in the add function in Shenzhim AAPTJS 1.3.1 which allows attackers to execute arbitrary code vi
An issue was discovered in the list function in shenzhim aaptjs 1.3.1, allows attackers to execute arbitrary code via th
An issue was discovered in the dump function in shenzhim aaptjs 1.3.1, allows attackers to execute arbitrary code via th
An issue was discovered in the packageCmd function in shenzhim aaptjs 1.3.1, allows attackers to execute arbitrary code
An issue was discovered in the remove function in shenzhim aaptjs 1.3.1, allows attackers to execute arbitrary code via
An issue was discovered in the crunch function in shenzhim aaptjs 1.3.1, allows attackers to execute arbitrary code via
An issue was discovered in the singleCrunch function in shenzhim aaptjs 1.3.1, allows attackers to execute arbitrary cod
A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B0
A command injection vulnerability was discovered in the HNAP1 protocol in D-Link DIR-823G devices with firmware V1.0.2B0
Sharetribe Go is a source available marketplace software. In affected versions operating system command injection is pos
OS Command Injection vulnerability in debug_fcgi of D-Link DWR-932C E1 firmware allows a remote attacker to perform comm
PowerCMS XMLRPC API of PowerCMS 5.19 and earlier, PowerCMS 4.49 and earlier, PowerCMS 3.295 and earlier, and PowerCMS 2
A command injection vulnerability has been reported to affect QNAP device, VioStor. If exploited, this vulnerability all
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. Multiple functions in the bpserverd daemon w
naholyr github-todos 3.1.0 is vulnerable to command injection. The range argument for the _hook subcommand is concatenat
Git-it through 4.4.0 allows OS command injection at the Branches Aren't Just For Birds challenge step. During the verifi
IBM Spectrum Copy Data Management 2.2.13 and earlier could allow a remote attacker to execute arbitrary commands on the
Gerapy is a distributed crawler management framework. Gerapy prior to version 0.9.8 is vulnerable to remote code executi
A vulnerability in the Command Runner tool of Cisco DNA Center could allow an authenticated, remote attacker to perform
nbgitpuller is a Jupyter server extension to sync a git repository one-way to a local path. Due to unsanitized input, vi
BinderHub is a kubernetes-based cloud service that allows users to share reproducible interactive computing environments
OS Command Injection vulnerability in the wirelessConnect handler of Abode iota All-In-One Security Kit allows an attack
APKLeaks is an open-source project for scanning APK file for URIs, endpoints & secrets. APKLeaks prior to v2.0.3 allows
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to OS command inject
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to OS command inject
The package async-git before 1.13.2 are vulnerable to Command Injection via shell meta-characters (back-ticks). For exam
A command execution vulnerability exists in the default legacy spellchecker plugin in Moodle 3.10. A specially crafted s
Command injection vulnerability in QSAN Storage Manager allows remote privileged users to execute arbitrary commands. Su
Dell EMC OpenManage Enterprise-Modular (OME-M) versions prior to 1.10.00 contain a command injection vulnerability. A re
Dell OpenManage Enterprise versions prior to 3.6.1 contain an OS command injection vulnerability in RACADM and IPMI tool
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an XML Inj
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an Imprope
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to an attacker using a ping tool to i
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to an attacker using a traceroute too
Dell EMC CloudLink 7.1 and all prior versions contain an OS command injection Vulnerability. A remote high privileged at
There is a Potential Zip Slip Vulnerability and OS Command Injection Vulnerability on the management system of baserCMS.
A specially-crafted HTTP request can lead to arbitrary command execution in RSA keypasswd parameter. An attacker can mak
A specially-crafted HTTP request can lead to arbitrary command execution in DSA keypasswd parameter. An attacker can mak
A specially-crafted HTTP request can lead to arbitrary command execution in EC keypasswd parameter. An attacker can make
Specially-crafted HTTP requests can lead to arbitrary command execution in PUT requests. An attacker can make authentica
Specially-crafted HTTP requests can lead to arbitrary command execution in “GET” requests. An attacker can make authenti
An OS command injection vulnerability exists in the Web Manager SslGenerateCSR functionality of Lantronix PremierWave 20
An OS command injection vulnerability exists in the Web Manager SslGenerateCertificate functionality of Lantronix Premie
This affects all versions of package docker-cli-js. If the command parameter of the Docker.command method can at least b
systeminformation is an open source system and OS information library for node.js. A command injection vulnerability has
An OS command injection vulnerability in FortiDeceptor 3.1.0, 3.0.1, 3.0.0 may allow a remote authenticated attacker to
The Yale WIPC-303W 2.21 through 2.31 camera is vulnerable to remote command execution (RCE) through command injection vi
A Command Injection issue in the traceroute feature on TP-Link TL-WR841N V13 (JP) with firmware versions prior to 201216
KLog Server through 2.4.1 allows authenticated command injection. async.php calls shell_exec() on the original value of
Frequently Asked Questions
What is CWE-78?
CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-78?
There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.
How can I protect against CWE-78 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.
Detect CWE-78 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.
Get Started