CWE-78
MITRE ↗Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)
WRC-300FEBK, WRC-F300NF, WRC-733FEBK, WRH-300RD, WRH-300BK, WRH-300SV, WRH-300WH, WRH-H300WH, WRH-H300BK, WRH-300BK-S, a
A command injection vulnerability in the sandcat plugin of Caldera 2.3.1 and earlier allows authenticated attackers to e
Poddycast is a podcast app made with Electron. Prior to version 0.8.1, an attacker can create a podcast or episode with
An improper neutralization of special elements used in an OS Command vulnerability in FortiSandbox 3.2.0 through 3.2.2,
An OS command injection vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administra
Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a command injection vulnerability in ma
/graphStatus/displayServiceStatus.php in Centreon 19.10.8 allows remote attackers to execute arbitrary OS commands via s
Authenticated Semi-Blind Command Injection (via Parameter Injection) exists on Altus Nexto, Nexto Xpress, and Hadron Xto
Certain MOXA devices allow Authenticated Command Injection via /forms/web_importTFTP. This affects WAC-2004 1.7, WAC-100
A Improper neutralization of special elements used in a command ('Command Injection') in Fortinet FortiWeb version 6.3.1
SAP NetWeaver Knowledge Management XML Forms versions - 7.10, 7.11, 7.30, 7.31, 7.40, 7.50, contains an XSLT vulnerabili
On version 15.1.x before 15.1.0.5, 14.1.x before 14.1.3.1, 13.1.x before 13.1.3.5, and all versions of 12.1.x and 11.6.x
The Device42 Remote Collector before 17.05.01 does not sanitize user input in its SNMP Connectivity utility. This allows
Multiple vulnerabilities in the Cisco ATA 190 Series Analog Telephone Adapter Software could allow an attacker to perfor
A vulnerability in the web-based management interface of Cisco Intersight Virtual Appliance could allow an authenticated
The WordPress PDF Light Viewer Plugin WordPress plugin before 1.4.12 allows users with Author roles to execute arbitrary
A improper neutralization of special elements used in an OS command ('OS Command Injection') in Fortinet FortiWLM versio
A shell command injection in the HW Events SNMP community in XoruX LPAR2RRD and STOR2RRD before 7.30 allows authenticate
An issue was discovered in OpenGamePanel OGP-Agent-Linux through 2021-08-14. An authenticated attacker could inject OS c
An OS command injection vulnerability in the Palo Alto Networks PAN-OS web interface enables an authenticated administra
kustomize-controller is a Kubernetes operator, specialized in running continuous delivery pipelines for infrastructure a
An unauthenticated remote code execution vulnerability was reported in some Motorola-branded Binatone Hubble Cameras tha
This issue was discovered when the ipTIME C200 IP Camera was synchronized with the ipTIME NAS. It is necessary to extrac
An issue was discovered on Victure WR1200 devices through 1.0.3. A command injection vulnerability was found within the
Improper neutralization of special elements in the SMA100 management interface '/cgi-bin/viewcert' POST http method allo
A post-authentication remote command injection vulnerability in SonicWall SMA100 allows a remote authenticated attacker
An unauthenticated command injection vulnerability exists in multiple parameters in the Gryphon Tower router’s web inter
An unauthenticated command injection vulnerability exists in the parameters of operation 3 in the controller_server serv
An unauthenticated command injection vulnerability exists in the parameters of operation 10 in the controller_server ser
An unauthenticated command injection vulnerability exists in the parameters of operation 32 in the controller_server ser
An unauthenticated command injection vulnerability exists in the parameters of operation 41 in the controller_server ser
An unauthenticated command injection vulnerability exists in the parameters of operation 48 in the controller_server ser
An unauthenticated command injection vulnerability exists in the parameters of operation 49 in the controller_server ser
FiberHome ONU GPON AN5506-04-F RP2617 is affected by an OS command injection vulnerability. This vulnerability allows th
OS Command injection vulnerability in function link in Filesystem.php in Laravel Framework before 5.8.17.
An OS command injection vulnerability exists in the Web Manager FsUnmount functionality of Lantronix PremierWave 2050 8.
TP-Link wifi router TL-WR802N V4(JP), with firmware version prior to 211202, is vulnerable to OS command injection.
A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cach
Trendnet AC2600 TEW-827DRU version 2.08B01 is vulnerable to command injection. The system log functionality of the firmw
Trendnet AC2600 TEW-827DRU version 2.08B01 contains a command injection vulnerability in the smb functionality of the de
Netgear Nighthawk R6700 version 1.0.4.120 contains a command injection vulnerability in update functionality of the devi
The restricted shell provided by Akkadian Provisioning Manager Engine (PME) can be bypassed by switching the OpenSSH cha
A command injection vulnerability has been reported to affect QNAP device running Media Streaming add-on. If exploited,
This affects the package total.js before 3.4.7. The issue occurs in the image.pipe and image.stream functions. The type
Adobe Digital Editions 4.5.11.187646 (and earlier) are affected by an arbitrary command execution vulnerability. An auth
A command injection vulnerability in MVISION EDR (MVEDR) prior to 3.4.0 allows an authenticated MVEDR administrator to t
Nimble is a package manager for the Nim programming language. In Nim release version before versions 1.2.10 and 1.4.4, N
Discord-Recon is a bot for the Discord chat service. Versions of Discord-Recon 0.0.3 and prior contain a vulnerability i
Dell OpenManage Enterprise-Modular (OME-M) versions prior to 1.30.00 contain a security bypass vulnerability. An authent
Adobe Illustrator version 25.2.3 (and earlier) is affected by a potential Command injection vulnerability when chained w
Frequently Asked Questions
What is CWE-78?
CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-78?
There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.
How can I protect against CWE-78 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.
Detect CWE-78 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.
Get Started