CWE-78
MITRE ↗Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)
Adobe After Effects version 18.1 (and earlier) is affected by a potential Command injection vulnerability when chained w
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.3, 14.1.x before 14.1.4, and 13.1.x before 13.1.4, lack of
A vulnerability in the web-based management interface of Cisco Small Business RV160, RV160W, RV260, RV260P, and RV260W V
Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) a
A remote execution of arbitrary commands vulnerability was discovered in some Aruba Instant Access Point (IAP) products
An unvalidated REST API in the AppFormix Agent of Juniper Networks AppFormix allows an unauthenticated remote attacker t
A command injection vulnerability has been reported to affect QNAP NAS running legacy versions of QTS. If exploited, thi
All versions of package gitlogplus are vulnerable to Command Injection via the main functionality, as options attributes
A Shell Metacharacter Injection vulnerability in result.php in DRK Odenwaldkreis Testerfassung March-2021 allow an attac
An OS command injection vulnerability in the Palo Alto Networks PAN-OS management interface exists when performing dynam
An OS command injection vulnerability in the Simple Certificate Enrollment Protocol (SCEP) feature of PAN-OS software al
Multiple improper neutralization of special elements used in a command vulnerabilities [CWE-77] in FortiWeb management i
Magento versions 2.4.1 (and earlier), 2.4.0-p1 (and earlier) and 2.3.6 (and earlier) are vulnerable to an OS command inj
/jsonrpc on D-Link DIR-841 3.03 and 3.04 devices allows authenticated command injection via ping, ping6, or traceroute (
HomeAutomation 3.3.2 suffers from an authenticated OS command execution vulnerability using custom command v0.1 plugin.
The affected product is vulnerable to a parameter injection via passphrase, which enables the attacker to supply uncontr
ELECOM LAN routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmwar
OS command injection vulnerability in ELECOM routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.2
An issue was discovered in ClusterLabs crmsh through 4.2.1. Local attackers able to call "crm history" (when "crm" is ru
A command injection vulnerability in the license-check daemon of Juniper Networks Junos OS that may allow a locally auth
A vulnerability in a CLI command of Cisco IOS XR Software for the Cisco 8000 Series Routers and Network Convergence Syst
Dell EMC PowerScale OneFS versions 8.1.0 - 9.1.0 contain an improper input validation vulnerability. A user with the ISI
Accellion FTA 9_12_411 and earlier is affected by OS command execution via a local web service call. The fixed version i
A command injection issue in dji_sys in DJI Mavic 2 Remote Controller before firmware version 01.00.0510 allows for code
Amaze File Manager before 3.5.1 allows attackers to obtain root privileges via shell metacharacters in a symbolic link.
PowerScale OneFS 8.1.2,8.2.2 and 9.1.0 contains an improper input sanitization issue in a command. The Compadmin user co
The text-to-speech engine in libretro RetroArch for Windows 1.9.0 passes unsanitized input to PowerShell through platfor
In SaltStack Salt 2016.9 through 3002.6, a command injection vulnerability exists in the snapper module that allows for
A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker
A vulnerability in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, local attacker to
A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to inject arbitrary com
An improper input validation in FortiAI v1.4.0 and earlier may allow an authenticated user to gain system shell access v
Inkdrop versions prior to v5.3.1 allows an attacker to execute arbitrary OS commands on the system where it runs by load
An improper neutralization of special elements used in an OS Command vulnerability in FortiAP's console 6.4.1 through 6.
D-Link router DSL-2750U with firmware vME1.16 or prior versions is vulnerable to OS command injection. An unauthenticate
This affects the package bikeshed before 3.0.0. This can occur when an untrusted source file containing Inline Tag Comma
Multiple vulnerabilities in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker with a low-pri
Multiple vulnerabilities in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker with a low-pri
A command injection vulnerability in command processing on Juniper Networks Junos OS Evolved allows an attacker with aut
A command injection vulnerability in tcpdump command processing on Juniper Networks Junos OS Evolved allows an attacker
A command injection vulnerability in sftp command processing on Juniper Networks Junos OS Evolved allows an attacker wit
A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to execute arbit
Prisma is an open source ORM for Node.js & TypeScript. As of today, we are not aware of any Prisma users or external con
An OS command injection vulnerability in FortiWeb's management interface 6.3.7 and below, 6.2.3 and below, 6.1.x, 6.0.x,
Pepperl+Fuchs Comtrol IO-Link Master in Version 1.5.48 and below is prone to an authenticated blind OS Command Injection
This affects all versions of package port-killer. If (attacker-controlled) user input is given, it is possible for an at
This affects the package killport before 1.0.2. If (attacker-controlled) user input is given, it is possible for an atta
Gradle is a build tool with a focus on build automation. In versions prior to 7.2, start scripts generated by the `appli
ssh2 is client and server modules written in pure JavaScript for node.js. In ssh2 before version 1.4.0 there is a comman
furlongm openvpn-monitor through 1.1.3 allows %0a command injection via the OpenVPN management interface socket. This ca
Frequently Asked Questions
What is CWE-78?
CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-78?
There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.
How can I protect against CWE-78 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.
Detect CWE-78 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.
Get Started