CWE-78
MITRE ↗Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)
A vulnerability in the REST API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker
TensorFlow is an open source platform for machine learning. In affected versions TensorFlow's `saved_model_cli` tool is
ohmyzsh is vulnerable to Improper Neutralization of Special Elements used in an OS Command
Vulnerability in dirhistory plugin Description: the widgets that go back and forward in the directory history, triggered
# Vulnerability in `title` function **Description**: the `title` function defined in `lib/termsupport.zsh` uses `print`
# Vulnerability in `rand-quote` and `hitokoto` plugins **Description**: the `rand-quote` and `hitokoto` fetch quotes fro
# Vulnerability in `pygmalion`, `pygmalion-virtualenv` and `refined` themes **Description**: these themes use `print -P`
Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. In Vela compiler
Mechanize is an open-source ruby library that makes automated web interaction easy. In Mechanize from version 2.0.0 and
All versions of package kill-process-on-port are vulnerable to Command Injection via a.getProcessPortId.
All versions of package geojson2kml are vulnerable to Command Injection via the index.js file. PoC: var a =require("geoj
This affects all versions of package ps-visitor. If attacker-controlled user input is given to the kill function, it is
This affects all versions of package psnode. If attacker-controlled user input is given to the kill function, it is poss
This affects all versions of package portkiller. If (attacker-controlled) user input is given, it is possible for an att
This affects all versions of package killing. If attacker-controlled user input is given, it is possible for an attacker
This affects all versions of package wincred. If attacker-controlled user input is given to the getCredential function,
A command injection vulnerability in the CGI program of the Zyxel VPN2S firmware version 1.12 could allow an authenticat
In Mahara before 20.04.5, 20.10.3, 21.04.2, and 21.10.0, exporting collections via PDF export could lead to code executi
A vulnerability in SonicWall SMA100 appliance allow an authenticated management-user to perform OS command injection usi
A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows
An issue was discovered in the Manage Plugins page in Nagios XI before 5.8.0. Because the line-ending conversion feature
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV110W, RV130, RV130W, and RV215W
Zen Cart 1.5.7b allows admins to execute arbitrary OS commands by inspecting an HTML radio input element (within the mod
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV32
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV32
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV32
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV32
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV32
vSphere Replication 8.3.x prior to 8.3.1.2, 8.2.x prior to 8.2.1.1, 8.1.x prior to 8.1.2.3 and 6.5.x prior to 6.5.1.5 co
FileZen (V3.0.0 to V4.2.7 and V5.0.0 to V5.0.2) allows a remote attacker with administrator rights to execute arbitrary
On Netshield NANO 25 10.2.18 devices, /usr/local/webmin/System/manual_ping.cgi allows OS command injection (after authen
OS Command Injection vulnerability when changing date settings or hostname using web GUI of Nozomi Networks Guardian and
A remote authenticated command Injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prio
A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prio
A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prio
A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prio
A remote authenticated command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prio
A remote authenticated arbitrary command execution vulnerability was discovered in Aruba AirWave Management Platform ver
baserCMS versions prior to 4.4.5 allows a remote attacker with an administrative privilege to execute arbitrary OS comma
A remote execution of arbitrary commands vulnerability was discovered in some Aruba Instant Access Point (IAP) products
A remote execution of arbitrary commands vulnerability was discovered in some Aruba Instant Access Point (IAP) products
Improper neutralization of special elements used in an OS command in SYNO.Core.Network.PPPoE in Synology DiskStation Man
The Web Set Media Image function in ASUS BMC’s firmware Web management page does not filter the specific parameter. As o
The specific function in ASUS BMC’s firmware Web management page (Modify user’s information function) does not filter th
A command injection vulnerability in Avaya Session Border Controller for Enterprise could allow an authenticated, remote
NEC Aterm devices (Aterm WF1200CR firmware Ver1.3.2 and earlier, Aterm WG1200CR firmware Ver1.3.3 and earlier, and Aterm
Frequently Asked Questions
What is CWE-78?
CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-78?
There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.
How can I protect against CWE-78 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.
Detect CWE-78 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.
Get Started