CWE-78
MITRE ↗Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)
systeminformation is an npm package that provides system and OS information library for node.js. In systeminformation be
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulne
react-dev-utils prior to v11.0.4 exposes a function, getProcessForPort, where an input argument is concatenated into a c
This affects all versions of package ps-kill. If (attacker-controlled) user input is given to the kill function, it is p
This affects all versions of package kill-process-by-name. If (attacker-controlled) user input is given, it is possible
This affects all versions of package roar-pidusage. If attacker-controlled user input is given to the stat function of t
A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to execute arbitrar
Sage X3 System CHAINE Variable Script Command Injection. An authenticated user with developer access can pass OS command
Multiple vulnerabilities exist in the web-based management interface of Cisco Small Business RV Series Routers. A remote
CODESYS V2 runtime system SP before 2.4.7.55 has Improper Neutralization of Special Elements used in an OS Command.
SLO generator allows for loading of YAML files that if crafted in a specific format can allow for code execution within
A vulnerability in the configuration dashboard of Cisco Common Services Platform Collector (CSPC) could allow an authent
Multiple command injection vulnerabilities in the command line interpreter of FortiWeb versions 6.4.1, 6.4.0, 6.3.0 thro
The @diez/generation npm package is a client for Diez. The locateFont method of @diez/generation has a command injection
It was discovered that the get_modified_conffiles() function in backends/packaging-apt-dpkg.py allowed injecting modifie
SAP Solution Manager and SAP Focused Run (update provided in WILY_INTRO_ENTERPRISE 9.7, 10.1, 10.5, 10.7), allows an att
The reported vulnerability allows an attacker who has network access to the device to execute code with specially crafte
An exploitable command injection vulnerability exists in encrypted diagnostic script functionality of the Moxa AWK-3131A
Command Injection in EntoneWebEngine in Amino Communications AK45x series, AK5xx series, AK65x series, Aria6xx series, A
USVN (aka User-friendly SVN) before 1.0.9 allows remote code execution via shell metacharacters in the number_start or n
Bulb Security Smartphone Pentest Framework (SPF) 0.1.2 through 0.1.4 allows remote attackers to execute arbitrary comman
The application login page in AKIPS Network Monitor 15.37 through 16.5 allows a remote unauthenticated attacker to execu
In "index.js" file line 240, the run command executes the git command with a user controlled variable called remoteUrl.
devcert-sanscache before 0.4.7 allows remote attackers to execute arbitrary code or cause a Command Injection via the ex
In aws-lambda versions prior to version 1.0.5, the "config.FunctioName" is used to construct the argument used within th
Unify OpenStage / OpenScape Desk Phone IP before V3 R3.11.0 SIP has an OS command injection vulnerability in the web bas
languageOptions.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows unauthenticated attackers to re
A remote code execution issue was discovered in HashBrown CMS through 1.3.3. Server/Entity/Deployer/GitDeployer.js has a
Freelancy v1.0.0 allows remote command execution via the "file":"data:application/x-php;base64 substring (in conjunction
BibTeX-ruby before 5.1.0 allows shell command injection due to unsanitized user input being passed directly to the built
emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST requ
emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST requ
emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST requ
emfd in Ruckus Wireless Unleashed through 200.7.10.102.64 allows remote attackers to execute OS commands via a POST requ
In IXP EasyInstall 6.2.13723, there is Remote Code Execution via the Agent Service. An unauthenticated attacker can comm
Intellian Aptus Web 1.24 allows remote attackers to execute arbitrary OS commands via the Q field within JSON data to th
Synacor Zimbra Collaboration before 8.0.9 allows plaintext command injection during STARTTLS.
Command-injection vulnerability in Huawei E587 3G Mobile Hotspot 11.203.27 allows remote attackers to execute arbitrary
The download_from_url function in OpenShift Origin allows remote attackers to execute arbitrary commands via shell metac
A Command Injection vulnerability exists in the /var/www/cgi-bin/rtpd.cgi script in D-Link IP Cameras DCS-3411/3430 firm
D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via a urn: to the
D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via the urn: to t
D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via the urn: to t
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
A Command Injection vulnerability exists in Zavio IP Cameras through 1.6.3 via the ap parameter to /cgi-bin/mft/wireless
A Command Injection vulnerability exists in Zavio IP Cameras through 1.6.3 in the General.Time.NTP.Server parameter to t
A Command Injection vulnerability exists in the ap parameter to the /cgi-bin/mft/wireless_mft.cgi file in TP-Link IP Cam
All versions including 0.0.4 of lsof npm module are vulnerable to Command Injection. Every exported method used by the p
DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow
network-manager through 1.0.2 allows remote attackers to execute arbitrary commands via the "execSync()" argument.
Frequently Asked Questions
What is CWE-78?
CWE-78 (Improper Neutralization of Special Elements used in an OS Command (OS Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-78?
There are 7,691 CVE records associated with CWE-78 in our database. Of these, 1941 are critical severity, 3146 are high severity, and 963 are medium severity.
How can I protect against CWE-78 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-78 using AI-powered security agents.
Detect CWE-78 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in an os command (os command injection) vulnerabilities across your infrastructure.
Get Started