CWE-78
6,643 CVEs • Abstraction: Base • Likelihood of Exploit: High
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
CVEs (6,643)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.7 and earlier, the schedule router does not enforce organization/role checks. As a result, any authenticated user can create, update, run, or delete...Show more |
Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection in the application.updateTraefikConfig tRPC endpoint allows admin/owner users to execute arbitrary...Show more |
Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection in the /listen-deployment WebSocket endpoint allows any organization member to execute arbitrary sy...Show more |
Arcane is an interface for managing Docker containers, images, networks, and volumes. In 1.18.1 and earlier, GET /environments/{id}/volumes/{volumeName}/browse accepts a path query parameter that is passed to a shell com...Show more |
Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.0 and earlier, the deleteRegistry function in Dokploy (packages/server/src/services/registry.ts) executes docker logout ${response.registryUrl} witho...Show more |
WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a classic shell-metacharacter injection. The YPTSocket notification branch in plugin/Live/on_publish.php builds an execAsync() command line by s...Show more |
1Waterfall Security 1Wf 500 Firmware Jul 21, 2026 May 29, 2026 7.5 HIGH· v4 7.8 HIGH· v3 N/A· v2 Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in Waterfall WF-500 RX Host in version 7.9.1.0 R2502171040 that allows attackers with a...Show more |
1Waterfall Security 1Wf 500 Firmware Jul 21, 2026 May 29, 2026 8.6 HIGH· v4 7.2 HIGH· v3 N/A· v2 Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall WF-500 RX Host in version 7.9.1.0 R2502171040...Show more |
1Waterfall Security 1Wf 500 Firmware Jul 21, 2026 May 29, 2026 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040...Show more |
1Waterfall Security 1Wf 500 Firmware Jul 21, 2026 May 29, 2026 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040...Show more |
1Waterfall Security 1Wf 500 Firmware Jul 21, 2026 May 29, 2026 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040...Show more |
1Waterfall Security 1Wf 500 Firmware Jul 21, 2026 May 29, 2026 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040...Show more |
1Waterfall Security 1Wf 500 Firmware Jul 21, 2026 May 29, 2026 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040...Show more |
1Waterfall Security 1Wf 500 Firmware Jul 21, 2026 May 29, 2026 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040...Show more |
1Waterfall Security 1Wf 500 Firmware Jul 21, 2026 May 29, 2026 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040...Show more |
1Waterfall Security 1Wf 500 Firmware Jul 21, 2026 May 29, 2026 8.5 HIGH· v4 7.2 HIGH· v3 N/A· v2 Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall WF-500 TX Host in version 7.9.1.0 R2502171040...Show more |
1Waterfall Security 1Wf 500 Firmware Jul 21, 2026 May 29, 2026 8.6 HIGH· v4 7.2 HIGH· v3 N/A· v2 Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall WF-500 TX Host in version 7.9.1.0 R2502171040...Show more |
1Waterfall Security 1Wf 500 Firmware Jul 21, 2026 May 29, 2026 8.6 HIGH· v4 7.2 HIGH· v3 N/A· v2 Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall WF-500 TX Host in version 7.9.1.0 R2502171040...Show more |
Exposed methods allow authenticated users to create and execute arbitrary JavaScript code on the server. The scripts execute with full access, enabling complete system compromise as commands are executed as root. |
Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed via bash arithmetic expansion $((...)), allowing execution of arbitrary commands nested inside an allowlisted command like ech...Show more |