Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in a Command (Command Injection)

1,041
CRITICAL
1,473
HIGH
1,080
MEDIUM
26
LOW
3,664 CVEs · Page 20/74
9.8
CVE-2025-55637

Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 was discovered to contain a

9.8
CVE-2025-57105

The DI-7400G+ router has a command injection vulnerability, which allows attackers to execute arbitrary commands on the

9.8
CVE-2025-50722

Insecure Permissions vulnerability in sparkshop v.1.1.7 allows a remote attacker to execute arbitrary code via the Commo

9.8
CVE-2025-50428

In RaspAP raspap-webgui 3.3.2 and earlier, a command injection vulnerability exists in the includes/hostapd.php script.

9.8
CVE-2025-57285

codeceptjs 3.7.3 contains a command injection vulnerability in the emptyFolder function (lib/utils.js). The execSync com

9.8
CVE-2025-57633

A command injection vulnerability in FTP-Flask-python through 5173b68 allows unauthenticated remote attackers to execute

9.8
CVE-2025-59046

The npm package `interactive-git-checkout` is an interactive command-line tool that allows users to checkout a git branc

9.8
CVE-2025-52053

TOTOLINK X6000R V9.4.0cu.1360_B20241207 was found to contain a command injection vulnerability in the sub_417D74 functio

9.8
CVE-2025-59834

ADB MCP Server is a MCP (Model Context Protocol) server for interacting with Android devices through ADB. In versions 0.

9.8
CVE-2025-61044

TOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability via the agentName param

9.8
CVE-2025-61045

TOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability via the mac parameter i

9.8
CVE-2025-59735

Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe

9.8
CVE-2025-59736

Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe

9.8
CVE-2025-59737

Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe

9.8
CVE-2025-59738

Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe

9.8
CVE-2025-59739

Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe

9.8
CVE-2025-59740

Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe

9.8
CVE-2025-59741

Operating system command injection vulnerability in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to exe

9.8
CVE-2025-66219

willitmerge is a command line tool to check if pull requests are mergeable. In versions 0.2.1 and prior, there is a comm

9.8
CVE-2025-60854

A vulnerability has been found in D-Link R15 (AX1500) 1.20.01 and below. By manipulating the model name parameter during

9.8
CVE-2025-66032

Claude Code is an agentic coding tool. Prior to 1.0.93, Due to errors in parsing shell commands related to $IFS and shor

9.8
CVE-2025-67728

Fireshare facilitates self-hosted media and link sharing. Versions 1.2.30 and below allow an authenticated user, or unau

9.8
CVE-2025-14705

A vulnerability was determined in Shiguangwu sgwbox N3 2.0.25. This affects an unknown function of the component SHARESE

9.8
CVE-2025-14706

A vulnerability was identified in Shiguangwu sgwbox N3 2.0.25. This impacts an unknown function of the file /usr/sbin/ht

9.8
CVE-2025-14707

A security flaw has been discovered in Shiguangwu sgwbox N3 2.0.25. Affected is an unknown function of the file /usr/sbi

9.8
CVE-2025-50526

Netgear EX8000 V1.0.0.126 was discovered to contain a command injection vulnerability via the switch_status function.

9.8
CVE-2025-29228

Linksys E5600 V1.1.0.26 is vulnerable to command injection in the runtime.macClone function via the mc.ip parameter.

9.8
CVE-2025-29229

linksys E5600 V1.1.0.26 is vulnerable to command injection in the function ddnsStatus.

9.8
CVE-2025-69201

Tugtainer is a self-hosted app for automating updates of docker containers. In versions prior to 1.15.1, arbitary argume

9.6
CVE-2024-52325

ECOVACS robot lawnmowers and vacuums are vulnerable to command injection via SetNetPin() over an unauthenticated BLE con

9.6
CVE-2025-3621

Vulnerabilities* in ActADUR local server product, developed and maintained by ProTNS, allows Remote Code Inclusion on ho

9.6
CVE-2025-67511

Cybersecurity AI (CAI) is an open-source framework for building and deploying AI-powered offensive and defensive automat

9.4
CVE-2025-46816

goshs is a SimpleHTTPServer written in Go. Starting in version 0.3.4 and prior to version 1.0.5, running goshs without a

9.4
CVE-2025-29628

A Gardyn Azure IoT Hub connection string is downloaded over an insecure HTTP connection in Gardyn Home Kit firmware befo

9.3
CVE-2025-59252

Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized at

9.3
CVE-2025-59272

Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized at

9.3
CVE-2025-59286

Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized at

9.2
CVE-2025-43858

YoutubeDLSharp is a wrapper for the command-line video downloaders youtube-dl and yt-dlp. In versions starting from 1.0.

9.1
CVE-2024-37186

An os command injection vulnerability exists in the adm.cgi set_ledonoff() functionality of Wavlink AC3000 M33A8.V5030.2

9.1
CVE-2024-39360

An os command injection vulnerability exists in the nas.cgi remove_dir() functionality of Wavlink AC3000 M33A8.V5030.210

9.1
CVE-2024-39367

An os command injection vulnerability exists in the firewall.cgi iptablesWebsFilterRun() functionality of Wavlink AC3000

9.1
CVE-2024-39762

Multiple OS command injection vulnerabilities exist in the internet.cgi set_add_routing() functionality of Wavlink AC300

9.1
CVE-2024-39763

Multiple OS command injection vulnerabilities exist in the internet.cgi set_add_routing() functionality of Wavlink AC300

9.1
CVE-2024-39764

Multiple OS command injection vulnerabilities exist in the internet.cgi set_add_routing() functionality of Wavlink AC300

9.1
CVE-2024-39765

Multiple OS command injection vulnerabilities exist in the internet.cgi set_add_routing() functionality of Wavlink AC300

9.1
CVE-2024-39781

Multiple OS command injection vulnerabilities exist in the adm.cgi sch_reboot() functionality of Wavlink AC3000 M33A8.V5

9.1
CVE-2024-39782

Multiple OS command injection vulnerabilities exist in the adm.cgi sch_reboot() functionality of Wavlink AC3000 M33A8.V5

9.1
CVE-2024-39783

Multiple OS command injection vulnerabilities exist in the adm.cgi sch_reboot() functionality of Wavlink AC3000 M33A8.V5

9.1
CVE-2024-41783

IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow a privileged user to inje

9.1
CVE-2024-54794

The script input feature of SpagoBI 3.5.1 allows arbitrary code execution.

Frequently Asked Questions

What is CWE-77?

CWE-77 (Improper Neutralization of Special Elements used in a Command (Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-77?

There are 4,365 CVE records associated with CWE-77 in our database. Of these, 1041 are critical severity, 1473 are high severity, and 1080 are medium severity.

How can I protect against CWE-77 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-77 using AI-powered security agents.

Detect CWE-77 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in a command (command injection) vulnerabilities across your infrastructure.

Get Started