CWE-77
MITRE ↗Improper Neutralization of Special Elements used in a Command (Command Injection)
gluestack-ui is a library of copy-pasteable components & patterns crafted with Tailwind CSS (NativeWind). Prior to commi
An issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the authenticat
tj-actions/branch-names is a Github actions repository that contains workflows to retrieve branch or tag names with supp
aiven-db-migrate is an Aiven database migration tool. Prior to 1.0.7, there is a privilege escalation vulnerability that
OPNsense before 25.1.8 contains an authenticated command injection vulnerability in its Bridge Interface Edit endpoint (
A vulnerability was found in Roxy-WI up to 8.1.3. It has been declared as critical. Affected by this vulnerability is th
Command Injection in Minidlna version v1.3.3 and before allows an attacker to execute arbitrary OS commands via a specia
A code injection vulnerability exists in the Ambari Alert Definition feature, allowing authenticated users to inject an
Edimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 suffers from Command Injection issues in /bin/goahead. Specificall
A privacy issue was addressed with improved handling of files. This issue is fixed in Safari 18.3, iOS 18.3 and iPadOS 1
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint
The vulnerability may allow a remote low priviledged attacker to run arbitrary shell commands by using lower-level funct
A command injection vulnerability exists in the /check_image_and_trigger_recovery API endpoint of Bitdefender Box 1 (fir
A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiManager versions
Improper Neutralization of Special Elements used in a Command vulnerability allows OS Command Injection.This issue affec
Lack of input validation/sanitization in the 'setLanCfg' API endpoint in httpd in the Tenda RX2 Pro 16.03.30.14 allows a
A vulnerability classified as critical has been found in D-Link DIR-600L up to 2.07B01. This affects the function formSy
A vulnerability classified as critical was found in D-Link DIR-600L up to 2.07B01. This vulnerability affects the functi
Jan v0.5.14 and before is vulnerable to remote code execution (RCE) when the user clicks on a rendered link in the conve
Multiple Code Injection vulnerabilities in EasyVirt DC NetScope <= 8.7.0 allows remote authenticated attackers to execut
The Meteobridge web interface let meteobridge administrator manage their weather station data collection and administer
A vulnerability was found in Teledyne FLIR AX8 up to 1.46.16. This vulnerability affects the function setDataTime of the
GetSimple CMS is a content management system. In versions starting from 3.3.16 to 3.3.21, an authenticated user with acc
A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the
A vulnerability classified as critical was found in Wifi-soft UniBox Controller up to 20250506. Affected by this vulnera
A vulnerability, which was classified as critical, has been found in Wifi-soft UniBox Controller up to 20250506. Affecte
A vulnerability, which was classified as critical, was found in Wifi-soft UniBox Controller up to 20250506. This affects
Mingyu Security Gateway before v3.0-5.3p was discovered to contain a remote command execution (RCE) vulnerability via th
A vulnerability was found in TOTOLINK X15 1.0.0-B20230714.1105. It has been classified as critical. Affected is an unkno
Nest is a framework for building scalable Node.js server-side applications. In versions 0.2.0 and below, a critical Remo
The KuWFi 4G AC900 LTE router 1.0.13 is vulnerable to command injection on the HTTP API endpoints /goform/formMultiApnSe
A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attack
A security issue exists within FactoryTalk Optix MQTT broker due to the lack of URI sanitization. This flaw enables the
Improper neutralization of special elements used in a command ('command injection') in SQL Server allows an authorized a
Ai command injection in Agentic AI and Visual Studio Code allows an unauthorized attacker to execute code over a network
A command injection vulnerability in COMFAST CF-XR11 (firmware V2.7.2) exists in the multi_pppoe API, processed by the s
In 2wcom IP-4c 2.16, the web interface allows admin and manager users to execute arbitrary code as root via a ping or tr
The LB-Link routers, including the BL-AC2100_AZ3 V1.0.4, BL-WR4000 v2.5.0, BL-WR9000_AE4 v2.4.9, BL-AC1900_AZ2 v1.0.2, B
A vulnerability in the HTTP API subsystem of Cisco IOS XE Software could allow a remote attacker to inject commands that
git-commiters is a Node.js function module providing committers stats for their git repository. Prior to version 0.1.2,
An issue was discovered in DIR-823 firmware 20250416. There is an RCE vulnerability in the set_cassword settings interfa
Zohocorp ManageEngine Applications Manager versions 178100 and below are vulnerable to authenticated command injection v
Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code CoPilot Chat E
Dell SmartFabric OS10 Software, versions prior to 10.6.1.0, contain an Improper Neutralization of Special Elements used
Dell SmartFabric OS10 Software, versions prior to 10.6.1.0, contain an Improper Neutralization of Special Elements used
An issue in Intermesh BV GroupOffice vulnerable before v.25.0.47 and 6.8.136 allows a remote attacker to execute arbitra
Cacti is an open source performance and fault management framework. Prior to 1.2.29, there is an input-validation flaw i
AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injec
AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injec
AVTECH SECURITY Corporation DGM1104 FullImg-1015-1004-1006-1003 was discovered to contain an authenticated command injec
Frequently Asked Questions
What is CWE-77?
CWE-77 (Improper Neutralization of Special Elements used in a Command (Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-77?
There are 4,365 CVE records associated with CWE-77 in our database. Of these, 1041 are critical severity, 1473 are high severity, and 1080 are medium severity.
How can I protect against CWE-77 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-77 using AI-powered security agents.
Detect CWE-77 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in a command (command injection) vulnerabilities across your infrastructure.
Get Started