CWE-77
MITRE ↗Improper Neutralization of Special Elements used in a Command (Command Injection)
A vulnerability was identified in ZSPACE Q2C NAS up to 1.1.0210050. Affected is the function zfilev2_api.CloseSafe of th
A security flaw has been discovered in ZSPACE Q2C NAS up to 1.1.0210050. Affected by this vulnerability is the function
A weakness has been identified in ZSPACE Q2C NAS up to 1.1.0210050. Affected by this issue is the function zfilev2_api.O
A vulnerability was detected in D-Link DIR-860LB1 and DIR-868LB1 203b01/203b03. Affected is an unknown function of the c
An issue in Yealink T21P_E2 Phone 52.84.0.15 allows a remote normal privileged attacker to execute arbitrary code via a
A security vulnerability has been detected in TRENDnet TEW-800MB 1.0.1.0. Affected is the function do_setWizard_asp of t
A vulnerability was detected in TRENDnet TEW-800MB 1.0.1.0. Affected by this vulnerability is the function sub_F934 of
A JNDI injection issue was discovered in Cloudera JDBC Connector for Hive before 2.6.26 and JDBC Connector for Impala be
When running in Appliance mode, and logged into a highly-privileged role, an authenticated remote command injection vuln
When running in Appliance mode, a command injection vulnerability exists in an undisclosed iControl REST and BIG-IP TMOS
Linksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.emailReg function. Th
VMware vCenter contains an SMTP header injection vulnerability. A malicious actor with non-administrative privileges on
Zohocorp ManageEngine ADManager Plus version before 8024 are vulnerable to authenticated command injection vulnerability
Improper neutralization of special elements used in a command ('command injection') in Azure Command Line Integration (C
A command injection vulnerability has been reported to affect HybridDesk Station. If an attacker gains local network acc
It was possible to perform Remote Command Execution (RCE) via Java RMI interface in the OpenEdge AdminServer, allowing a
The cbis_manager Podman container is vulnerable to remote command execution via the /api/plugins endpoint. Improper sani
This vulnerability allows malicious actors to execute arbitrary commands on the underlying system of the Zenitel ICX500
This vulnerability allows attackers to execute arbitrary commands on the underlying system. Because the web portal runs
An issue was discovered in BAE SOCET GXP before 4.6.0.2. An attacker with the ability to interact with the GXP Job Servi
Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized at
gardenctl is a command-line client for the Gardener which configures access to clusters and cloud provider CLI tools. Wh
A command injection vulnerability in the me.connectify.SMJobBlessHelper XPC service of Speedify VPN up to v15.0.0 allows
In JetBrains Toolbox App before 2.6 command injection in SSH plugin was possible
In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected application do not properly
Linksys E8450 v1.2.00.360516 was discovered to contain a command injection vulnerability via userEmail.
Microsoft 365 Copilot BizChat Information Disclosure Vulnerability
jshERP up to commit fbda24da was discovered to contain an unauthenticated remote code execution (RCE) vulnerability via
SPH Engineering UgCS 5.13.0 is vulnerable to Arbitary code execution.
Due to the improper handling of batch files in child_process.spawn / child_process.spawnSync, a malicious command line a
TOTOLINK A810R V4.1.2cu.5032_B20200407 was found to contain a command insertion vulnerability in downloadFile.cgi main f
A vulnerability was found in MicroWorld eScan Antivirus 7.0.32 on Linux. It has been rated as critical. This issue affec
Zitadel is open-source identity infrastructure software. Prior to versions 2.70.12, 2.71.10, and 3.2.2, a potential vuln
Roo Code is an AI-powered autonomous coding agent. The project-specific MCP configuration for the Roo Code agent is stor
A vulnerability, which was classified as critical, has been found in Comodo Internet Security Premium 12.3.4.8162. This
Successful exploitation of the vulnerability could allow an attacker to execute arbitrary commands as root, potentially
1Panel is a web interface and MCP Server that manages websites, files, containers, databases, and LLMs on a Linux server
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Versions prior to 2.5.3 and 2.2.15 are vulnerable to Command
Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Prior to version 3.26.7, Due to an error
TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the modifyOne para
Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the iface parameter in the vif_
Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the ifname parameter in the apc
Linksys E7350 1.1.00.032 was discovered to contain a command injection vulnerability via the iface parameter in the vif_
Linksys E8450 v1.2.00.360516 was discovered to contain a command injection vulnerability via wizard_status.
A vulnerability classified as critical was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic B
A vulnerability, which was classified as critical, has been found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic
A vulnerability, which was classified as critical, was found in H3C Magic NX30 Pro up to V100R007. This affects an unkno
A vulnerability has been found in H3C Magic NX30 Pro and Magic NX400 up to V100R014 and classified as critical. This vul
A vulnerability was found in H3C Magic NX15, Magic NX30 Pro, Magic NX400, Magic R3010 and Magic BE18000 up to V100R014 a
Frequently Asked Questions
What is CWE-77?
CWE-77 (Improper Neutralization of Special Elements used in a Command (Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-77?
There are 4,365 CVE records associated with CWE-77 in our database. Of these, 1041 are critical severity, 1473 are high severity, and 1080 are medium severity.
How can I protect against CWE-77 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-77 using AI-powered security agents.
Detect CWE-77 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in a command (command injection) vulnerabilities across your infrastructure.
Get Started