Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in a Command (Command Injection)

1,041
CRITICAL
1,473
HIGH
1,080
MEDIUM
26
LOW
3,664 CVEs · Page 33/74
4.7
CVE-2025-14094

A flaw has been found in Edimax BR-6478AC V3 1.0.15. The affected element is the function sub_44CCE4 of the file /boafrm

4.7
CVE-2025-14648

A security vulnerability has been detected in DedeBIZ up to 6.5.9. Affected by this vulnerability is an unknown function

4.5
CVE-2025-1369

A vulnerability classified as critical was found in MicroWord eScan Antivirus 7.0.32 on Linux. Affected by this vulnerab

4.5
CVE-2025-10767

A vulnerability was detected in CosmodiumCS OnlyRAT up to 3.2. The affected element is the function connect/remote_uploa

4.4
CVE-2025-25791

An arbitrary file upload vulnerability in the plugin installation feature of YZNCMS v2.0.1 allows attackers to execute a

4.4
CVE-2025-25792

SeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the isopen parameter at admin_wei

4.3
CVE-2025-25274

Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8 fail to restrict command execution in archived

4.1
CVE-2025-9769

A security flaw has been discovered in D-Link DI-7400G+ 19.12.25A1. Affected is the function sub_478D28 of the file /mng

4.1
CVE-2025-58132

Command injection in some Zoom Clients for Windows may allow an authenticated user to conduct a disclosure of informatio

3.7
CVE-2024-8402

An issue was discovered in GitLab EE affecting all versions starting from 17.2 before 17.7.7, all versions starting from

3.7
CVE-2024-9773

An issue was discovered in GitLab EE affecting all versions starting from 14.9 before 17.8.6, all versions starting from

3.7
CVE-2025-59376

feiskyer mcp-kubernetes-server through 0.1.11 does not consider chained commands in the implementation of --disable-writ

3.5
CVE-2024-54681

Multiple bash files were present in the application's private directory. Bash files can be used on their own, by an att

3.5
CVE-2025-6945

GitLab has remediated an issue in GitLab EE affecting all versions from 17.8 before 18.3.6, 18.4 before 18.4.4, and 18.5

3.4
CVE-2025-48979

An Improper Input Validation in UISP Application could allow a Command Injection by a malicious actor with High Privileg

2.7
CVE-2025-27146

matrix-appservice-irc is a Node.js IRC bridge for Matrix. The matrix-appservice-irc bridge up to version 3.0.3 contains

2.7
CVE-2025-41721

A high privileged remote attacker can influence the parameters passed to the openssl command due to improper neutralizat

2.4
CVE-2025-52687

Successful exploitation of the vulnerability could allow an attacker with administrator credentials for the access point

CVE-2023-5878

Honeywell OneWireless Wireless Device Manager (WDM) for the following versions R310.x, R320.x, R321.x, R322.1, R322.2,

CVE-2025-46735

Terraform WinDNS Provider allows users to manage their Windows DNS server resources through Terraform. A security issue

CVE-2025-4009

The Evertz SDVN 3080ipx-10G is a High Bandwidth Ethernet Switching Fabric for Video Application. This device exposes a w

CVE-2025-4010

The Netcom NTC 6200 and NWL 222 series expose a web interface to be configured and set up by operators. Multiple endpoin

CVE-2025-5113

The Diviotec professional series exposes a web interface. One endpoint is vulnerable to arbitrary command injection and

CVE-2025-4653

Improper Neutralization of Special Elements in the backup name field may allow OS command injection. This issue affects

CVE-2025-4678

Improper Neutralization of Special Elements in the chromium_path variable may allow OS command injection. This issue aff

0.0
CVE-2025-49823

(conda) Constructor is a tool which allows constructing an installer for a collection of conda packages. Prior to versio

CVE-2025-7769

Tigo Energy's CCA is vulnerable to a command injection vulnerability in the /cgi-bin/mobile_api endpoint when the DEVICE

CVE-2025-41451

Improper neutralization of alarm-to-mail configuration fields used in an OS shell Command ('Command Injection') in Danfo

CVE-2025-27233

Zabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get parameters, allowing an attacker to inject unex

CVE-2025-10364

The Evertz SDVN 3080ipx-10G is a High Bandwidth Ethernet Switching Fabric for Video Application. This device exposes a w

CVE-2025-61584

serverless-dns is a RethinkDNS resolver that deploys to Cloudflare Workers, Deno Deploy, Fastly, and Fly.io. Versions th

CVE-2025-62696

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in The Wikimedia Found

CVE-2025-1549

A local privilege escalation vulnerability in the WatchGuard Mobile VPN with SSL client on Windows enables a local user

CVE-2025-12155

A Command Injection vulnerability, resulting from improper file path sanitization (Directory Traversal) in Looker allows

CVE-2025-11921

iStats contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root via c

CVE-2025-1910

The WatchGuard Mobile VPN with SSL Client on Windows allows a locally authenticated non-administrative Windows user to e

10.0
CVE-2024-28354

There is a command injection vulnerability in the TRENDnet TEW-827DRU router with firmware version 2.10B01. An attacker

10.0
CVE-2024-3400 KEV

A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Netwo

10.0
CVE-2024-32766

An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited,

10.0
CVE-2024-29895

Cacti provides an operational monitoring and fault management framework. A command injection vulnerability on the 1.3.x

10.0
CVE-2024-43693

A specially crafted POST request to the ProGauge MAGLINK LX CONSOLE UTILITY sub-menu can allow a remote attacker to inj

10.0
CVE-2024-45066

A specially crafted POST request to the ProGauge MAGLINK LX CONSOLE IP sub-menu can allow a remote attacker to inject a

10.0
CVE-2024-20418

A vulnerability in the web-based management interface of Cisco Unified Industrial Wireless Software for Cisco Ultra-Reli

9.9
CVE-2024-21663

Discord-Recon is a Discord bot created to automate bug bounty recon, automated scans and information gathering via a dis

9.9
CVE-2024-37091

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in StylemixThemes Cons

9.9
CVE-2024-20432

A vulnerability in the REST API and web UI of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticate

9.9
CVE-2024-9264

The SQL Expressions experimental feature of Grafana allows for the evaluation of `duckdb` queries containing user input.

9.8
CVE-2023-51812

Tenda AX3 v16.03.12.11 was discovered to contain a remote code execution (RCE) vulnerability via the list parameter at /

9.8
CVE-2023-49237

An issue was discovered on TRENDnet TV-IP1314PI 5.5.3 200714 devices. Command injection can occur because the system fun

9.8
CVE-2023-31446

In Cassia Gateway firmware XC1000_2.1.1.2303082218 and XC2000_2.1.1.2303090947, the queueUrl parameter in /bypass/config

Frequently Asked Questions

What is CWE-77?

CWE-77 (Improper Neutralization of Special Elements used in a Command (Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-77?

There are 4,365 CVE records associated with CWE-77 in our database. Of these, 1041 are critical severity, 1473 are high severity, and 1080 are medium severity.

How can I protect against CWE-77 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-77 using AI-powered security agents.

Detect CWE-77 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in a command (command injection) vulnerabilities across your infrastructure.

Get Started