CWE-77
MITRE ↗Improper Neutralization of Special Elements used in a Command (Command Injection)
Command injection in IrGraph.draw in paddlepaddle/paddle 2.6.0
The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4,
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Wake DMCUB before executing GPINT
Insecure default configurations in Hikvision Interactive Tablet DS-D5B86RB/B V2.3.0 build220119, allows attackers to exe
The issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and
An arbitrary file creation vulnerability exists in PaperCut NG/MF that only affects Windows servers with Web Print enabl
A local attacker with low privileges can use a command injection vulnerability to gain root privileges due to improper i
Remote Code Execution has been discovered in OpenText™ iManager 3.2.6.0200. The vulnerability can trigger command inject
A vulnerability in the ConfD CLI and the Cisco Crosswork Network Services Orchestrator CLI could allow an authenticated
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in WatchGuard AuthPoin
A local privilege escalation vlnerability in the WatchGuard Mobile VPN with SSL client on Windows enables a local user t
A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 HF1). The system service of aff
A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 HF1). The system service of aff
The issue was addressed with improved memory handling. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14, wat
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited,
A Command Injection vulnerability found in a Self-Hosted UniFi Network Servers (Linux) with UniFi Network Application (V
In Progress Telerik UI for WPF versions prior to 2024 Q3 (2024.3.924), a command injection attack is possible through im
In Progress Telerik UI for WinForms versions prior to 2024 Q3 (2024.3.924), a command injection attack is possible throu
Visual Studio Code for Linux Remote Code Execution Vulnerability
In Progress Telerik Reporting versions prior to 2024 Q3 (18.2.24.924), a command injection attack is possible through im
A vulnerability has been found in the CPython `venv` module and CLI where path names provided when creating a virtual en
An attacker with local access the to medical office computer can escalate his Windows user privileges to "NT AUTHORITY\
Dell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) an Improper Neutralization
Dell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) a command injection vulner
Microsoft Excel Remote Code Execution Vulnerability
An OS command injection vulnerability has been reported to affect several product versions. If exploited, the vulnerabil
virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic templ
VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with local administrative
An issue in Razer Synapse 3 v.3.9.131.20813 and Synapse 3 App v.20240213 allows a local attacker to execute arbitrary co
A command injection is possible through the user interface, allowing arbitrary command execution as the root user. oMG2
Nginx-ui is online statistics for Server Indicators Monitor CPU usage, memory usage, load average, and disk usage in r
Dell ThinOS versions 2402 and 2405, contains an Improper Neutralization of Special Elements used in a Command ('Command
An injection vulnerability in Barco ClickShare CX-30/20, C-5/10, and ClickShare Bar Pro and Core models, running firmwar
Azure DevOps Server Remote Code Execution Vulnerability
Outlook for Android Information Disclosure Vulnerability
Improper verification of a user input in Open Source MANO v7-v12 allows an authenticated attacker to execute arbitrary c
D-Link DIR-822+ V1.0.5 was found to contain a command injection in SetPlcNetworkpwd function of prog.cgi, which allows r
D-Link DIR-845L router v1.01KRb03 and before is vulnerable to Command injection via the hnap_main()func.
Dell SmartFabric OS10 Software, version(s) 10.5.5.4 through 10.5.5.10 and 10.5.6.x , contain(s) an Improper Neutralizati
A prompt injection vulnerability in the chatbox of Blackbox AI v1.3.95 allows attackers to access and exfiltrate all pre
A prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica Your AI Copilot powered by ChatGPT4 v
A prompt injection vulnerability in the chatbox of Zhipu AI CodeGeeX v2.17.0 allows attackers to access and exfiltrate a
A prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica ChatGPT AI Assistant v2.4.0 allows at
A potential vulnerability was discovered in certain Poly video conferencing devices. The firmware flaw does not properly
An OS command injection vulnerability has been reported to affect QuMagie. If exploited, the vulnerability could allow a
An OS command injection vulnerability has been reported to affect Photo Station. If exploited, the vulnerability could a
VMware SD-WAN Edge contains an unauthenticated command injection vulnerability potentially leading to remote code execut
pgAdmin <= 8.4 is affected by a Remote Code Execution (RCE) vulnerability through the validate binary path API. This vu
Starship is a cross-shell prompt. Starting in version 1.0.0 and prior to version 1.20.0, undocumented and unpredictable
An OS command injection vulnerability has been reported to affect Video Station. If exploited, the vulnerability could a
Frequently Asked Questions
What is CWE-77?
CWE-77 (Improper Neutralization of Special Elements used in a Command (Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-77?
There are 4,365 CVE records associated with CWE-77 in our database. Of these, 1041 are critical severity, 1473 are high severity, and 1080 are medium severity.
How can I protect against CWE-77 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-77 using AI-powered security agents.
Detect CWE-77 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in a command (command injection) vulnerabilities across your infrastructure.
Get Started