CWE-77
MITRE ↗Improper Neutralization of Special Elements used in a Command (Command Injection)
Versions of the package network before 0.7.0 are vulnerable to Arbitrary Command Injection due to use of the child_proce
An unauthenticated remote attacker can perform a command injection in the OCPP Service with limited privileges due to im
A vulnerability was found in Ruijie RG-NBS2009G-P up to 20240305. It has been declared as critical. Affected by this vul
A flaw was found in Cockpit. Deleting a sosreport with a crafted name via the Cockpit web interface can lead to a comman
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in D-Link DNS-320L, DNS-325
Tenda FH1203 V2.0.1.6 firmware has a command injection vulnerablility in formexeCommand function via the cmdinput parame
An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in Fortine
A Command Injection vulnerability in Juniper Networks Junos Space allows an unauthenticated, network-based attacker send
Sercomm Router Etisalat Model S3- AC2100 is affected by Incorrect Access Control via the diagnostic utility in the route
Databricks JDBC Driver 2.x before 2.6.40 could potentially allow remote code execution (RCE) by triggering a JNDI inject
A vulnerability, which was classified as critical, has been found in DrayTek Vigor2960 and Vigor300B 1.5.1.3/1.5.1.4. Th
A vulnerability, which was classified as critical, was found in DrayTek Vigor2960 and Vigor300B 1.5.1.4. Affected is an
The Newsletters WordPress plugin before 4.9.3 does not properly escape user-controlled parameters when they are appended
A vulnerability was found in TRENDnet TEW-822DRE 1.03B02. It has been declared as critical. This vulnerability affects u
An issue was discovered in GTB Central Console 15.17.1-30814.NG. The method systemSettingsDnsDataAction at /opt/webapp/s
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run a
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run a
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run a
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run a
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run a
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of
Dell vApp Manager, versions prior to 9.2.4.9 contain a Command Injection Vulnerability. An authorized attacker could pot
Dell vApp Manager, versions prior to 9.2.4.9 contain a Command Injection Vulnerability. An authorized attacker could pot
There is a command injection vulnerability in some Hikvision NVRs. This could allow an authenticated user with administr
Microsoft Defender for IoT Remote Code Execution Vulnerability
A flaw was found in cri-o, where an arbitrary systemd property can be injected via a Pod annotation. Any user who can cr
Tenda O3V2 with firmware versions V1.0.0.10 and V1.0.0.12 was discovered to contain a Blind Command Injection via dest p
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V5.30), SICORE Base syste
A command injection vulnerability exists in the IOCTL that manages OTA updates. A specially crafted command can lead to
TELSAT marKoni FM Transmitters are vulnerable to a command injection vulnerability through the manipulation of settings
Netwrix CoSoSys Endpoint Protector through 5.9.3 and CoSoSys Unify through 7.0.6 contain a remote code execution vulnera
A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface that allows remot
A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface that allows remot
A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface that allows remot
A command-injection issue in the Certificate Signing Request (CSR) functionality in R-HUB TurboMeeting through 8.x allow
A command injection vulnerability could allow an authenticated user to execute operating system commands as root via a s
An issue in Koha ILS 23.05 and before allows a remote attacker to execute arbitrary code via a crafted script to the for
Firmware in KAON AR2140 routers, prior to versions 3.2.50 and 4.2.16, is vulnerable to a shell command injection via sen
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability via the url parameter
DedeCMS V5.7.115 has a command execution vulnerability via file_manage_view.php?fmdo=newfile&activepath.
Vulnerability in admin_ip.php in Seacms v13.1, when action=set, allows attackers to control IP parameters that are writt
Microsoft SharePoint Server Remote Code Execution Vulnerability
Microsoft SharePoint Server Remote Code Execution Vulnerability
An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authen
Authenticated Remote Code Execution in Altalink, Versalink & WorkCentre Products.
A vulnerability was found in WAVLINK WN530H4, WN530HG4 and WN572HG3 up to 20221028. It has been rated as critical. This
A vulnerability classified as critical has been found in WAVLINK WN530H4, WN530HG4 and WN572HG3 up to 20221028. Affected
Frequently Asked Questions
What is CWE-77?
CWE-77 (Improper Neutralization of Special Elements used in a Command (Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-77?
There are 4,365 CVE records associated with CWE-77 in our database. Of these, 1041 are critical severity, 1473 are high severity, and 1080 are medium severity.
How can I protect against CWE-77 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-77 using AI-powered security agents.
Detect CWE-77 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in a command (command injection) vulnerabilities across your infrastructure.
Get Started