CWE-77
MITRE ↗Improper Neutralization of Special Elements used in a Command (Command Injection)
An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited,
A vulnerability has been found in Tenda FH1202 1.2.0.14(408) and classified as critical. Affected by this vulnerability
A vulnerability was found in Edimax IC-6220DC and IC-5150W up to 3.06. It has been rated as critical. Affected by this i
A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the
CSV Injection vulnerability in the Asus RT-N12+ router allows administrator users to inject arbitrary commands or formul
Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). Sup
D-LINK DIR-845L <=v1.01KRb03 is vulnerable to Information disclosurey via bsc_sms_inbox.php.
WAVLINK WN551K1 found a command injection vulnerability through the IP parameter of /cgi-bin/touchlist_sync.cgi.
WAVLINK WN551K1 found a command injection vulnerability through the start_hour parameter of /cgi-bin/nightled.cgi.
A vulnerability identified in Advance Authentication that allows bash command Injection in administrative controlled fun
A low privileged remote attacker can use a command injection vulnerability in the API which performs remote code executi
Custom Twitter Feeds WordPress plugin before 2.2.3 does not sanitise and escape some of its settings, which could allow
A vulnerability was found in Arris VAP2500 08.50. It has been declared as critical. Affected by this vulnerability is an
A vulnerability was found in Arris VAP2500 08.50. It has been rated as critical. Affected by this issue is some unknown
A vulnerability classified as critical has been found in Arris VAP2500 08.50. This affects an unknown part of the file /
A vulnerability has been found in Ruijie RG-UAC 1.0 and classified as critical. This vulnerability affects the function
In streampark, the project module integrates Maven's compilation capabilities. The input parameter validation is not str
In streampark, the project module integrates Maven's compilation capabilities. The input parameter validation is not str
A vulnerability was found in DedeCMS up to 5.7.115. It has been rated as critical. This issue affects some unknown proce
A vulnerability was found in WAVLINK WN530H4, WN530HG4 and WN572HG3 up to 20221028 and classified as critical. This issu
A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. It has been classified as crit
A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. It has been declared as critic
A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. It has been rated as critical.
A vulnerability classified as critical has been found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. Th
A vulnerability classified as critical was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118. This vu
A vulnerability, which was classified as critical, has been found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to
A vulnerability, which was classified as critical, was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241
A vulnerability has been found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118 and classified as critical
A vulnerability was found in EnGenius ENH1350EXT, ENS500-AC and ENS620EXT up to 20241118 and classified as critical. Aff
A vulnerability in the ClearPass Policy Manager web-based management interface allows remote authenticated users to run
Splinefont in FontForge through 20230101 allows command injection via crafted filenames.
An issue discovered in Alldata v0.4.6 allows attacker to run arbitrary commands via the processId parameter.
H3C Magic R230 V100R002's udpserver opens port 9034, allowing attackers to execute arbitrary commands.
Monica AI Assistant desktop application v2.3.0 is vulnerable to Exposure of Sensitive Information to an Unauthorized Act
Tenda AC500 V2.0.1.9(1307) firmware contains a command injection vulnerablility in the formexeCommand function via the c
TOTOLINK outdoor CPE CP450 v4.1.0cu.747_B20191224 was discovered to contain a command injection vulnerability in the NTP
In Helix Sync versions prior to 2024.1, a local command injection was identified. Reported by Bryan Riggins.
sshproxy is used on a gateway to transparently proxy a user SSH connection on the gateway to an internal host via SSH. P
Zabbix allows to configure SMS notifications. AT command injection occurs on "Zabbix Server" because there is no validat
A vulnerability in the web-based management interface of multiple Ligowave devices could allow an authenticated remote a
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Netflix ConsoleMe a
The affected device expose a network service called "rftest" that is vulnerable to unauthenticated command injection on
This vulnerability allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by
Improper filering of special characters result in a command ('command injection') vulnerability in Korenix JetPort 5601v
Wiz Code Visual Studio Code extension in versions 1.0.0 up to 1.5.3 and Wiz (legacy) Visual Studio Code extension in ver
Symphony process is a module for the Symphony PHP framework which executes commands in sub-processes. On Windows, when a
A vulnerability has been identified in SCALANCE LPE9403 (All versions < V2.1). The web based management of affected devi
The Danfoss AK-EM100 web applications allow for an authenticated user to perform OS command injection through the web ap
Improper Input Validation vulnerability in Honeywell PM43 on 32 bit, ARM (Printer web page modules) allows Command Injec
In Boa, there is a possible command injection due to improper input validation. This could lead to remote escalation of
Frequently Asked Questions
What is CWE-77?
CWE-77 (Improper Neutralization of Special Elements used in a Command (Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-77?
There are 4,365 CVE records associated with CWE-77 in our database. Of these, 1041 are critical severity, 1473 are high severity, and 1080 are medium severity.
How can I protect against CWE-77 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-77 using AI-powered security agents.
Detect CWE-77 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in a command (command injection) vulnerabilities across your infrastructure.
Get Started