CWE-77
MITRE ↗Improper Neutralization of Special Elements used in a Command (Command Injection)
Improper neutralization of livestatus command delimiters in the RestAPI in Checkmk < 2.0.0p36, < 2.1.0p28, and < 2.2.0b8
Osprey Pump Controller version 1.01 contains an unauthenticated command injection vulnerability that could allow system
Netdata is an open source option for real-time infrastructure monitoring and troubleshooting. An attacker with the abili
Baicells Nova 436Q, Nova 430E, Nova 430I, and Neutrino 430 LTE TDD eNodeB devices with firmware through QRTB 2.12.7 are
Command Injection in GitHub repository thorsten/phpmyfaq prior to 3.1.11.
In Splunk Enterprise versions below 8.1.13, 8.2.10, and 9.0.4, the ‘display.page.search.patterns.sensitivity’ search par
Cocos Engine is an open-source framework for building 2D & 3D real-time rendering and interactive content. In the github
A post-authentication command injection vulnerability in the “account_operator.cgi” CGI program of Zyxel USG FLEX series
The `Release PR Merged` workflow in the github repo taosdata/grafanaplugin is subject to a command injection vulnerabili
An os command injection vulnerability exists in the liburvpn.so create_private_key functionality of Milesight VPN v2.0.2
Command Injection in GitHub repository gradio-app/gradio prior to main.
Microsoft Dynamics Unified Service Desk Remote Code Execution Vulnerability
nophp is a PHP web framework. Prior to version 0.0.1, nophp is vulnerable to shell command injection on httpd user. A pa
Command injection vulnerability in ELECOM and LOGITEC wireless LAN routers allows a network-adjacent authenticated attac
ELECOM wireless LAN routers WRC-1167GHBK-S v1.03 and earlier, and WRC-1167GEBK-S v1.03 and earlier allow a network-adjac
Command injection vulnerability in the homemng.htm endpoint in Juplink RX4-1500 Wifi router firmware versions V1.0.2, V1
Command injection in homemng.htm in Juplink RX4-1500 versions V1.0.2, V1.0.3, V1.0.4, and V1.0.5 allows remote authentic
A command injection vulnerability in the firmware_update command, in the device's restricted telnet interface, allows an
Windows MSHTML Platform Remote Code Execution Vulnerability
A vulnerability, which was classified as critical, was found in kylin-system-updater up to 1.4.20kord on Ubuntu Kylin. A
DrayTek Vigor2960 v1.5.1.4 allows an authenticated attacker with network access to the web management interface to injec
A flaw was found in the Emacs text editor. Processing a specially crafted org-mode code with the "org-babel-execute:late
LuaTeX before 1.17.0 allows execution of arbitrary shell commands when compiling a TeX file obtained from an untrusted s
All versions of the package n158 are vulnerable to Command Injection due to improper input sanitization in the 'module.e
A vulnerability was found in ImageMagick. This security flaw causes a shell command injection vulnerability via video:vs
In Percona XtraBackup (PXB) through 2.2.24 and 3.x through 8.0.27-19, a crafted filename on the local file system could
Previous versions of HP Device Manager (prior to HPDM 5.0.10) could potentially allow command injection and/or elevation
In Zimbra Collaboration Suite through 9.0 and 8.8.15, an attacker (who has initial user access to a Zimbra server instan
com.perimeter81.osx.HelperTool in Perimeter81 10.0.0.19 on macOS allows Local Privilege Escalation (to root) via shell m
.NET and Visual Studio Remote Code Execution Vulnerability
Phicomm k2 v22.6.529.216 was discovered to contain a command injection vulnerability via the function luci.sys.call.
Dell SmartFabric Storage Software v1.4 (and earlier) contains an OS Command Injection Vulnerability in the CLI use of t
Shell Injection vulnerability GL.iNet A1300 v4.4.6, AX1800 v4.4.6, AXT1800 v4.4.6, MT3000 v4.4.6, MT2500 v4.4.6, MT6000
The [`tj-actions/verify-changed-files`](https://github.com/tj-actions/verify-changed-files) action allows for command in
In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n
Command Injection vulnerability found in Tenda G103 v.1.0.05 allows an attacker to obtain sensitive information via a cr
An issue was discovered on GL.iNet devices running firmware before 3.216. There is an arbitrary file write in which an e
Versions of the package yhirose/cpp-httplib before 0.12.4 are vulnerable to CRLF Injection when untrusted user input is
Aria Operations for Networks contains an information disclosure vulnerability. A malicious actor with network access to
SRS is a real-time video server supporting RTMP, WebRTC, HLS, HTTP-FLV, SRT, MPEG-DASH, and GB28181. Prior to versions 5
Thymeleaf through 3.1.1.RELEASE, as used in spring-boot-admin (aka Spring Boot Admin) through 3.1.1 and other products,
Memcached 1.6.0 before 1.6.3 allows remote attackers to cause a denial of service (daemon crash) via a crafted meta comm
Command injection vulnerability in the distributed file system module. Successful exploitation of this vulnerability may
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Xiaomi Xiaomi Route
Versions of the package exec-local-bin before 1.2.0 are vulnerable to Command Injection via the theProcess() functionali
Versions of the package global-modules-path before 3.0.0 are vulnerable to Command Injection due to missing input saniti
All versions of the package smartctl are vulnerable to Command Injection via the info method due to improper input sanit
All versions of the package puppet-facter are vulnerable to Command Injection via the getFact function due to improper
All versions of the package create-choo-electron are vulnerable to Command Injection via the devInstall function due to
All versions of the package vagrant.js are vulnerable to Command Injection via the boxAdd function due to improper input
Frequently Asked Questions
What is CWE-77?
CWE-77 (Improper Neutralization of Special Elements used in a Command (Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-77?
There are 4,365 CVE records associated with CWE-77 in our database. Of these, 1041 are critical severity, 1473 are high severity, and 1080 are medium severity.
How can I protect against CWE-77 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-77 using AI-powered security agents.
Detect CWE-77 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in a command (command injection) vulnerabilities across your infrastructure.
Get Started