CWE-77
MITRE ↗Improper Neutralization of Special Elements used in a Command (Command Injection)
Versions of the package nemo-appium before 0.0.9 are vulnerable to Command Injection due to improper input sanitization
Versions of the package mt7688-wiscan before 0.8.3 are vulnerable to Command Injection due to improper input sanitizatio
All versions of the package create-choo-app3 are vulnerable to Command Injection via the devInstall function due to impr
There is a command injection problem in the old version of the mobile phone backup app.
This affects versions of the package pydash before 6.0.0. A number of pydash methods such as pydash.objects.invoke() and
An issue was discovered in GNU Emacs through 28.2. In ruby-mode.el, the ruby-find-library-file function has a local comm
OneSignal is an email, sms, push notification, and in-app message service for mobile apps.The Zapier.yml workflow is tri
Snowflake JDBC provides a JDBC type 4 driver that supports core functionality, allowing Java program to connect to Snowf
snowflake-connector-net, the Snowflake Connector for .NET, is vulnerable to command injection prior to version 2.0.18 vi
snowflake-connector-nodejs, a NodeJS driver for Snowflake, is vulnerable to command injection via single sign on (SSO) b
All versions of the package node-qpdf are vulnerable to Command Injection such that the package-exported method encrypt(
A vulnerability was found in kalcaddle kodbox up to 1.48. It has been declared as critical. Affected by this vulnerabili
tj-actions/changed-files is a Github action to retrieve all files and directories. Prior to 41.0.0, the `tj-actions/chan
The webserver in Delta DX-3021 versions prior to 1.24 is vulnerable to command injection through the network diagnosis
OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, Custom Layout enabled admin users to exec
OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, Magento admin users with access to the cu
OpenMage LTS is an e-commerce platform. Prior to versions 19.4.22 and 20.0.19, an administrator with the permissions to
A vulnerability has been found in TRENDnet TEW-811DRU 1.0.10.0 and classified as critical. This vulnerability affects un
A vulnerability was found in TRENDnet TEW-652BRP 3.04b01. It has been classified as critical. Affected is an unknown fun
NetModule NSRW web administration interface executes an OS command constructed with unsanitized user input. A successful
Authenticated remote command injection vulnerabilities exist in the ArubaOS web-based management interface. Successful e
Authenticated remote command injection vulnerabilities exist in the ArubaOS web-based management interface. Successful e
Authenticated remote command injection vulnerabilities exist in the ArubaOS web-based management interface. Successful e
Authenticated remote command injection vulnerabilities exist in the ArubaOS web-based management interface. Successful e
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, was found in DrayTek Vigor 2960 1.5.1
A command injection vulnerability was discovered in Array Networks APV products. A remote attacker can send a crafted pa
An authenticated remote code execution vulnerability exists in the AOS-CX Network Analytics Engine. Successful e
A vulnerability, which was classified as critical, has been found in Ubiquiti EdgeRouter X 2.0.9-hotfix.6. This issue af
A vulnerability, which was classified as critical, was found in Ubiquiti EdgeRouter X 2.0.9-hotfix.6. Affected is an unk
A vulnerability has been found in Ubiquiti EdgeRouter X 2.0.9-hotfix.6 and classified as critical. Affected by this vuln
A post-auth command injection vulnerability in the exception wizard of Sophos Web Appliance older than version 4.3.10.4
Zoho ManageEngine ADManager Plus before 7181 allows for authenticated users to exploit command injection via Proxy setti
Atos Unify OpenScape SBC 10 before 10R3.1.3, OpenScape Branch 10 before 10R3.1.2, and OpenScape BCF 10 before 10R10.7.0
WBCE CMS 1.5.3 has a command execution vulnerability via admin/languages/install.php.
VMware Aria Operations for Logs contains a command injection vulnerability. A malicious actor with administrative privil
IBM Cloud Pak for Data 4.5 and 4.6 could allow a privileged user to upload malicious files of dangerous types that can
A vulnerability was identified in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. This vulnerability affects unknown code of
A security flaw has been discovered in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. This issue affects some unknown proce
A weakness has been identified in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. Impacted is an unknown function of the com
A security vulnerability has been detected in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. The affected element is an unk
A vulnerability was detected in Ubiquiti EdgeRouter X up to 2.0.9-hotfix.6. The impacted element is an unknown function
Frequently Asked Questions
What is CWE-77?
CWE-77 (Improper Neutralization of Special Elements used in a Command (Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-77?
There are 4,365 CVE records associated with CWE-77 in our database. Of these, 1041 are critical severity, 1473 are high severity, and 1080 are medium severity.
How can I protect against CWE-77 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-77 using AI-powered security agents.
Detect CWE-77 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in a command (command injection) vulnerabilities across your infrastructure.
Get Started