CWE-77
MITRE ↗Improper Neutralization of Special Elements used in a Command (Command Injection)
In network service, there is a missing permission check. This could lead to local escalation of privilege with System ex
In network service, there is a missing permission check. This could lead to local escalation of privilege with System ex
In network service, there is a missing permission check. This could lead to local escalation of privilege with System ex
In network service, there is a missing permission check. This could lead to local escalation of privilege with System ex
In network service, there is a missing permission check. This could lead to local escalation of privilege with System ex
Dell PowerScale OneFS, 8.2.x-9.4.x, contain a command injection vulnerability. An authenticated user having access loca
Amanda 3.5.1 allows privilege escalation from the regular user backup to root. The SUID binary located at /lib/amanda/ru
An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Xiaomi Xiaomi Route
An OS command injection vulnerability has been reported to affect QNAP operating systems. If exploited, the vulnerabilit
A vulnerability in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320 and RV3
A vulnerability in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV
A vulnerability in the web-based management interface of Cisco Small Business Routers RV016, RV042, RV042G, RV082, RV320
An issue was discovered in GitLab Community and Enterprise Edition before 11.11.8, 12 before 12.0.6, and 12.1 before 12.
A vulnerability in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communicat
Multiple vulnerabilities in Cisco Intersight Private Virtual Appliance could allow an authenticated, remote attacker to
Multiple vulnerabilities in Cisco Intersight Private Virtual Appliance could allow an authenticated, remote attacker to
A command injection vulnerability in Trellix Intelligent Sandbox CLI for version 5.2 and earlier, allows a local user t
SAP Solution Manager - version 720, allows an authorized attacker to execute certain deprecated function modules which c
A vulnerability was found in eprintsug ulcc-core. It has been declared as critical. Affected by this vulnerability is an
A vulnerability classified as critical was found in dst-admin 1.5.0. Affected by this vulnerability is an unknown functi
A vulnerability, which was classified as critical, has been found in dst-admin 1.5.0. Affected by this issue is some unk
A vulnerability, which was classified as critical, was found in dst-admin 1.5.0. This affects an unknown part of the fil
A vulnerability has been found in dst-admin 1.5.0 and classified as critical. This vulnerability affects unknown code of
A vulnerability classified as critical has been found in EasyNAS 1.1.0. Affected is the function system of the file /bac
A vulnerability was found in HadSky up to 7.11.8. It has been declared as critical. This vulnerability affects unknown c
A vulnerability was found in Weaver E-Office 9.5 and classified as critical. Affected by this issue is some unknown func
A vulnerability was found in Caton Live up to 2023-04-26 and classified as critical. This issue affects some unknown pro
1Panel is an open source Linux server operation and maintenance management panel. Prior to version 1.3.6, an authenticat
1Panel is an open source Linux server operation and maintenance management panel. Prior to version 1.3.6, an authenticat
Insufficient validation of untrusted input in Chromad in Google Chrome on ChromeOS prior to 115.0.5790.131 allowed a rem
A vulnerability was found in Byzoro Smart S85F Management Platform up to 20230722 and classified as critical. This issue
A vulnerability was found in Byzoro Smart S85F Management Platform up to 20230807. It has been declared as critical. Aff
Post-authentication remote command injection vulnerability in Western Digital My Cloud OS 5 devices that could allow an
Docker Desktop before 4.17.0 allows an attacker to execute an arbitrary command inside a Dev Environments container duri
Vulnerability in the CLI of Cisco Secure Email Gateway could allow an authenticated, remote attacker to execute arbitrar
Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, loc
Multiple vulnerabilities in the restricted shell of Cisco Evolved Programmable Network Manager (EPNM), Cisco Identity Se
Multiple vulnerabilities in the restricted shell of Cisco Evolved Programmable Network Manager (EPNM), Cisco Identity Se
Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, loc
A post-authentication remote command injection vulnerability in a CGI file in Western Digital My Cloud OS 5 devices that
A vulnerability in a specific Cisco ISE CLI command could allow an authenticated, local attacker to perform command inje
An issue was discovered in Citadel through webcit-926. Meddler-in-the-middle attackers can pipeline commands after POP3
matrix-appservice-irc is a Node.js IRC bridge for Matrix. Prior to version 1.0.1, it is possible to craft a command with
Jumpserver is a popular open source bastion host, and Koko is a Jumpserver component that is the Go version of coco, ref
An issue was identified in GitLab CE/EE affecting all versions from 1.0 prior to 15.8.5, 15.9 prior to 15.9.4, and 15.10
Versions of the package github.com/gin-gonic/gin before 1.9.0 are vulnerable to Improper Input Validation by allowing an
A vulnerability was found in trampgeek jobe up to 1.6.x and classified as critical. This issue affects the function run_
A vulnerability, which was classified as critical, was found in IonicaBizau node-gry up to 5.x. This affects an unknown
A vulnerability, which was classified as critical, has been found in json-logic-js 2.0.0. Affected by this issue is some
Frequently Asked Questions
What is CWE-77?
CWE-77 (Improper Neutralization of Special Elements used in a Command (Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-77?
There are 4,365 CVE records associated with CWE-77 in our database. Of these, 1041 are critical severity, 1473 are high severity, and 1080 are medium severity.
How can I protect against CWE-77 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-77 using AI-powered security agents.
Detect CWE-77 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in a command (command injection) vulnerabilities across your infrastructure.
Get Started