CWE-77
MITRE ↗Improper Neutralization of Special Elements used in a Command (Command Injection)
A malicious user on the same LAN could use DNS spoofing followed by a command injection attack to trick a NAS device int
An issue was discovered in Cobbler before 3.3.1. In the templar.py file, the function check_for_invalid_imports can allo
The laser command injection vulnerability exists on AIS-BW80H-00 versions earlier than AIS-BW80H-00 9.0.3.4(H100SP13C00)
A command injection vulnerability in the function formImportOMCIShell of C-DATA ONU4FERW V2.1.13_X139 allows attackers t
powerline-gitstatus (aka Powerline Gitstatus) before 1.3.2 allows arbitrary code execution. git repositories can contain
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13
In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the
totolink EX300_v2 V4.0.3c.140_B20210429 was discovered to contain a command injection vulnerability via the component cl
The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. Due to t
Apache James prior to release 3.6.3 and 3.7.1 is vulnerable to a buffering attack relying on the use of the STARTTLS com
A denial of service vulnerability exists in the web_server hashFirst functionality of Robustel R1510 3.1.16 and 3.3.0. A
A denial of service vulnerability exists in the web_server hashFirst functionality of Robustel R1510 3.1.16 and 3.3.0. A
A denial of service vulnerability exists in the web_server hashFirst functionality of Robustel R1510 3.1.16 and 3.3.0. A
A denial of service vulnerability exists in the web_server hashFirst functionality of Robustel R1510 3.1.16 and 3.3.0. A
A denial of service vulnerability exists in the web_server hashFirst functionality of Robustel R1510 3.1.16 and 3.3.0. A
A denial of service vulnerability exists in the web_server hashFirst functionality of Robustel R1510 3.1.16 and 3.3.0. A
This affects all versions of package google-cloudstorage-commands.
This affects all versions of package curljs.
This affects all versions of package node-latex-pdf.
The package get-npm-package-version before 1.0.7 are vulnerable to Command Injection via main function in index.js.
Dell Hybrid Client below 1.8 version contains a gedit vulnerability. A guest attacker could potentially exploit this vul
A vulnerability has been found in Teledyne FLIR AX8 up to 1.46.16. Affected by this issue is some unknown functionality
Citrix XenMobile Server 10.12 through RP11, 10.13 through RP7, and 10.14 through RP4 allows Command Injection.
Windows DNS Server Remote Code Execution Vulnerability
An OS command injection vulnerability exists in the console factory functionality of InHand Networks InRouter302 V3.5.4.
Totolink A830R V5.9c.4729_B20191112, Totolink A3100R V4.1.2cu.5050_B20200504, Totolink A950RG V4.1.2cu.5161_B20200903, T
A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < 2.15.1), RUGGEDCOM ROX MX5000RE (All version
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run a
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run a
Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run a
AP Manager in Innovaphone before 13r2 Service Release 17 allows command injection via a modified service ID during app u
MyBB is a free and open source forum software. The _Mail Settings_ → Additional Parameters for PHP's mail() function mai
In versions 16.1.x before 16.1.3.1, 15.1.x before 15.1.6.1, 14.1.x before 14.1.5.1, and 13.1.x before 13.1.5.1, When the
Zoho ManageEngine ADManager Plus through 7151 allows authenticated admin users to execute the commands in proxy settings
IBM i Access Family 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.0 could allow a local authenticated attacker to execut
Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to authenticated command injection. This can
SolarWinds Platform was susceptible to Command Injection. This vulnerability allows a remote adversary with complete con
Cradlepoint IBR600 NCOS versions 6.5.0.160bc2e and prior are vulnerable to shell escape, which enables local attackers
Dashboards in Splunk Enterprise versions before 9.0 might let an attacker inject risky search commands into a form token
A vulnerability in the Edge Gateway component of Mitel MiVoice Connect through 19.3 (22.22.6100.0) could allow an authen
sharp is an application for Node.js image processing. Prior to version 0.30.5, there is a possible vulnerability in logi
All versions of package git-archive are vulnerable to Command Injection via the exports function.
A vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Software could allow an a
A vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Software could allow an a
Dell EMC Unity, Dell EMC UnityVSA and Dell EMC Unity XT versions prior to 5.1.2.0.5.007 contain an operating system (OS)
A vulnerability in the CLI of Cisco StarOS could allow an authenticated, local attacker to elevate privileges on an affe
A vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software and Cisco FXOS Software could allow an authe
Apache James prior to release 3.6.1 is vulnerable to a buffering attack relying on the use of the STARTTLS command. This
A vulnerability in the web UI feature of Cisco IOS XE Software could allow an authenticated, remote attacker to perform
A vulnerability was found in Exciting Printer and classified as critical. This issue affects some unknown processing of
Frequently Asked Questions
What is CWE-77?
CWE-77 (Improper Neutralization of Special Elements used in a Command (Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-77?
There are 4,365 CVE records associated with CWE-77 in our database. Of these, 1041 are critical severity, 1473 are high severity, and 1080 are medium severity.
How can I protect against CWE-77 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-77 using AI-powered security agents.
Detect CWE-77 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in a command (command injection) vulnerabilities across your infrastructure.
Get Started