CWE-77
MITRE ↗Improper Neutralization of Special Elements used in a Command (Command Injection)
The GitHub Actions ToolKit provides a set of packages to make creating actions easier. The `core.exportVariable` functio
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV340 and RV345 Routers could all
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV340 and RV345 Routers could all
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in ping tool of Profel
Mesa Labs AmegaView version 3.0 is vulnerable to a command injection, which may allow an attacker to remotely execute ar
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.
Improper neutralization of special elements used in a command ('Command Injection') vulnerability in task management com
Mesa Labs AmegaView Versions 3.0 and prior has a command injection vulnerability that can be exploited to execute comman
Barco TransForm NDN-210 Lite, NDN-210 Pro, NDN-211 Lite, and NDN-211 Pro before 3.8 allows Command Injection (issue 1 of
The vulnerability have been reported to affect earlier versions of QTS. If exploited, this command injection vulnerabili
Wavlink WN575A4, WN579X3, and WN530G3A devices through 2020-05-15 allow unauthenticated remote users to inject commands
The samba-client package before 4.0.0 for Node.js allows command injection because of the use of process.exec.
An issue was discovered in SaltStack Salt before 3002.5. Sending crafted web requests to the Salt API can result in salt
fs-path node module before 0.0.25 is vulnerable to command injection by way of user-supplied inputs via the `copy`, `cop
The eslint-fixer package through 0.1.5 for Node.js allows command injection via shell metacharacters to the fix function
An exploitable unatuhenticated command injection exists in the OpenClinic GA 5.173.3. Specially crafted web requests can
A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows
In Fibaro Home Center 2 and Lite devices with firmware version 4.540 and older an authenticated user can run commands as
Akuvox C315 115.116.2613 allows remote command Injection via the cfgd_server service. The attack vector is sending a pay
Command injection vulnerability in China Mobile An Lianbao WF-1 1.01 via the 'ip' parameter with a POST request to /api/
Multiple vulnerabilities in the web-based management interface of Cisco HyperFlex HX could allow an unauthenticated, rem
In Pluck-4.7.10-dev2 admin background, a remote command execution vulnerability exists when uploading files.
Command Injection in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation or Code Execution as root via vecto
Command Injection in Nagios Fusion 4.1.8 and earlier allows Privilege Escalation from apache to root in cmd_subsys.php.
Command Injection in Nagios Fusion 4.1.8 and earlier allows for Privilege Escalation to nagios.
In Versa Director, the command injection is an attack in which the goal is execution of arbitrary commands on the host o
The restapps (aka Rest Phone apps) module for Sangoma FreePBX and PBXact 13, 14, and 15 through 15.0.19.2 allows remote
Sharp NEC Displays ((UN462A R1.300 and prior to it, UN462VA R1.300 and prior to it, UN492S R1.300 and prior to it, UN492
Command injection vulnerability in QSAN XEVO, SANOS allows remote unauthenticated attackers to execute arbitrary command
In ProLink PRC2402M V1.0.18 and older, the set_ledonoff function in the adm.cgi binary, accessible with a page parameter
Btrbk before 0.31.2 allows command execution because of the mishandling of remote hosts filtering SSH commands using ssh
An issue was discovered in the lettre crate before 0.9.6 for Rust. In an e-mail message body, an attacker can place a .
An issue in Dut Computer Control Engineering Co.'s PLC MAC1100 allows attackers to execute arbitrary code.
A command-injection vulnerability in the Image Upload function of the NASCENT RemKon Device Manager 4.0.0.0 allows attac
An issue was discovered in D-Link DIR-816 DIR-816A2_FWv1.10CNB05_R1B011D88210 The HTTP request parameter is used in the
An issue was discovered in D-Link DIR816_A1_FW101CNB04 750m11ac wireless router, The HTTP request parameter is used in t
Command Injection in Simiki v1.6.2.1 and prior allows remote attackers to execute arbitrary system commands via line 64
bash command injection vulnerability in Apache Zeppelin allows an attacker to inject system commands into Spark interpre
An issue in craigms/main.php of CraigMS 1.0 allows attackers to execute arbitrary commands via a crafted input entered i
There is command injection in the addMeshNode interface of xqnetwork.lua, which leads to command execution under adminis
Zoho ManageEngine Desktop Central before build 10.0.683 allows unauthenticated command injection due to improper handlin
Edgecore ECS2020 Firmware 1.0.0.0 devices allow Unauthenticated Command Injection via the command1 HTTP header to the /E
A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability
A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability
Remote Code Execution vulnerability in Micro Focus ArcSight Enterprise Security Manager (ESM) product, affecting version
An issue was discovered in Zammad before 4.1.1. Command Injection can occur via custom Packages.
The shell-quote package before 1.7.3 for Node.js allows command injection. An attacker can inject unescaped shell metach
All versions of yongyou PLM are affected by a command injection issue. UFIDA PLM (Product Life Cycle Management) is a st
In the wazuh-slack active response script in Wazuh 4.2.x before 4.2.5, untrusted user agents are passed to a curl comman
Zoho ManageEngine Network Configuration Manager before 125488 is vulnerable to command injection due to improper validat
Frequently Asked Questions
What is CWE-77?
CWE-77 (Improper Neutralization of Special Elements used in a Command (Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-77?
There are 4,365 CVE records associated with CWE-77 in our database. Of these, 1041 are critical severity, 1473 are high severity, and 1080 are medium severity.
How can I protect against CWE-77 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-77 using AI-powered security agents.
Detect CWE-77 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in a command (command injection) vulnerabilities across your infrastructure.
Get Started