Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in a Command (Command Injection)

1,041
CRITICAL
1,473
HIGH
1,080
MEDIUM
26
LOW
3,664 CVEs · Page 60/74
9.8
CVE-2021-35978

An issue was discovered in Digi TransPort DR64, SR44 VC74, and WR. The ZING protocol allows arbitrary remote command exe

9.8
CVE-2021-43113

iTextPDF in iText 7 and up to (excluding 4.4.13.3) 7.1.17 allows command injection via a CompareTool filename that is mi

9.8
CVE-2021-45459

lib/cmd.js in the node-windows package before 1.0.0-beta.6 for Node.js allows command injection via the PID parameter.

9.8
CVE-2021-45617

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.

9.6
CVE-2021-29071

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK852 before 3.2.17.12

9.6
CVE-2021-29076

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK852 before 3.2

9.6
CVE-2021-29077

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBW30 before 2.6.

9.6
CVE-2021-29078

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK852 before 3.2

9.6
CVE-2021-29079

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK852 before 3.2

9.6
CVE-2021-38528

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D8500 before 1.0.

9.6
CVE-2021-38530

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK40 before 2.5.

9.6
CVE-2021-45513

NETGEAR XR1000 devices before 1.0.0.58 are affected by command injection by an unauthenticated attacker.

9.6
CVE-2021-45514

NETGEAR XR1000 devices before 1.0.0.58 are affected by command injection by an unauthenticated attacker.

9.6
CVE-2021-45612

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.

9.6
CVE-2021-45613

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.

9.6
CVE-2021-45614

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D7000v2 before 1.

9.6
CVE-2021-45615

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.

9.6
CVE-2021-45616

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR750 before 3.2

9.6
CVE-2021-45618

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D7800 before 1.0.

9.6
CVE-2021-45619

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects EX6200v2 before 1

9.6
CVE-2021-45620

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.

9.6
CVE-2021-45621

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.

9.6
CVE-2021-45622

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.

9.6
CVE-2021-45624

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D7000v2 before 1.

9.6
CVE-2021-45625

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects XR300 before 1.0.

9.6
CVE-2021-45626

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK20 before 2.6.

9.6
CVE-2021-45627

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR750 before 4.6

9.6
CVE-2021-45628

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.

9.6
CVE-2021-45629

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR750 before 4.6

9.6
CVE-2021-45631

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.

9.6
CVE-2021-45632

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR750 before 4.6

9.6
CVE-2021-45633

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR750 before 4.6

9.6
CVE-2021-45634

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR750 before 4.6

9.6
CVE-2021-45635

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR750 before 4.6

9.1
CVE-2021-36024

Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an Imprope

9.0
CVE-2020-15180

A flaw was found in the mysql-wsrep component of mariadb. Lack of input sanitization in `wsrep_sst_method` allows for co

8.8
CVE-2021-1298

Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection att

8.8
CVE-2021-1299

Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection att

8.8
CVE-2020-27862

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DVA-2

8.8
CVE-2020-27864

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1

8.8
CVE-2020-10519

A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a

8.8
CVE-2021-22864

A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a

8.8
CVE-2020-10580

A command injection on the /admin/broadcast.php script of Invigo Automatic Device Management (ADM) through 5.0 allows re

8.8
CVE-2020-13664

Arbitrary PHP code execution vulnerability in Drupal Core under certain circumstances. An attacker could trick an admini

8.8
CVE-2021-22899 KEV

A command injection vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker

8.8
CVE-2015-1877

The open_generic_xdg_mime function in xdg-open in xdg-utils 1.1.0 rc1 in Debian, when using dash, does not properly hand

8.8
CVE-2021-28812

A command injection vulnerability has been reported to affect certain versions of Video Station. If exploited, this vuln

8.8
CVE-2020-21785

In IBOS 4.5.4 Open, the database backup has Command Injection Vulnerability.

8.8
CVE-2020-17759

An issue was found in the Evernote client for Windows 10, 7, and 2008 in the protocol handler. This enables attackers fo

8.8
CVE-2021-38169

Roxy-WI through 5.2.2.0 allows command injection via /app/funct.py and /api/api_funct.py.

Frequently Asked Questions

What is CWE-77?

CWE-77 (Improper Neutralization of Special Elements used in a Command (Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-77?

There are 4,365 CVE records associated with CWE-77 in our database. Of these, 1041 are critical severity, 1473 are high severity, and 1080 are medium severity.

How can I protect against CWE-77 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-77 using AI-powered security agents.

Detect CWE-77 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in a command (command injection) vulnerabilities across your infrastructure.

Get Started