Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in a Command (Command Injection)

1,041
CRITICAL
1,473
HIGH
1,080
MEDIUM
26
LOW
3,664 CVEs · Page 61/74
8.8
CVE-2021-37708

Shopware is an open source eCommerce platform. Versions prior to 6.4.3.1 contain a command injection vulnerability in ma

8.8
CVE-2021-38556

includes/configure_client.php in RaspAP 2.6.6 allows attackers to execute commands via command injection.

8.8
CVE-2020-19151

Command Injection in Jfinal CMS v4.7.1 and earlier allows remote attackers to execute arbitrary code by uploading a mali

8.8
CVE-2021-34748

A vulnerability in the web-based management interface of Cisco Intersight Virtual Appliance could allow an authenticated

8.8
CVE-2021-41146

qutebrowser is an open source keyboard-focused browser with a minimal GUI. Starting with qutebrowser v1.7.0, the Windows

8.8
CVE-2021-43339

In Ericsson Network Location before 2021-07-31, it is possible for an authenticated attacker to inject commands via file

8.8
CVE-2021-37102

There is a command injection vulnerability in CMA service module of FusionCompute product when processing the default ce

8.8
CVE-2021-43469

VINGA WR-N300U 77.102.1.4853 is affected by a command execution vulnerability in the goahead component.

8.8
CVE-2021-42129

A command injection vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail

8.8
CVE-2021-42132

A command Injection vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail

8.8
CVE-2021-3621

A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cach

8.7
CVE-2021-34362

A command injection vulnerability has been reported to affect QNAP device running Media Streaming add-on. If exploited,

8.7
CVE-2021-45553

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7000 before 1.0.11.126

8.4
CVE-2021-29070

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK852 before 3.2.17.12

8.4
CVE-2021-29072

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK852 before 3.2.17.12

8.4
CVE-2021-38518

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RAX200 before 1.0.4.120

8.4
CVE-2021-45533

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects EX6120 before 1.0.0.66,

8.4
CVE-2021-45535

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RAX200 before 1.0.3.106

8.4
CVE-2021-45536

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RAX75 before 1.0.3.106,

8.4
CVE-2021-45537

Certain NETGEAR devices are affected by command injection by an authenticated user . This affects RAX200 before 1.0.3.10

8.4
CVE-2021-45538

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RAX75 before 1.0.3.106,

8.4
CVE-2021-45539

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7900P before 1.4.2.84,

8.4
CVE-2021-45540

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7000 before 1.0.11.126

8.4
CVE-2021-45541

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7900 before 1.0.4.38,

8.4
CVE-2021-45542

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RAX200 before 1.0.4.120

8.4
CVE-2021-45543

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R8000 before 1.0.4.74,

8.4
CVE-2021-45544

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7850 before 1.0.5.74,

8.4
CVE-2021-45545

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7850 before 1.0.5.74,

8.4
CVE-2021-45546

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7850 before 1.0.5.74,

8.4
CVE-2021-45547

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7850 before 1.0.5.74,

8.4
CVE-2021-45549

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects LAX20 before 1.1.6.28,

8.4
CVE-2021-45554

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6400 before 1.0.1.74,

8.4
CVE-2021-45555

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7900P before 1.4.2.84,

8.4
CVE-2021-45558

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,

8.4
CVE-2021-45559

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,

8.4
CVE-2021-45560

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,

8.4
CVE-2021-45561

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,

8.4
CVE-2021-45562

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,

8.4
CVE-2021-45563

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,

8.4
CVE-2021-45564

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,

8.4
CVE-2021-45565

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,

8.4
CVE-2021-45566

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,

8.4
CVE-2021-45567

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,

8.4
CVE-2021-45568

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,

8.4
CVE-2021-45569

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,

8.4
CVE-2021-45570

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,

8.4
CVE-2021-45571

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,

8.4
CVE-2021-45572

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,

8.4
CVE-2021-45574

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,

8.4
CVE-2021-45575

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,

Frequently Asked Questions

What is CWE-77?

CWE-77 (Improper Neutralization of Special Elements used in a Command (Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-77?

There are 4,365 CVE records associated with CWE-77 in our database. Of these, 1041 are critical severity, 1473 are high severity, and 1080 are medium severity.

How can I protect against CWE-77 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-77 using AI-powered security agents.

Detect CWE-77 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in a command (command injection) vulnerabilities across your infrastructure.

Get Started