Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in a Command (Command Injection)

1,041
CRITICAL
1,473
HIGH
1,080
MEDIUM
26
LOW
3,664 CVEs · Page 62/74
8.4
CVE-2021-45576

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,

8.4
CVE-2021-45577

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,

8.4
CVE-2021-45578

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,

8.4
CVE-2021-45579

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,

8.4
CVE-2021-45580

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,

8.4
CVE-2021-45581

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,

8.4
CVE-2021-45582

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,

8.4
CVE-2021-45583

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,

8.4
CVE-2021-45584

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,

8.4
CVE-2021-45585

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,

8.4
CVE-2021-45586

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,

8.4
CVE-2021-45587

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,

8.4
CVE-2021-45588

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,

8.4
CVE-2021-45589

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,

8.4
CVE-2021-45590

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,

8.4
CVE-2021-45591

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,

8.4
CVE-2021-45592

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBK752 before 3.2.16.6,

8.4
CVE-2021-45593

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBR20 before 2.7.3.22,

8.4
CVE-2021-45594

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBS50Y before 2.7.3.22,

8.4
CVE-2021-45596

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects CBR750 before 4.6.3.6,

8.4
CVE-2021-45597

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects CBR40 before 2.5.0.24,

8.4
CVE-2021-45598

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects CBR40 before 2.5.0.24,

8.4
CVE-2021-45599

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects CBR40 before 2.5.0.24,

8.4
CVE-2021-45600

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects CBR750 before 4.6.3.6,

8.4
CVE-2021-45601

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects CBR40 before 2.5.0.24,

8.3
CVE-2021-38529

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D7800 before 1.0.

8.3
CVE-2021-45623

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects R7800 before 1.0.

8.2
CVE-2021-41116

Composer is an open source dependency manager for the PHP language. In affected versions windows users running Composer

8.1
CVE-2021-29501

Ticketer is a command based ticket system cog (plugin) for the red discord bot. A vulnerability allowing discord users t

8.1
CVE-2020-36448

An issue was discovered in the cache crate through 2020-11-24 for Rust. There are unconditional implementations of Send

8.1
CVE-2020-36449

An issue was discovered in the kekbit crate before 0.3.4 for Rust. For ShmWriter<H>, Send is implemented without requiri

8.1
CVE-2020-36450

An issue was discovered in the bunch crate through 2020-11-12 for Rust. There are unconditional implementations of Send

8.1
CVE-2020-36451

An issue was discovered in the rcu_cell crate through 2020-11-14 for Rust. There are unconditional implementations of Se

8.1
CVE-2020-36455

An issue was discovered in the slock crate through 2020-11-17 for Rust. Slock<T> unconditionally implements Send and Syn

8.1
CVE-2020-36456

An issue was discovered in the toolshed crate through 2020-11-15 for Rust. In CopyCell<T>, the Send trait lacks bounds o

8.1
CVE-2020-36457

An issue was discovered in the lever crate before 0.1.1 for Rust. AtomicBox<T> implements the Send and Sync traits for a

8.1
CVE-2020-36459

An issue was discovered in the dces crate through 2020-12-09 for Rust. The World type is marked as Send but lacks bounds

8.1
CVE-2020-36461

An issue was discovered in the noise_search crate through 2020-12-10 for Rust. There are unconditional implementations o

8.1
CVE-2020-36462

An issue was discovered in the syncpool crate before 0.1.6 for Rust. There is an unconditional implementation of Send fo

8.1
CVE-2020-36463

An issue was discovered in the multiqueue crate through 2020-12-25 for Rust. There are unconditional implementations of

8.1
CVE-2021-38527

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects CBR40 before 2.5.

8.1
CVE-2020-29548

An issue was discovered in SmarterTools SmarterMail through 100.0.7537. Meddler-in-the-middle attackers can pipeline com

8.1
CVE-2021-35220

Command Injection vulnerability in EmailWebPage API which can lead to a Remote Code Execution (RCE) from the Alerts Sett

8.0
CVE-2020-7848

The EFM ipTIME C200 IP Camera is affected by a Command Injection vulnerability in /login.cgi?logout=1 script. To exploit

8.0
CVE-2021-42538

The affected product is vulnerable to a parameter injection via passphrase, which enables the attacker to supply uncontr

8.0
CVE-2021-20167

Netgear RAX43 version 1.0.3.96 contains a command injection vulnerability. The readycloud cgi application is vulnerable

7.8
CVE-2018-19418

Foxit PDF ActiveX before 5.5.1 allows remote code execution via command injection because of the lack of a security perm

7.8
CVE-2020-4688

IBM Security Guardium 10.6 and 11.2 could allow a local attacker to execute arbitrary commands on the system as an unpri

7.8
CVE-2021-1260

Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection att

7.8
CVE-2021-1261

Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection att

Frequently Asked Questions

What is CWE-77?

CWE-77 (Improper Neutralization of Special Elements used in a Command (Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-77?

There are 4,365 CVE records associated with CWE-77 in our database. Of these, 1041 are critical severity, 1473 are high severity, and 1080 are medium severity.

How can I protect against CWE-77 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-77 using AI-powered security agents.

Detect CWE-77 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in a command (command injection) vulnerabilities across your infrastructure.

Get Started