CWE-77
MITRE ↗Improper Neutralization of Special Elements used in a Command (Command Injection)
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection att
Multiple vulnerabilities in Cisco SD-WAN products could allow an authenticated attacker to perform command injection att
The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a command injec
The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a command injec
An issue was discovered in SaltStack Salt before 3002.5. The minion's restartcheck is vulnerable to command injection vi
BPF JIT compilers in the Linux kernel through 5.11.12 have incorrect computation of branch displacements, allowing them
NFX Series devices using Juniper Networks Junos OS are susceptible to a local code execution vulnerability thereby allow
NFX Series devices using Juniper Networks Junos OS are susceptible to a local command execution vulnerability thereby al
A command injection vulnerability in command processing on Juniper Networks Junos OS Evolved allows an attacker with aut
A command injection vulnerability in tcpdump command processing on Juniper Networks Junos OS Evolved allows an attacker
A command injection vulnerability in sftp command processing on Juniper Networks Junos OS Evolved allows an attacker wit
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects AC2100 before 1.2.0.88,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D6200 before 1.1.00.40,
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects LBR20 before 2.6.3.50,
The uri-block plugin in Apache APISIX before 2.10.2 uses $request_uri without verification. The $request_uri is the full
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects GS108Tv2 before 5.4.2.3
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects GC108P before 1.0.8.2,
This affects the package celery before 5.2.2. It by default trusts the messages and metadata stored in backends (result
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects XR450 before 2.3.2.114,
Barco TransForm N before 3.8 allows Command Injection (issue 2 of 4). The NDN-210 has a web administration panel which i
The NDN-210 has a web administration panel which is made available over https. There is a command injection issue that w
The NDN-210 has a web administration panel which is made available over https. There is a command injection issue that w
A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows
There is command injection when ddns processes the hostname, which causes the administrator user to obtain the root priv
Grandstream GRP261x VoIP phone running firmware version 1.0.3.6 (Base) allows Command Injection as root in its administr
IBM Resilient SOAR V38.0 could allow a privileged user to create create malicious scripts that could be executed as anot
A command injection vulnerability in Avaya Session Border Controller for Enterprise could allow an authenticated, remote
The lack of nested page table protection in the AMD SEV/SEV-ES feature could potentially lead to arbitrary code executio
In the AMD SEV/SEV-ES feature, memory can be rearranged in the guest address space that is not detected by the attestati
If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. Roon Labs has
A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform command inje
A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform command inje
A vulnerability was reported in Lenovo Smart Camera X3, X5, and C2E that could allow command injection by setting a spec
Command Injection in PHPMyWind v5.6 allows remote attackers to execute arbitrary code via the "text color" field of the
A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating
A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating
A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating
A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating
A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating
A remote arbitrary command execution vulnerability was discovered in Aruba SD-WAN Software and Gateways; Aruba Operating
A remote arbitrary command execution vulnerability was discovered in Aruba Operating System Software version(s): Prior t
A remote arbitrary command execution vulnerability was discovered in Aruba Operating System Software version(s): Prior t
A command-injection vulnerability in an authenticated Telnet connection in Poly (formerly Polycom) CX5500 and CX5100 1.3
There is command injection in the meshd program in the routing system, resulting in command execution under administrato
setup.cgi on NETGEAR R6020 1.0.0.48 devices allows an admin to execute arbitrary shell commands via shell metacharacters
A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability
There is a command injection vulnerability in CMA service module of FusionCompute 6.3.0, 6.3.1, 6.5.0 and 8.0.0 when pro
A command injection vulnerability has been reported to affect QNAP device running QVR. If exploited, this vulnerability
A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPas
A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPas
Frequently Asked Questions
What is CWE-77?
CWE-77 (Improper Neutralization of Special Elements used in a Command (Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-77?
There are 4,365 CVE records associated with CWE-77 in our database. Of these, 1041 are critical severity, 1473 are high severity, and 1080 are medium severity.
How can I protect against CWE-77 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-77 using AI-powered security agents.
Detect CWE-77 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in a command (command injection) vulnerabilities across your infrastructure.
Get Started