Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in a Command (Command Injection)

1,041
CRITICAL
1,473
HIGH
1,080
MEDIUM
26
LOW
3,664 CVEs · Page 64/74
7.2
CVE-2021-40986

A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPas

7.2
CVE-2021-40987

A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPas

7.2
CVE-2021-40998

A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPas

7.2
CVE-2021-40345

An issue was discovered in Nagios XI 5.8.5. In the Manage Dashlets section of the Admin panel, an administrator can uplo

7.1
CVE-2021-45531

NETGEAR D6220 devices before 1.0.0.76 are affected by command injection by an authenticated user.

6.9
CVE-2020-8101

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in HTTP interface of A

6.8
CVE-2020-27867

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R602

6.8
CVE-2021-32660

Backstage is an open platform for building developer portals, and techdocs-common contains common functionalities for Ba

6.8
CVE-2021-32661

Backstage is an open platform for building developer portals. In versions of Backstage's Techdocs Plugin (`@backstage/pl

6.7
CVE-2021-0356

In netdiag, there is a possible command injection due to improper input validation. This could lead to local escalation

6.7
CVE-2021-0358

In netdiag, there is a possible command injection due to improper input validation. This could lead to local escalation

6.7
CVE-2021-0363

In mobile_log_d, there is a possible command injection due to a missing bounds check. This could lead to local escalatio

6.7
CVE-2021-0364

In mobile_log_d, there is a possible command injection due to improper input validation. This could lead to local escala

6.7
CVE-2021-1488

A vulnerability in the upgrade process of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat De

6.7
CVE-2020-36198

A command injection vulnerability has been reported to affect certain versions of Malware Remover. If exploited, this vu

6.7
CVE-2021-3515

A shell injection flaw was found in pglogical in versions before 2.3.4 and before 3.6.26. An attacker with CREATEDB priv

6.7
CVE-2021-34725

A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to inject arbitr

6.7
CVE-2021-34726

A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to inject arbitrary com

6.7
CVE-2021-34729

A vulnerability in the CLI of Cisco IOS XE SD-WAN Software and Cisco IOS XE Software could allow an authenticated, local

6.7
CVE-2021-45532

NETGEAR R8000 devices before 1.0.4.76 are affected by command injection by an authenticated user.

6.6
CVE-2021-38520

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6400 before 1.0.1.52,

6.6
CVE-2021-45550

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76,

6.5
CVE-2021-1384

A vulnerability in Cisco IOx application hosting environment of Cisco IOS XE Software could allow an authenticated, remo

6.5
CVE-2021-1560

Multiple vulnerabilities in Cisco DNA Spaces Connector could allow an authenticated, remote attacker to perform a comman

6.5
CVE-2021-22867

A path traversal vulnerability was identified in GitHub Enterprise Server that could be exploited when building a GitHub

6.5
CVE-2021-1580

Multiple vulnerabilities in the web UI and API endpoints of Cisco Application Policy Infrastructure Controller (APIC) or

6.3
CVE-2021-38519

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6250 before 1.0.4.36,

6.3
CVE-2021-40994

A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPas

6.3
CVE-2021-40995

A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): ClearPas

6.3
CVE-2021-45548

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.60,

6.3
CVE-2021-45552

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7800 before 1.0.1.58,

6.1
CVE-2021-38521

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6400 before 1.0.1.50,

6.0
CVE-2021-1382

A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to inject arbitr

6.0
CVE-2021-21595

Dell EMC PowerScale OneFS versions 8.2.x - 9.1.1.x contain an improper neutralization of special elements used in an OS

5.9
CVE-2021-38370

In Alpine before 2.25, untagged responses from an IMAP server are accepted before STARTTLS.

5.9
CVE-2020-15955

In s/qmail through 4.0.07, an active MitM can inject arbitrary plaintext commands into a STARTTLS encrypted session betw

5.9
CVE-2020-26300

systeminformation is an npm package that provides system and OS information library for node.js. In systeminformation be

5.8
CVE-2021-21406

Combodo iTop is an open source, web based IT Service Management tool. In versions prior to 2.7.4, there is a command inj

5.5
CVE-2021-1443

A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to execute arbitrar

5.5
CVE-2021-26321

Insufficient ID command validation in the SEV Firmware may allow a local authenticated attacker to perform a denial of s

5.3
CVE-2021-38373

In KDE KMail 19.12.3 (aka 5.13.3), the SMTP STARTTLS option is not honored (and cleartext messages are sent) unless "Ser

4.8
CVE-2021-33515

The submission service in Dovecot before 2.3.15 allows STARTTLS command injection in lib-smtp. Sensitive information can

4.7
CVE-2021-1547

Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series

4.7
CVE-2021-1548

Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series

4.7
CVE-2021-1549

Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series

4.7
CVE-2021-1550

Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series

4.7
CVE-2021-1551

Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series

4.7
CVE-2021-1552

Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series

4.7
CVE-2021-1553

Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series

4.7
CVE-2021-1554

Multiple vulnerabilities in the web-based management interface of certain Cisco Small Business 100, 300, and 500 Series

Frequently Asked Questions

What is CWE-77?

CWE-77 (Improper Neutralization of Special Elements used in a Command (Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-77?

There are 4,365 CVE records associated with CWE-77 in our database. Of these, 1041 are critical severity, 1473 are high severity, and 1080 are medium severity.

How can I protect against CWE-77 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-77 using AI-powered security agents.

Detect CWE-77 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in a command (command injection) vulnerabilities across your infrastructure.

Get Started