Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in a Command (Command Injection)

1,041
CRITICAL
1,473
HIGH
1,080
MEDIUM
26
LOW
3,664 CVEs · Page 66/74
8.8
CVE-2020-3219

A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to inject and execu

8.8
CVE-2020-3224

A vulnerability in the web-based user interface (web UI) of Cisco IOS XE Software could allow an authenticated, remote a

8.8
CVE-2020-14435

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects SRK60 before 2.5.

8.8
CVE-2020-14436

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK752 before 3.2

8.8
CVE-2020-14437

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK752 before 3.2

8.8
CVE-2020-14438

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK752 before 3.2

8.8
CVE-2020-14439

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK752 before 3.2

8.8
CVE-2020-14440

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK752 before 3.2

8.8
CVE-2020-14441

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK752 before 3.2

8.8
CVE-2020-14442

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK752 before 3.2

8.8
CVE-2020-5601

Chrome Extension for e-Tax Reception System Ver1.0.0.0 allows remote attackers to execute an arbitrary command via unspe

8.8
CVE-2020-8188

We have recently released new version of UniFi Protect firmware v1.13.3 and v1.14.10 for Unifi Cloud Key Gen2 Plus and U

8.8
CVE-2020-9242

FusionCompute 8.0.0 have a command injection vulnerability. The software does not sufficiently validate certain paramete

8.8
CVE-2020-8233

A command injection vulnerability exists in EdgeSwitch firmware <v1.9.0 that allowed an authenticated read-only user to

8.8
CVE-2020-15642

This vulnerability allows remote attackers to execute arbitrary code on affected installations of installations of Marve

8.8
CVE-2020-10518

A remote code execution vulnerability was identified in GitHub Enterprise Server that could be exploited when building a

8.8
CVE-2020-25079 KEV

An issue was discovered on D-Link DCS-2530L before 1.06.01 Hotfix and DCS-2670L through 2.02 devices. cgi-bin/ddns_enc.c

8.8
CVE-2020-26909

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects D7800 before 1.0.

8.8
CVE-2020-26920

Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects SRK60 before 2.5.

8.8
CVE-2020-25847

This command injection vulnerability allows attackers to execute arbitrary commands in a compromised application. QNAP h

8.6
CVE-2020-11079

node-dns-sync (npm module dns-sync) through 0.2.0 allows execution of arbitrary commands . This issue may lead to remote

8.4
CVE-2020-26910

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects CBR40 before 2.5.0.10,

8.4
CVE-2020-35777

NETGEAR DGN2200v1 devices before v1.0.0.58 are affected by command injection.

8.4
CVE-2020-35794

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects RBS40V before 2.6.1.4,

8.3
CVE-2019-9507

The web interface of the Vertiv Avocent UMG-4000 version 4.2.1.19 is vulnerable to command injection because the applica

8.3
CVE-2020-35792

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7500v2 before 1.0.3.48

8.1
CVE-2019-16012

A vulnerability in the web UI of Cisco SD-WAN Solution vManage software could allow an authenticated, remote attacker to

8.0
CVE-2019-20680

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7000v2 before 1.0.0.53

8.0
CVE-2019-20701

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76,

8.0
CVE-2019-20702

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76,

8.0
CVE-2019-20703

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76,

8.0
CVE-2019-20704

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76,

8.0
CVE-2019-20705

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76,

8.0
CVE-2019-20706

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7800 before 1.0.2.60 a

8.0
CVE-2019-20707

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7800 before 1.0.2.60 a

8.0
CVE-2019-20708

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76,

8.0
CVE-2019-20709

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76,

8.0
CVE-2019-20710

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76,

8.0
CVE-2019-20711

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76,

8.0
CVE-2019-20761

NETGEAR R7800 devices before 1.0.2.62 are affected by command injection by an authenticated user.

7.9
CVE-2020-11073

In Autoswitch Python Virtualenv before version 0.16.0, a user who enters a directory with a malicious `.venv` file could

7.8
CVE-2019-17148

This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop Parallel

7.8
CVE-2020-1980

A shell command injection vulnerability in the PAN-OS CLI allows a local authenticated user to escape the restricted she

7.8
CVE-2020-3266

A vulnerability in the CLI of Cisco SD-WAN Solution software could allow an authenticated, local attacker to inject arbi

7.8
CVE-2019-20655

Certain NETGEAR devices are affected by command injection by an authenticated user. This affects XR500 before 2.3.2.56 a

7.8
CVE-2019-16011

A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to inject arbitr

7.8
CVE-2020-9688

Adobe Download Manager version 2.0.0.518 have a command injection vulnerability. Successful exploitation could lead to a

7.8
CVE-2020-0130

In screencap, there is a possible command injection due to improper input validation. This could lead to local escalatio

7.8
CVE-2020-9862

A command injection issue existed in Web Inspector. This issue was addressed with improved escaping. This issue is fixed

7.8
CVE-2019-14719

Verifone MX900 series Pinpad Payment Terminals with OS 30251000 allow multiple arbitrary command injections, as demonstr

Frequently Asked Questions

What is CWE-77?

CWE-77 (Improper Neutralization of Special Elements used in a Command (Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-77?

There are 4,365 CVE records associated with CWE-77 in our database. Of these, 1041 are critical severity, 1473 are high severity, and 1080 are medium severity.

How can I protect against CWE-77 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-77 using AI-powered security agents.

Detect CWE-77 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in a command (command injection) vulnerabilities across your infrastructure.

Get Started