CWE-77
MITRE ↗Improper Neutralization of Special Elements used in a Command (Command Injection)
Command injection in Raynet rvia RayVentory Scan Engine 12.6 Update 8 and previous versions allows adversaries to execut
Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote co
A code injection vulnerability in the wxExecute() function of OpenCPN v5.12.0 allows attackers to execute arbitrary code
Improper neutralization of special elements used in a command ('command injection') in Windows Narrator Braille allows a
Improper neutralization of special elements used in a command ('command injection') in Windows Clipboard User Service al
Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.234, Tabby inserts dropped file paths
Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an unauth
Improper neutralization of special elements used in a command ('command injection') in Microsoft Office allows an author
Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an au
FunJSQ, a third-party module integrated on some NETGEAR routers and Orbi WiFi Systems, exposes an HTTP server over the L
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an autho
Exposure of Sensitive Information to an Unauthorized Actor in Copilot Studio allows a unauthenticated attacker to view s
IBM Sterling B2B Integrator and and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.
Flannel is a network fabric for containers, designed for Kubernetes. The Flannel project includes an experimental Extens
Prompt injection vulnerability in 1millionbot Millie chatbot that occurs when a user manages to evade chat restrictions
Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) all
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti
MeltanoHub is the source code for hub.meltano.com, the central place for Meltano plugins. Versions of the repo prior to
A flaw has been found in Wavlink WL-NU516U1 708c073-mt7628. The impacted element is an unknown function of the component
Command Injection in BOSH CLI tool on windows in Cloud Foundry allows a remote attacker to execute arbitrary shell comma
An issue in OpenSourcePOS v3.4.1 allows attackers to execute arbitrary code via returning a crafted AJAX response.
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthoriz
A security vulnerability has been detected in Edimax EW-7478APC 1.04. This impacts the function formWlbasic of the file
A flaw has been found in Edimax EW-7478APC 1.04. Affected by this vulnerability is the function setWAN of the file /gofo
A vulnerability has been found in Edimax EW-7478APC 1.04. Affected by this issue is the function stainfo of the file /go
A weakness has been identified in GL.iNet A1300, AX1800, AXT1800, BE1400, BE3600, BE6500, BE9300, BE10000, E5800, MT2500
A security vulnerability has been detected in GL.iNet BE9300 and MT6000 4.8.x. This vulnerability affects unknown code o
A vulnerability was detected in TRENDnet TEW-823DRU 1.1.02b01. Impacted is an unknown function of the file /cgi-bin/admi
A flaw has been found in TRENDnet Router 1.1.02b01. The affected element is an unknown function of the file /cgi-bin/pin
A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected is the function popen/system of the file /cgi-
A vulnerability was identified in TRENDnet TV-IP751WIC 11.03.03. Affected by this vulnerability is an unknown functional
A security flaw has been discovered in TRENDnet TEW-755AP up to 20260702. This affects the function log_email_server of
A flaw has been found in Comfast CF-N1-S 2.6.0.1. This impacts the function sprintf of the file /cgi-bin/mbox-config?met
A vulnerability has been found in Tenda CH22 1.0.0.1. The affected element is the function formcreateFileName of the fil
A vulnerability was found in TRENDnet TEW-821DAP 2.2.01b05. Affected is an unknown function of the file /cgi-bin/upload.
A security flaw has been discovered in Tenda CH22 1.0.0.1. The impacted element is the function formeditFileName of the
A vulnerability has been found in Tenda CH22 1.0.0.1. This affects the function formexeCommand of the file /goform/exeCo
A vulnerability was found in D-Link DIR-825M 1.1.8. Affected by this vulnerability is the function sub_456CF4 of the fil
A vulnerability was identified in TOTOLINK NR1800X 9.1.0u.6681_B20230703. This affects the function setUssd of the file
A vulnerability was identified in Sangfor Operation and Maintenance Management System up to 3.0.8. The affected element
A weakness has been identified in D-Link DIR-823X 250416. Affected by this issue is the function sub_412E7C of the file
A vulnerability was determined in Tosei Online Store Management System ネット店舗管理システム 1.01. The affected element is an unkn
A vulnerability has been found in Sangfor Operation and Maintenance Security Management System up to 3.0.12. The impacte
A weakness has been identified in Tenda HG10 US_HG7_HG9_HG10re_300001138_en_xpon. Impacted is an unknown function of the
A vulnerability was detected in Tenda HG10 US_HG7_HG9_HG10re_300001138_en_xpon. The impacted element is the function che
A security flaw has been discovered in Ziroom ZHOME A0101 1.0.1.0. This issue affects the function macAddrClone of the f
A vulnerability was detected in Great Developers Certificate Generation System up to 97171bb0e5e22e52eacf4e4fa81773e5f3c
A flaw has been found in Tosei Self-service Washing Machine 4.02. Impacted is an unknown function of the file /cgi-bin/t
A security flaw has been discovered in yued-fe LuLu UI up to 3.0.0. This issue affects the function child_process.exec o
A weakness has been identified in jishi node-sonos-http-api up to 3776f0ee2261c924c7b7204de121a38100a08ca7. Affected is
Frequently Asked Questions
What is CWE-77?
CWE-77 (Improper Neutralization of Special Elements used in a Command (Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-77?
There are 4,365 CVE records associated with CWE-77 in our database. Of these, 1041 are critical severity, 1473 are high severity, and 1080 are medium severity.
How can I protect against CWE-77 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-77 using AI-powered security agents.
Detect CWE-77 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in a command (command injection) vulnerabilities across your infrastructure.
Get Started