CWE-77
MITRE ↗Improper Neutralization of Special Elements used in a Command (Command Injection)
Concatenating unsanitized user input in the `whereis` npm module < 0.4.1 allowed an attacker to execute arbitrary comman
A vulnerability in lack of validation of user-supplied parameters pass to XML-RPC calls on SonicWall Global Management S
active-support ruby gem 5.2.0 could allow a remote attacker to execute arbitrary code on the system, caused by containin
Command injection vulnerability in Helpdesk versions 1.1.21 and earlier in QNAP QTS 4.2.6 build 20180531, QTS 4.3.3 buil
A command injection vulnerability in egg-scripts <v2.8.1 allows arbitrary shell command execution through a maliciously
A command Injection in ps package versions <1.0.0 for Node.js allowed arbitrary commands to be executed when attacker co
Command injection vulnerability in Music Station 5.1.2 and earlier versions in QNAP QTS 4.3.3 and 4.3.4 could allow remo
Python Software Foundation Python (CPython) version 2.7 contains a CWE-77: Improper Neutralization of Special Elements u
The karo gem 2.3.8 for Ruby allows Remote command injection via the host field.
It was found that ceph-isci-cli package as shipped by Red Hat Ceph Storage 2 and 3 is using python-werkzeug in debug she
A Command Injection issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x befo
A command injection vulnerability in libnmapp package for versions <0.4.16 allows arbitrary commands to be executed via
Command Injection vulnerability in QTS 4.3.5 build 20181013, QTS 4.3.4 build 20181008, QTS 4.3.3 build 20180829, QTS 4.2
An OS command injection vulnerability in the web administration component of Micro Focus Secure Messaging Gateway (SMG)
IBM Security Identity Manager (ISIM) Virtual Appliance 7.0.0.0 through 7.0.1.0 before 7.0.1-ISS-SIM-FP0001 allows remote
Sourcetree for macOS had several argument and command injection bugs in Mercurial and Git repository handling. An attack
Sourcetree for Windows had several argument and command injection bugs in Mercurial and Git repository handling. An atta
The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an e
A Remote Arbitrary Code Execution vulnerability in HPE Smart Storage Administrator version before v2.60.18.0 was found.
An issue was discovered in certain Apple products. Safari before 11.0.2 is affected. The issue involves the "WebKit Web
The safe_eval function in trytond in Tryton before 2.4.15, 2.6.x before 2.6.14, 2.8.x before 2.8.11, 3.0.x before 3.0.7,
The version control adapters component of TIBCO Data Virtualization (formerly known as Cisco Information Server) contain
The web-based diagnostics console in Dell EMC iDRAC6 (Monolithic versions prior to 2.91 and Modular all versions) contai
Dell EMC iDRAC7/iDRAC8, versions prior to 2.60.60.60, and iDRAC9 versions prior to 3.21.21.21 contain a command injectio
A vulnerability in the web-based UI of Cisco IP Phone 6800, 7800, and 8800 Series with Multiplatform Firmware before 11.
A vulnerability in the VPN subsystem configuration in the Cisco SD-WAN Solution could allow an authenticated, remote att
A vulnerability in the CronJob scheduler API of Cisco Digital Network Architecture (DNA) Center could allow an authentic
An authenticated attacker can execute arbitrary code using command ejection in Eltex ESP-200 firmware version 1.2.0.
An exploitable command execution vulnerability exists in Information Builders WebFOCUS Business Intelligence Portal 8.1
A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could all
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could all
A vulnerability in the web-based management interface of Cisco Cloud Services Platform 2100 could allow an authenticated
A system command injection vulnerability in zyshclient in ZyXEL NSA325 V2 version 4.81 allows attackers to execute syste
The perform_request function in /lib/echor/backplane.rb in echor 0.1.6 Ruby Gem allows local users to inject arbitrary c
The mdcheck script of the mdadm package for openSUSE 13.2 prior to version 3.3.1-5.14.1 does not properly sanitize devic
A vulnerability in the Zero Touch Provisioning (ZTP) subsystem of the Cisco SD-WAN Solution could allow an authenticated
A vulnerability in the command-line tcpdump utility in the Cisco SD-WAN Solution could allow an authenticated, local att
A vulnerability in the command-line interface (CLI) in the Cisco SD-WAN Solution could allow an authenticated, local att
An issue was discovered in Amanda 3.3.1. A user with backup privileges can trivially compromise a client installation. T
Ansible before version 2.2.0 fails to properly sanitize fact variables sent from the Ansible controller. An attacker wit
An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Ca
DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in
FreeSWITCH through 1.8.2, when mod_xml_rpc is enabled, allows remote attackers to execute arbitrary commands via the api
Missing escaping of ESSID values in sysconfig of SUSE Linux Enterprise allows attackers controlling an access point to c
An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Ca
Command injection vulnerability in EZ-Internet in Synology DiskStation Manager (DSM) before 6.2-23739 allows remote auth
Command injection vulnerability in EZ-Internet in Synology Router Manager (SRM) before 1.1.6-6931 allows remote authenti
A vulnerability in the vManage dashboard for the configuration and management service of the Cisco SD-WAN Solution could
A vulnerability in the CLI of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to inject arbitrar
Frequently Asked Questions
What is CWE-77?
CWE-77 (Improper Neutralization of Special Elements used in a Command (Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-77?
There are 4,365 CVE records associated with CWE-77 in our database. Of these, 1041 are critical severity, 1473 are high severity, and 1080 are medium severity.
How can I protect against CWE-77 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-77 using AI-powered security agents.
Detect CWE-77 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in a command (command injection) vulnerabilities across your infrastructure.
Get Started