Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Improper Neutralization of Special Elements used in a Command (Command Injection)

1,041
CRITICAL
1,473
HIGH
1,080
MEDIUM
26
LOW
3,664 CVEs · Page 72/74
6.7
CVE-2018-0217

A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers c

6.7
CVE-2018-0224

A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers c

6.7
CVE-2018-0324

A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, high-pr

6.7
CVE-2018-0477

A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to execute comma

6.7
CVE-2018-0481

A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to execute comma

6.4
CVE-2016-7076

sudo before version 1.8.18p1 is vulnerable to a bypass in the sudo noexec restriction if application run via sudo execut

5.5
CVE-2018-8306

A command injection vulnerability exists in the Microsoft Wireless Display Adapter (MWDA) when the Microsoft Wireless Di

5.3
CVE-2017-1720

IBM Notes 8.5 and 9.0 could allow a local attacker to execute arbitrary commands by carefully crafting a command line se

10.0
CVE-2017-7722

In SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4, a menu system is encountered when the SSH service is acce

10.0
CVE-2017-7876

This command injection vulnerability in QTS allows attackers to run arbitrary commands in the compromised application. Q

9.9
CVE-2017-2349

A command injection vulnerability in the IDP feature of Juniper Networks Junos OS on SRX series devices potentially allo

9.8
CVE-2016-10107

Unauthenticated Remote Command injection as root occurs in the Western Digital MyCloud NAS 2.11.142 index.php page via a

9.8
CVE-2016-10108

Unauthenticated Remote Command injection as root occurs in the Western Digital MyCloud NAS 2.11.142 /web/google_analytic

9.8
CVE-2016-7399

scripts/license.pl in Veritas NetBackup Appliance 2.6.0.x through 2.6.0.4, 2.6.1.x through 2.6.1.2, 2.7.x through 2.7.3,

9.8
CVE-2016-10182

An issue was discovered on the D-Link DWR-932B router. qmiweb allows command injection with ` characters.

9.8
CVE-2016-10098

An issue was discovered on SendQuick Entera and Avera devices before 2HF16. Multiple Command Injection vulnerabilities a

9.8
CVE-2015-6024

ping.cgi in NetCommWireless HSPA 3G10WVE wireless routers with firmware before 3G10WVE-L101-S306ETS-C01_R05 allows remot

9.8
CVE-2016-9682

The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to two Remote Command Injection vulnerabi

9.8
CVE-2016-9683

The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerabili

9.8
CVE-2016-9684

The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerabili

9.8
CVE-2016-10194

The festivaltts4r gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a strin

9.8
CVE-2008-7313

The _httpsrequest function in Snoopy allows remote attackers to execute arbitrary commands. NOTE: this issue exists due

9.8
CVE-2014-5008

Snoopy allows remote attackers to execute arbitrary commands.

9.8
CVE-2014-5009

Snoopy allows remote attackers to execute arbitrary commands. NOTE: this vulnerability exists due to an incomplete fix

9.8
CVE-2016-10312

Jensen of Scandinavia AS Air:Link 3G (AL3G) version 2.23m (Rev. 3), Air:Link 5000AC (AL5000AC) version 1.13, and Air:Lin

9.8
CVE-2016-5065

Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 allow Embedded_Ace_Set_Task.cgi command injection.

9.8
CVE-2017-7689

A Command Injection vulnerability in Schneider Electric homeLYnk Controller exists in all versions before 1.5.0.

9.8
CVE-2016-1555 KEV

(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear

9.8
CVE-2016-10329

Command injection vulnerability in login.php in Synology Photo Station before 6.5.3-3226 allows remote attackers to exec

9.8
CVE-2015-9059

picocom before 2.0 has a command injection vulnerability in the 'send and receive file' command because the command line

9.8
CVE-2017-4918

VMware Horizon View Client (2.x, 3.x and 4.x prior to 4.5.0) contains a command injection vulnerability in the service s

9.8
CVE-2016-6655

An issue was discovered in Cloud Foundry Foundation Cloud Foundry release versions prior to v245 and cf-mysql-release ve

9.8
CVE-2017-4984

In EMC VNX2 versions prior to OE for File 8.1.9.211 and VNX1 versions prior to OE for File 7.1.80.8, an unauthenticated

9.8
CVE-2017-7977

The Screensavercc component in eLux RP before 5.5.0 allows attackers to bypass intended configuration restrictions and e

9.8
CVE-2017-9980

In Green Packet DX-350 Firmware version v2.8.9.5-g1.4.8-atheeb, the "PING" (aka tag_ipPing) feature within the web inter

9.8
CVE-2015-2857

Accellion File Transfer Appliance before FTA_9_11_210 allows remote attackers to execute arbitrary code via shell metach

9.8
CVE-2015-7841

The login page of the server on Huawei FusionServer rack servers RH2288 V3 with software before V100R003C00SPC603, RH228

9.8
CVE-2017-13069

QNAP discovered a number of command injection vulnerabilities found in Music Station versions 4.8.6 (for QTS 4.2.x), 5.0

9.8
CVE-2008-7315

UI-Dialog 1.09 and earlier allows remote attackers to execute arbitrary commands.

9.8
CVE-2013-6924

Seagate BlackArmor NAS devices with firmware sg2000-2000.1331 allow remote attackers to execute arbitrary commands via s

9.8
CVE-2015-7806

Eval injection vulnerability in the fm_saveHelperGatherItems function in ajax.php in the Form Manager plugin before 1.7.

9.8
CVE-2014-3741

The printDirect function in lib/printer.js in the node-printer module 0.0.1 and earlier for Node.js allows remote attack

9.8
CVE-2014-1203

The get_login_ip_config_file function in Eyou Mail System before 3.6 allows remote attackers to execute arbitrary comman

9.8
CVE-2008-7319

The Net::Ping::External extension through 0.15 for Perl does not properly sanitize arguments (e.g., invalid hostnames) c

9.8
CVE-2017-13071

QNAP has already patched this vulnerability. This security concern allows a remote attacker to run arbitrary commands on

9.8
CVE-2017-15940

The web interface packet capture management component in Palo Alto Networks PAN-OS before 6.1.19, 7.0.x before 7.0.19, 7

8.8
CVE-2015-3441

The Parental Control panel in Genexis devices with DRGOS before 1.14.1 allows remote authenticated users to execute arbi

8.8
CVE-2016-6270

The handle_certificate function in /vmi/manager/engine/management/commands/apns_worker.py in Trend Micro Virtual Mobile

8.8
CVE-2017-5675

A command-injection vulnerability exists in a web application on a custom-built GoAhead web server used on Foscam, Vstar

8.8
CVE-2015-8988

Unquoted executable path vulnerability in Client Management and Gateway components in McAfee (now Intel Security) ePO De

Frequently Asked Questions

What is CWE-77?

CWE-77 (Improper Neutralization of Special Elements used in a Command (Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.

How many CVEs are classified as CWE-77?

There are 4,365 CVE records associated with CWE-77 in our database. Of these, 1041 are critical severity, 1473 are high severity, and 1080 are medium severity.

How can I protect against CWE-77 vulnerabilities?

Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-77 using AI-powered security agents.

Detect CWE-77 Vulnerabilities

CyberStrike's AI agents automatically detect improper neutralization of special elements used in a command (command injection) vulnerabilities across your infrastructure.

Get Started