CWE · MITRE source
CWE-77Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
Many protocols and products have their own custom command language. While OS or shell command strings are frequently discovered and targeted, developers may not realize that these other command languages might also be vulnerable to attacks.
Last updated: 09 May 2026 03:25 UTC
NIST 800-53 r5 controls that address this weakness (0)AI
| Control | Title | Family | Why it addresses this CWE |
|---|---|---|---|
| No NIST controls proposed yet. | |||
Top CVEs of this weakness type, ranked by Risk Priority
| CVE | Risk | CVSS | EPSS | Published |
|---|---|---|---|---|
CVE-2024-3400 KEV | 9.7 | 10.0 | 0.9432 | 2024-04-12 |
CVE-2007-3010 KEV | 9.6 | 9.8 | 0.9402 | 2007-09-18 |
CVE-2012-1823 KEV | 9.6 | 9.8 | 0.9436 | 2012-05-11 |
CVE-2016-1555 KEV | 9.6 | 9.8 | 0.9433 | 2017-04-21 |
CVE-2021-1498 KEV | 9.6 | 9.8 | 0.9421 | 2021-05-06 |
CVE-2023-1671 KEV | 9.6 | 9.8 | 0.9430 | 2023-04-04 |
CVE-2023-20887 KEV | 9.6 | 9.8 | 0.9426 | 2023-06-07 |
CVE-2024-12356 KEV | 9.6 | 9.8 | 0.9386 | 2024-12-17 |
CVE-2016-20017 KEV | 9.5 | 9.8 | 0.9209 | 2022-10-19 |
CVE-2024-21887 KEV | 9.5 | 9.1 | 0.9441 | 2024-01-12 |
CVE-2023-1389 KEV | 9.4 | 8.8 | 0.9347 | 2023-03-15 |
CVE-2024-55956 KEV | 9.4 | 9.8 | 0.9122 | 2024-12-13 |
CVE-2005-2773 KEV | 9.3 | 9.8 | 0.8982 | 2005-09-02 |
CVE-2015-2051 KEV | 9.3 | 8.8 | 0.9302 | 2015-02-23 |
CVE-2023-2868 KEV | 9.3 | 9.4 | 0.9080 | 2023-05-24 |
CVE-2023-33538 KEV | 9.2 | 8.8 | 0.9057 | 2023-06-07 |
CVE-2024-3273 KEV | 9.1 | 7.3 | 0.9443 | 2024-04-04 |
CVE-2020-2509 KEV | 9.0 | 9.8 | 0.8396 | 2021-04-17 |
CVE-2019-0541 KEV | 8.8 | 8.8 | 0.8339 | 2019-01-08 |
CVE-2024-9380 KEV | 8.7 | 7.2 | 0.8814 | 2024-10-08 |
CVE-2017-6327 KEV | 8.4 | 8.8 | 0.7679 | 2017-08-11 |
CVE-2024-12987 KEV | 8.2 | 7.3 | 0.7899 | 2024-12-27 |
CVE-2016-10045 | 7.6 | 9.8 | 0.9337 | 2016-12-30 |
CVE-2019-5420 | 7.6 | 9.8 | 0.9375 | 2019-03-27 |
CVE-2020-13117 | 7.6 | 9.8 | 0.9387 | 2021-02-09 |