Threats Tagged 'cwe-77'
View all threats tagged with 'cwe-77'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-77'
Click on any threat for detailed analysis and mitigation recommendations
0 NVIDIA NeMo Speech for all platforms contains a vulnerability where malicious input created by an attacker could cause a code injection. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering. Join the discussion | CVE Database V5 | 09/22/2026, 14:03:59 UTC Added: 09/22/2026, 14:33:34 UTC |
0 A vulnerability was determined in spatie Scotty up to 1.4.4. This impacts the function DoctorCommand::checkSshConnectivity/DoctorCommand::checkRemoteTools of the file app/Commands/DoctorCommand.php of the component Doctor Command Handler. This manipulation of the argument host causes os command injection. It is possible to initiate the attack remotely. The pull request to fix this issue awaits acceptance. Join the discussion | CVE Database V5 | 09/18/2026, 16:15:10 UTC Added: 09/18/2026, 16:32:08 UTC |
Improper neutralization of special elements used in a command ('command injection') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to disclose information over a network. Join the discussion | CVE Database V5 | 09/17/2026, 22:55:56 UTC Added: 09/17/2026, 23:03:02 UTC |
Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized attacker to elevate privileges over a network. Join the discussion | CVE Database V5 | 09/17/2026, 22:55:55 UTC Added: 09/17/2026, 23:03:02 UTC |
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose information over a network. Join the discussion | CVE Database V5 | 09/17/2026, 22:55:52 UTC Added: 09/17/2026, 23:03:02 UTC |
Browsertrix is a high-fidelity, browser-based crawling service for web archiving that can be self-hosted or used through Webrecorder's hosted instance. From 1.15.0 until 1.22.8, Browsertrix improperly sanitizes Git URLs specified as Custom Behaviors, allowing command injection through /api/orgs/*/crawlconfigs/validate/custom-behavior. A user with crawler or administrator permission on the specific instance can supply a crafted Git URL that executes arbitrary operating-system commands in the backend pod. Open registration or hosted free-trial access can make the required role broadly obtainable. Successful exploitation can expose, modify, or delete application database records, archived items, browser profiles, storage data, proxy credentials, and other configured service data. This issue is fixed in version 1.22.8. Join the discussion | CVE Database V5 | 09/17/2026, 20:15:14 UTC Added: 09/17/2026, 20:47:37 UTC |
0 On affected platforms running Arista EOS with gRPC Network Security Interface (gNSI) Credentialz configured, a specially crafted request can cause unintended modifications to the target account's properties. This may result in the account being assigned elevated privileges or access beyond what an administrator intended. Join the discussion | CVE Database V5 | 09/16/2026, 08:14:40 UTC Added: 09/16/2026, 08:32:02 UTC |
0 A command injection vulnerability exists in the command line interface of EdgeConnect SD-WAN Gateways. Successful exploitation could allow an authenticated remote attacker with high privileges to execute arbitrary commands on the underlying operating system leading to complete system compromise. Join the discussion | GCVE Database | 09/15/2026, 19:23:36 UTC Added: 09/16/2026, 03:07:19 UTC |
PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, src/praisonai-agents/praisonaiagents/tools/email_tools.py interpolates LLM-controlled from_addr, subject, and query values directly into quoted IMAP SEARCH criteria. Embedded quote, backslash, newline, or null characters can escape the intended criterion and alter IMAP operations when search_emails, reply_email, or archive_email is exposed to an agent with configured email credentials, allowing mailbox data access, modification, deletion, or connection disruption. This issue is fixed in praisonaiagents 1.6.59. Join the discussion | CVE Database V5 | 09/14/2026, 14:28:09 UTC Added: 09/14/2026, 14:47:06 UTC |
0 A security vulnerability has been detected in webgjc web_robot 2.4.0/2.5.0/2.8.0. The affected element is the function controller_listen/controller_recover of the file py/web.py. The manipulation of the argument case_name leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | GCVE Database | 09/13/2026, 01:30:17 UTC Added: 09/14/2026, 00:36:59 UTC |
Showing 1 to 10 of 371 results