Weaknesses of type CWE-77

2,816 results

Injeção de comando por entrada não neutralizada

O software monta um comando (shell, sistema operacional ou aplicação) usando dados recebidos de fora (entrada do usuário, API, banco de dados) sem remover ou neutralizar caracteres especiais que alteram a semântica do comando. Isso permite que um atacante injete comandos arbitrários que serão executados com as permissões da aplicação.

Example

Um script PHP que executa ping com o IP fornecido pelo usuário: `system('ping ' . $_GET['ip'])`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, porque o ponto-e-vírgula não foi escapado e o shell interpreta dois comandos sequenciais.

How to mitigate

Use APIs seguras que não envolvem interpretação de shell (ex: ProcessBuilder em Java, subprocess.run com shell=False em Python). Se imperativo usar shell, valide com whitelist rigorosa (apenas caracteres alfanuméricos/IPs válidos) e escape com funções específicas da linguagem (escapeshellarg em PHP, shlex.quote em Python).

CVE-2024-26298HIGHVulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands onEPSS 0.9%CVE-2024-26296HIGHVulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands onEPSS 0.9%CVE-2024-4078CRITICALArbitrary Code Execution in parisneo/lollmsEPSS 0.9%CVE-2024-26297HIGHVulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands onEPSS 0.9%CVE-2026-11487MEDIUMNeovim View Branch secure.lua M.read command injectionEPSS 0.9%CVE-2026-42827MEDIUMM365 Copilot Information Disclosure VulnerabilityEPSS 0.9%CVE-2026-42824MEDIUMM365 Copilot Information Disclosure VulnerabilityEPSS 0.9%CVE-2026-26136MEDIUMMicrosoft Copilot Information Disclosure VulnerabilityEPSS 0.9%CVE-2026-47285MEDIUMVisual Studio Code Information Disclosure VulnerabilityEPSS 0.9%CVE-2026-24712HIGHNorthern.tech CFEngine Enterprise and Community before 3.21.8, 3.24.3, and 3.27.0 allows Command injection.EPSS 0.9%CVE-2026-7246HIGH[DISPUTED] Pallets Click contains a command injection via Unsanitized Filename "click.edit()"EPSS 0.9%CVE-2025-55319HIGHAgentic AI and Visual Studio Code Remote Code Execution VulnerabilityEPSS 0.9%CVE-2024-39577HIGHDell SmartFabric OS10 Software, versions 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contains an Improper Neutralization of Special Elements useEPSS 0.9%CVE-2023-23149CRITICALDEK-1705 <=Firmware:34.23.1 device was discovered to have a command execution vulnerability.EPSS 0.9%CVE-2022-36786CRITICALDLINK - DSL-224 Post-auth RCE.EPSS 0.9%CVE-2024-41136MEDIUMAuthenticated Command Injection in HPE Aruba Networking EdgeConnect SD-WAN Command Line InterfaceEPSS 0.9%CVE-2025-48492HIGHGetSimple CMS RCE in Edit componentEPSS 0.9%CVE-2026-20761HIGHEnOcean SmartServer IoT Command InjectionEPSS 0.9%CVE-2025-30264HIGHQTS, QuTS heroEPSS 0.9%CVE-2025-41451HIGHPost-Authentication OS Command Injection RCE in Danfoss AK-SM8xxA SeriesEPSS 0.9%