Weaknesses of type CWE-77

2,816 results

Injeção de comando por entrada não neutralizada

O software monta um comando (shell, sistema operacional ou aplicação) usando dados recebidos de fora (entrada do usuário, API, banco de dados) sem remover ou neutralizar caracteres especiais que alteram a semântica do comando. Isso permite que um atacante injete comandos arbitrários que serão executados com as permissões da aplicação.

Example

Um script PHP que executa ping com o IP fornecido pelo usuário: `system('ping ' . $_GET['ip'])`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, porque o ponto-e-vírgula não foi escapado e o shell interpreta dois comandos sequenciais.

How to mitigate

Use APIs seguras que não envolvem interpretação de shell (ex: ProcessBuilder em Java, subprocess.run com shell=False em Python). Se imperativo usar shell, valide com whitelist rigorosa (apenas caracteres alfanuméricos/IPs válidos) e escape com funções específicas da linguagem (escapeshellarg em PHP, shlex.quote em Python).

CVE-2023-26125MEDIUMVersions of the package github.com/gin-gonic/gin before 1.9.0 are vulnerable to Improper Input Validation by allowing an attacker to use a sEPSS 0.9%CVE-2023-28430HIGHOneSignal repository github action command injectionEPSS 0.9%CVE-2026-79682HIGHDell PowerStore contains a Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulEPSS 0.9%CVE-2026-78177LOWTanStack devtools-vite Development Devtools Event Bus package-manager.ts installPackage os command injectionEPSS 0.9%CVE-2024-39568HIGHA vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 HF1). The system service of affected applications iEPSS 0.9%CVE-2024-39567HIGHA vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 HF1). The system service of affected applications iEPSS 0.9%CVE-2023-29475CRITICALinventory in Atos Unify OpenScape 4000 Platform and OpenScape 4000 Manager Platform 10 R1 before 10 R1.34.4 allows an unauthenticated attackEPSS 0.9%CVE-2025-45493MEDIUMNetgear EX8000 V1.0.0.126 is vulnerable to Command Injection via the iface parameter in the action_bandwidth function.EPSS 0.9%CVE-2025-44015LOWHybridDesk StationEPSS 0.9%CVE-2026-78501HIGHMicrosoft 365 Copilot Business Chat Information Disclosure VulnerabilityEPSS 0.9%CVE-2025-65720CRITICALAn issue in Open Source GPT Researcher v3.3.7 allows attackers to execute arbitrary commands on a victim system via user interaction with a EPSS 0.9%CVE-2025-25364HIGHA command injection vulnerability in the me.connectify.SMJobBlessHelper XPC service of Speedify VPN up to v15.0.0 allows attackers to executEPSS 0.9%CVE-2024-20365MEDIUMCisco Integrated Management Controller Redfish Command Injection VulnerabilityEPSS 0.9%CVE-2025-37146HIGHUnauthorized Filesystem Operations in System Firmware allow Authenticated Remote Code ExecutionEPSS 0.9%CVE-2025-37162MEDIUMAuthenticated Command Injection Vulnerability Leading to Arbitrary Remote Command ExecutionEPSS 0.9%CVE-2022-20926MEDIUMA vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Software could allow an authenticated, remoteEPSS 0.9%CVE-2024-32283HIGHTenda FH1203 V2.0.1.6 firmware has a command injection vulnerablility in formexeCommand function via the cmdinput parameter.EPSS 0.9%CVE-2024-36842HIGHAn issue in Oncord+ Android Infotainment Systems OS Android 12, Model Hardware TS17,Hardware part Number F57L_V3.2_20220301, and Build NumbeEPSS 0.9%CVE-2025-55125HIGHThis vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicious backup configuraEPSS 0.9%CVE-2025-26627HIGHAzure Arc Installer Elevation of Privilege VulnerabilityEPSS 0.9%