Weaknesses of type CWE-77

2,816 results

Injeção de comando por entrada não neutralizada

O software monta um comando (shell, sistema operacional ou aplicação) usando dados recebidos de fora (entrada do usuário, API, banco de dados) sem remover ou neutralizar caracteres especiais que alteram a semântica do comando. Isso permite que um atacante injete comandos arbitrários que serão executados com as permissões da aplicação.

Example

Um script PHP que executa ping com o IP fornecido pelo usuário: `system('ping ' . $_GET['ip'])`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, porque o ponto-e-vírgula não foi escapado e o shell interpreta dois comandos sequenciais.

How to mitigate

Use APIs seguras que não envolvem interpretação de shell (ex: ProcessBuilder em Java, subprocess.run com shell=False em Python). Se imperativo usar shell, valide com whitelist rigorosa (apenas caracteres alfanuméricos/IPs válidos) e escape com funções específicas da linguagem (escapeshellarg em PHP, shlex.quote em Python).

CVE-2024-51114HIGHAn issue in Beijing Digital China Yunke Information Technology Co.Ltd v.7.2.6.120 allows a remote attacker to execute arbitrary code via theEPSS 0.9%CVE-2019-1609MEDIUMCisco NX-OS Software CLI Command Injection Vulnerability (CVE-2019-1609)EPSS 0.9%CVE-2024-42636HIGHDedeCMS V5.7.115 has a command execution vulnerability via file_manage_view.php?fmdo=newfile&activepath.EPSS 0.9%CVE-2024-51186HIGHD-Link DIR-820L 1.05b03 was discovered to contain a remote code execution (RCE) vulnerability via the ping_addr parameter in the ping_v4 andEPSS 0.9%CVE-2025-63603MEDIUMA command injection vulnerability exists in the MCP Data Science Server's (reading-plus-ai/mcp-server-data-exploration) 0.1.6 in the safe_evEPSS 0.9%CVE-2024-52308HIGHConnecting to a malicious Codespaces via GH CLI could allow command execution on the user's computerEPSS 0.9%CVE-2023-6071HIGH An Improper Neutralization of Special Elements used in a command vulnerability in ESM prior to version 11.6.9 allows a remote administratorEPSS 0.9%CVE-2025-6784HIGHCode Engine <= 0.3.5 - Authenticated (Contributor+) Remote Code ExecutionEPSS 0.9%CVE-2019-17101MEDIUMCommand execution due to unsanitized input in Netatmo Smart Indoor Security CameraEPSS 0.9%CVE-2023-28110MEDIUMJumpServer Koko vulnerable to Command Injection for Kubernetes Connection EPSS 0.8%CVE-2020-15685HIGHDuring the plaintext phase of the STARTTLS connection setup, protocol commands could have been injected and evaluated within the encrypted sEPSS 0.8%CVE-2024-10035CRITICALCode Injection in BG-TEK's CoslatV3EPSS 0.8%CVE-2025-46625HIGHLack of input validation/sanitization in the 'setLanCfg' API endpoint in httpd in the Tenda RX2 Pro 16.03.30.14 allows a remote attacker thaEPSS 0.8%CVE-2026-23947CRITICALOrval MCP client is vulnerable to code injection via unsanitized x-enum-descriptions in enum generationEPSS 0.8%CVE-2023-40598HIGHCommand Injection in Splunk Enterprise Using External LookupsEPSS 0.8%CVE-2025-29887HIGHQuRouter 2.5EPSS 0.8%CVE-2017-12305—A vulnerability in the debug interface of Cisco IP Phone 8800 series could allow an authenticated, local attacker to execute arbitrary commaEPSS 0.8%CVE-2023-29474CRITICALinventory in Atos Unify OpenScape 4000 Platform and OpenScape 4000 Manager Platform 10 R1 before 10 R1.34.4 allows an unauthenticated attackEPSS 0.8%CVE-2023-29473CRITICALwebservice in Atos Unify OpenScape 4000 Platform and OpenScape 4000 Manager Platform 10 R1 before 10 R1.34.4 allows an unauthenticated attacEPSS 0.8%CVE-2026-63694MEDIUMDell SmartFabric OS10 Software, versions prior to 10.5.6.14, contains an Improper Neutralization of Special Elements used in a Command ('ComEPSS 0.8%