Weaknesses of type CWE-77

2,819 results

Injeção de comando por entrada não neutralizada

O software monta um comando (shell, sistema operacional ou aplicação) usando dados recebidos de fora (entrada do usuário, API, banco de dados) sem remover ou neutralizar caracteres especiais que alteram a semântica do comando. Isso permite que um atacante injete comandos arbitrários que serão executados com as permissões da aplicação.

Example

Um script PHP que executa ping com o IP fornecido pelo usuário: `system('ping ' . $_GET['ip'])`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, porque o ponto-e-vírgula não foi escapado e o shell interpreta dois comandos sequenciais.

How to mitigate

Use APIs seguras que não envolvem interpretação de shell (ex: ProcessBuilder em Java, subprocess.run com shell=False em Python). Se imperativo usar shell, valide com whitelist rigorosa (apenas caracteres alfanuméricos/IPs válidos) e escape com funções específicas da linguagem (escapeshellarg em PHP, shlex.quote em Python).

CVE-2024-21903MEDIUMQTS, QuTS heroEPSS 0.8%CVE-2025-33180HIGHNVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could inject a command. A EPSS 0.8%CVE-2026-22708HIGHCursor has a Terminal Tool Allowlist Bypass via Environment VariablesEPSS 0.8%CVE-2024-46084HIGHScriptcase 9.10.023 and before is vulnerable to Remote Code Execution (RCE) via the nm_unzip function.EPSS 0.8%CVE-2023-26429LOWControl characters were not removed when exporting user feedback content. This allowed attackers to include unexpected content via user feedEPSS 0.8%CVE-2025-25604MEDIUMTotolink X5000R V9.1.0u.6369_B20230113 is vulnerable to command injection via the vif_disable function in mtkwifi.lua.EPSS 0.8%CVE-2025-25605MEDIUMTotolink X5000R V9.1.0u.6369_B20230113 is vulnerable to command injection via the apcli_wps_gen_pincode function in mtkwifi.lua.EPSS 0.8%CVE-2026-22785CRITICALorval MCP client is vulnerable to a code injection attack.EPSS 0.8%CVE-2026-45558CRITICALRoxy-WI: Authenticated RCE on every managed HAProxy load balancer via `option` field config injection in section saveEPSS 0.8%CVE-2024-43693CRITICALDover Fueling Solutions ProGauge MAGLINK LX CONSOLE Command InjectionEPSS 0.8%CVE-2024-45066CRITICALDover Fueling Solutions ProGauge MAGLINK LX CONSOLE Command InjectionEPSS 0.8%CVE-2026-54680CRITICALLogging operator has Fluentd configuration injection that allows remote code executionEPSS 0.8%CVE-2025-64093CRITICALUnauthenticated Remote Code Execution via the device hostnameEPSS 0.8%CVE-2024-7700MEDIUMForeman: command injection in "host init config" template via "install packages" field on foremanEPSS 0.8%CVE-2025-0593HIGHSICK Lector8xx and InspectorP8xx vulnerable for code executionEPSS 0.8%CVE-2026-20176CRITICALCisco Identity Services Engine Remote Code Execution VulnerabilityEPSS 0.8%CVE-2024-36073HIGHNetwrix CoSoSys Endpoint Protector through 5.9.3 and CoSoSys Unify through 7.0.6 contain a remote code execution vulnerability in the shadowEPSS 0.8%CVE-2023-28677CRITICALJenkins Convert To Pipeline Plugin 1.0 and earlier uses basic string concatenation to convert Freestyle projects' Build Environment, Build SEPSS 0.8%CVE-2025-50722CRITICALInsecure Permissions vulnerability in sparkshop v.1.1.7 allows a remote attacker to execute arbitrary code via the Common.php componentEPSS 0.8%CVE-2025-29230HIGHLinksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.emailReg function. The vulnerability can EPSS 0.8%