Weaknesses of type CWE-77

2,819 results

Injeção de comando por entrada não neutralizada

O software monta um comando (shell, sistema operacional ou aplicação) usando dados recebidos de fora (entrada do usuário, API, banco de dados) sem remover ou neutralizar caracteres especiais que alteram a semântica do comando. Isso permite que um atacante injete comandos arbitrários que serão executados com as permissões da aplicação.

Example

Um script PHP que executa ping com o IP fornecido pelo usuário: `system('ping ' . $_GET['ip'])`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, porque o ponto-e-vírgula não foi escapado e o shell interpreta dois comandos sequenciais.

How to mitigate

Use APIs seguras que não envolvem interpretação de shell (ex: ProcessBuilder em Java, subprocess.run com shell=False em Python). Se imperativo usar shell, valide com whitelist rigorosa (apenas caracteres alfanuméricos/IPs válidos) e escape com funções específicas da linguagem (escapeshellarg em PHP, shlex.quote em Python).

CVE-2018-19013—An attacker could inject commands to delete files and/or delete the contents of a file on CX-Supervisor (Versions 3.42 and prior) through a EPSS 0.8%CVE-2020-29547MEDIUMAn issue was discovered in Citadel through webcit-926. Meddler-in-the-middle attackers can pipeline commands after POP3 STLS, IMAP STARTTLS,EPSS 0.8%CVE-2023-26430LOWAttackers with access to user accounts can inject arbitrary control characters to SIEVE mail-filter rules. This could be abused to access SIEPSS 0.8%CVE-2024-28136HIGHPHOENIX CONTACT: command injection gains root privileges using the OCPP remote serviceEPSS 0.8%CVE-2025-62222HIGHAgentic AI and Visual Studio Code Remote Code Execution VulnerabilityEPSS 0.7%CVE-2026-24132HIGHOrval Mock Generation Code Injection via constEPSS 0.7%CVE-2024-7679HIGHImproper neutralization special element in hyperlinksEPSS 0.7%CVE-2025-63406HIGHAn issue in Intermesh BV GroupOffice vulnerable before v.25.0.47 and 6.8.136 allows a remote attacker to execute arbitrary code via the dbToEPSS 0.7%CVE-2022-26415HIGHOn F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior EPSS 0.7%CVE-2026-23653MEDIUMGitHub Copilot and Visual Studio Code Information Disclosure VulnerabilityEPSS 0.7%CVE-2023-21805HIGHWindows MSHTML Platform Remote Code Execution VulnerabilityEPSS 0.7%CVE-2023-49565HIGHRemote Code ExecutionEPSS 0.7%CVE-2024-48830HIGHDell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization of Special ElementsEPSS 0.7%CVE-2026-30461HIGHDaylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the /controllers/InsEPSS 0.7%CVE-2024-27818HIGHThe issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS EPSS 0.7%CVE-2026-93967MEDIUMaiyiyi121 SxDevOps Command services.py generate_host_task command injectionEPSS 0.7%CVE-2024-39703HIGHIn ThreatQuotient ThreatQ before 5.29.3, authenticated users are able to execute arbitrary commands by sending a crafted request to an API eEPSS 0.7%CVE-2025-56425CRITICALAn issue was discovered in the AppConnector component version 10.10.0.183 and earlier of enaio 10.10, in the AppConnector component version EPSS 0.7%CVE-2021-32692CRITICALActivity Watch vulnerable to command execution on macOS via printAppTitle.scptEPSS 0.7%CVE-2022-4009HIGHIn affected versions of Octopus Deploy it is possible for a user to introduce code via offline package creationEPSS 0.7%