Weaknesses of type CWE-77

2,819 results

Injeção de comando por entrada não neutralizada

O software monta um comando (shell, sistema operacional ou aplicação) usando dados recebidos de fora (entrada do usuário, API, banco de dados) sem remover ou neutralizar caracteres especiais que alteram a semântica do comando. Isso permite que um atacante injete comandos arbitrários que serão executados com as permissões da aplicação.

Example

Um script PHP que executa ping com o IP fornecido pelo usuário: `system('ping ' . $_GET['ip'])`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, porque o ponto-e-vírgula não foi escapado e o shell interpreta dois comandos sequenciais.

How to mitigate

Use APIs seguras que não envolvem interpretação de shell (ex: ProcessBuilder em Java, subprocess.run com shell=False em Python). Se imperativo usar shell, valide com whitelist rigorosa (apenas caracteres alfanuméricos/IPs válidos) e escape com funções específicas da linguagem (escapeshellarg em PHP, shlex.quote em Python).

CVE-2024-2366CRITICALRemote Code Execution in parisneo/lollms-webuiEPSS 0.7%CVE-2026-35847CRITICALAn issue in dnsmgr v.2.15 and before allows a local attacker to execute arbitrary code via the ping function of the CheckUils.php fileEPSS 0.7%CVE-2025-37138MEDIUMAuthenticated Command Injection Vulnerability in CLI Binary of AOS-10 GW and AOS-8 Controller/Mobility Conductor Web-Based Management Interface (Physical Access Required)EPSS 0.7%CVE-2018-0324—A vulnerability in the CLI of Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an authenticated, high-privileged, local attaEPSS 0.7%CVE-2025-65946HIGHRoo Code is Vulnerable to Potential Remote Code Execution via zsh Command Validation BugEPSS 0.7%CVE-2024-7840HIGHImproper neutralization special element in hyperlinksEPSS 0.7%CVE-2026-12045CRITICALpgAdmin 4: AI Assistant read-only transaction bypass allows unauthorised writes and remote code executionEPSS 0.7%CVE-2025-29223MEDIUMLinksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability via the pt parameter in the traceRoute function.EPSS 0.7%CVE-2025-29226MEDIUMIn Linksys E5600 V1.1.0.26, the \usr\share\lua\runtime.lua file contains a command injection vulnerability in the runtime.pingTest function EPSS 0.7%CVE-2020-14342MEDIUMIt was found that cifs-utils' mount.cifs was invoking a shell when requesting the Samba password, which could be used to inject arbitrary coEPSS 0.7%CVE-2026-72869CRITICALDokploy: Authenticated OS command injection in backup.restoreBackupWithLogs (databaseName) leading to host RCEEPSS 0.7%CVE-2025-12107HIGHServer-Side Template Injection via Velocity Template Engine in Multiple WSO2 Products Allows Remote Code ExecutionEPSS 0.6%CVE-2026-24299MEDIUMM365 Copilot Information Disclosure VulnerabilityEPSS 0.6%CVE-2025-43714MEDIUMThe ChatGPT system through 2025-03-30 performs inline rendering of SVG documents (instead of, for example, rendering them as text inside a cEPSS 0.6%CVE-2026-73712HIGHUnauthenticated Remote Code Execution in HPE Networking Fabric Composer APIEPSS 0.6%CVE-2025-64419CRITICALCoolify vulnerable to command injection via docker-compose.yaml parametersEPSS 0.6%CVE-2024-48015MEDIUMDell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization of Special ElementsEPSS 0.6%CVE-2014-9114HIGHBlkid in util-linux before 2.26rc-1 allows local users to execute arbitrary code.EPSS 0.6%CVE-2025-41250HIGHHeader injection vulnerabilityEPSS 0.6%CVE-2022-45095MEDIUM Dell PowerScale OneFS, 8.2.x-9.4.x, contain a command injection vulnerability. An authenticated user having access local shell and having tEPSS 0.6%