Weaknesses of type CWE-77

2,820 results

Injeção de comando por entrada não neutralizada

O software monta um comando (shell, sistema operacional ou aplicação) usando dados recebidos de fora (entrada do usuário, API, banco de dados) sem remover ou neutralizar caracteres especiais que alteram a semântica do comando. Isso permite que um atacante injete comandos arbitrários que serão executados com as permissões da aplicação.

Example

Um script PHP que executa ping com o IP fornecido pelo usuário: `system('ping ' . $_GET['ip'])`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, porque o ponto-e-vírgula não foi escapado e o shell interpreta dois comandos sequenciais.

How to mitigate

Use APIs seguras que não envolvem interpretação de shell (ex: ProcessBuilder em Java, subprocess.run com shell=False em Python). Se imperativo usar shell, valide com whitelist rigorosa (apenas caracteres alfanuméricos/IPs válidos) e escape com funções específicas da linguagem (escapeshellarg em PHP, shlex.quote em Python).

CVE-2024-34347HIGH@hoppscotch/cli affected by Sandbox Escape in @hoppscotch/js-sandbox leads to RCEEPSS 0.6%CVE-2024-51304HIGHIn Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the ldEPSS 0.6%CVE-2024-51296HIGHIn Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the piEPSS 0.6%CVE-2024-51301HIGHIn Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the paEPSS 0.6%CVE-2024-51300HIGHIn Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the geEPSS 0.6%CVE-2026-30616HIGHJaaz 1.0.30 contains a remote code execution vulnerability in its MCP STDIO command execution handling. A remote attacker can send crafted nEPSS 0.6%CVE-2024-51299HIGHIn Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the duEPSS 0.6%CVE-2018-5412—Imperva SecureSphere running v12.0.0.50 is vulnerable to local arbitrary code execution, escaping sealed-mode.EPSS 0.6%CVE-2020-3207MEDIUMCisco IOS XE Software Command Injection VulnerabilityEPSS 0.6%CVE-2025-53774MEDIUMMicrosoft 365 Copilot BizChat Information Disclosure VulnerabilityEPSS 0.6%CVE-2025-54416CRITICALtj-actions/branch-names Contains Command Injection VulnerabilityEPSS 0.6%CVE-2026-45497HIGHMicrosoft M365 Copilot Remote Code Execution VulnerabilityEPSS 0.6%CVE-2024-28729HIGHAn issue in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME allows a local attacker to execute arbitrary codEPSS 0.6%CVE-2026-86427HIGHLibreNMS before 26.8.0 Argument Injection via graph_titleEPSS 0.6%CVE-2026-82370HIGHUnauthenticated remote command injection in the Brocade SANnav orchestrator HTTP serviceEPSS 0.6%CVE-2025-26331HIGHDell ThinOS 2411 and prior, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. AEPSS 0.6%CVE-2026-43830CRITICALtbcEPSS 0.6%CVE-2024-35401MEDIUMTOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a command injection vulnerability via the FileName parameter in the UploadFEPSS 0.6%CVE-2025-4010HIGHArbitrary Command Injection in Netcom NTC-6200 & NWL-222EPSS 0.6%CVE-2026-83948HIGHMicrosoft Azure CLI Remote Code Execution VulnerabilityEPSS 0.6%