Weaknesses of type CWE-77

2,826 results

Injeção de comando por entrada não neutralizada

O software monta um comando (shell, sistema operacional ou aplicação) usando dados recebidos de fora (entrada do usuário, API, banco de dados) sem remover ou neutralizar caracteres especiais que alteram a semântica do comando. Isso permite que um atacante injete comandos arbitrários que serão executados com as permissões da aplicação.

Example

Um script PHP que executa ping com o IP fornecido pelo usuário: `system('ping ' . $_GET['ip'])`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, porque o ponto-e-vírgula não foi escapado e o shell interpreta dois comandos sequenciais.

How to mitigate

Use APIs seguras que não envolvem interpretação de shell (ex: ProcessBuilder em Java, subprocess.run com shell=False em Python). Se imperativo usar shell, valide com whitelist rigorosa (apenas caracteres alfanuméricos/IPs válidos) e escape com funções específicas da linguagem (escapeshellarg em PHP, shlex.quote em Python).

CVE-2024-56837HIGHA vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versions < V2.17.0), RUGGEEPSS 0.5%CVE-2026-22623HIGHDue to insufficient input parameter validation on the interface, authenticated users of certain HIKSEMI NAS products can execute arbitrary cEPSS 0.5%CVE-2024-52011HIGHlaunch-editor vulnerable to command injection via the crafted request on WindowsEPSS 0.5%CVE-2024-32884MEDIUMgix-transport indirect code execution via malicious usernameEPSS 0.5%CVE-2025-59818CRITICALAuthenticated Remote Code Execution via the file name of an uploaded fileEPSS 0.5%CVE-2019-1623MEDIUMCisco Meeting Server CLI Command Injection VulnerabilityEPSS 0.5%CVE-2026-41611HIGHVisual Studio Code Remote Code Execution VulnerabilityEPSS 0.5%CVE-2019-1791MEDIUMCisco NX-OS Software Command Injection VulnerabilityEPSS 0.5%CVE-2025-20334HIGHA vulnerability in the HTTP API subsystem of Cisco IOS XE Software could allow a remote attacker to inject commands that will execute with rEPSS 0.5%CVE-2026-75007MEDIUMIn Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the LDAP search filter was subject to injection via unescaped %u/%fu/%d substitutEPSS 0.5%CVE-2019-17148HIGHThis vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop Parallels Desktop version 14EPSS 0.5%CVE-2024-22545HIGHAn issue was discovered in TRENDnet TEW-824DRU version 1.04b01, allows unauthenticated attackers to execute arbitrary code via the system.ntEPSS 0.5%CVE-2025-50461MEDIUMA deserialization vulnerability exists in Volcengine's verl 3.0.0, specifically in the scripts/model_merger.py script when using the "fsdp" EPSS 0.5%CVE-2018-0481—Cisco IOS XE Software Command Injection VulnerabilitiesEPSS 0.5%CVE-2018-0477—Cisco IOS XE Software Command Injection VulnerabilitiesEPSS 0.5%CVE-2026-45585MEDIUMWindows BitLocker Security Feature Bypass VulnerabilityEPSS 0.5%CVE-2024-23971HIGHChargePoint Home Flex OCPP bswitch Command InjectionEPSS 0.5%CVE-2024-4578HIGHPrivilege escalation in Arista Wireless Access PointsEPSS 0.5%CVE-2025-29154MEDIUMHTML injection vulnerability in lemeconsultoria HCM galera.app v.4.58.0 allows an attacker to execute arbitrary code via the .galera.app/tedEPSS 0.5%CVE-2026-4786HIGHIncomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open()EPSS 0.5%