Weaknesses of type CWE-77

2,828 results

Injeção de comando por entrada não neutralizada

O software monta um comando (shell, sistema operacional ou aplicação) usando dados recebidos de fora (entrada do usuário, API, banco de dados) sem remover ou neutralizar caracteres especiais que alteram a semântica do comando. Isso permite que um atacante injete comandos arbitrários que serão executados com as permissões da aplicação.

Example

Um script PHP que executa ping com o IP fornecido pelo usuário: `system('ping ' . $_GET['ip'])`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, porque o ponto-e-vírgula não foi escapado e o shell interpreta dois comandos sequenciais.

How to mitigate

Use APIs seguras que não envolvem interpretação de shell (ex: ProcessBuilder em Java, subprocess.run com shell=False em Python). Se imperativo usar shell, valide com whitelist rigorosa (apenas caracteres alfanuméricos/IPs válidos) e escape com funções específicas da linguagem (escapeshellarg em PHP, shlex.quote em Python).

CVE-2018-0481—Cisco IOS XE Software Command Injection VulnerabilitiesEPSS 0.5%CVE-2026-45585MEDIUMWindows BitLocker Security Feature Bypass VulnerabilityEPSS 0.5%CVE-2024-23971HIGHChargePoint Home Flex OCPP bswitch Command InjectionEPSS 0.5%CVE-2024-4578HIGHPrivilege escalation in Arista Wireless Access PointsEPSS 0.5%CVE-2025-29154MEDIUMHTML injection vulnerability in lemeconsultoria HCM galera.app v.4.58.0 allows an attacker to execute arbitrary code via the .galera.app/tedEPSS 0.5%CVE-2026-4786HIGHIncomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open()EPSS 0.5%CVE-2025-59458HIGHIn JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54, 251.284.54, 251.28EPSS 0.5%CVE-2024-48139HIGHA prompt injection vulnerability in the chatbox of Blackbox AI v1.3.95 allows attackers to access and exfiltrate all previous and subsequentEPSS 0.5%CVE-2025-54131MEDIUMCursor bypasses its allow list to execute arbitrary commandsEPSS 0.5%CVE-2023-42136HIGHPAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow the execution of arbitrary commands witEPSS 0.5%CVE-2019-1795MEDIUMCisco FXOS and NX-OS Software Command Injection VulnerabilityEPSS 0.5%CVE-2019-1783MEDIUMCisco NX-OS Software Command Injection VulnerabilityEPSS 0.5%CVE-2019-1784MEDIUMCisco NX-OS Software Command Injection VulnerabilityEPSS 0.5%CVE-2025-56406HIGHAn issue was discovered in mcp-neo4j 0.3.0 allowing attackers to obtain sensitive information or execute arbitrary commands via the SSE servEPSS 0.5%CVE-2019-1923MEDIUMCisco Small Business SPA500 Series IP Phones Local Command Execution VulnerabilityEPSS 0.5%CVE-2023-5752MEDIUMMercurial configuration injectable in repo revision when installing via pipEPSS 0.5%CVE-2026-73763HIGHUnauthenticated Remote Command Execution in Management ComponentEPSS 0.5%CVE-2024-44570HIGHRELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a code injection vulnerability via the getParams function in phpinf.php.EPSS 0.5%CVE-2019-1606MEDIUMCisco NX-OS Software CLI Command Injection Vulnerability (CVE-2019-1606)EPSS 0.5%CVE-2018-0347—A vulnerability in the Zero Touch Provisioning (ZTP) subsystem of the Cisco SD-WAN Solution could allow an authenticated, local attacker to EPSS 0.5%