Weaknesses of type CWE-77

2,829 results

Injeção de comando por entrada não neutralizada

O software monta um comando (shell, sistema operacional ou aplicação) usando dados recebidos de fora (entrada do usuário, API, banco de dados) sem remover ou neutralizar caracteres especiais que alteram a semântica do comando. Isso permite que um atacante injete comandos arbitrários que serão executados com as permissões da aplicação.

Example

Um script PHP que executa ping com o IP fornecido pelo usuário: `system('ping ' . $_GET['ip'])`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, porque o ponto-e-vírgula não foi escapado e o shell interpreta dois comandos sequenciais.

How to mitigate

Use APIs seguras que não envolvem interpretação de shell (ex: ProcessBuilder em Java, subprocess.run com shell=False em Python). Se imperativo usar shell, valide com whitelist rigorosa (apenas caracteres alfanuméricos/IPs válidos) e escape com funções específicas da linguagem (escapeshellarg em PHP, shlex.quote em Python).

CVE-2020-3210MEDIUMCisco IOS Software for Cisco Industrial Routers Virtual Device Server CLI Command Injection VulnerabilityEPSS 0.4%CVE-2021-43589MEDIUMDell EMC Unity, Dell EMC UnityVSA and Dell EMC Unity XT versions prior to 5.1.2.0.5.007 contain an operating system (OS) command injection VEPSS 0.4%CVE-2026-76321HIGHSPL Injection through Nearby Event Searches in Splunk EnterpriseEPSS 0.4%CVE-2023-22657HIGHF5OS vulnerabilityEPSS 0.4%CVE-2025-71392CRITICALSurrealDB before 2.2.2 SurrealQL Injection via exportEPSS 0.4%CVE-2024-4638HIGHOnCell G3470A-LTE Series: Authenticated Command Injection via webUploadKeyEPSS 0.4%CVE-2024-57685MEDIUMAn issue in sparkshop v.1.1.7 and before allows a remote attacker to execute arbitrary code via a crafted phar file.EPSS 0.4%CVE-2026-23862HIGHDell ThinOS 10 versions prior to ThinOS 2602_10.0573, contain an Improper Neutralization of Special Elements used in a Command ('Command InjEPSS 0.4%CVE-2025-44023MEDIUMAn issue in dlink DNS-320 v.1.00 and DNS-320LW v.1.01.0914.20212 allows an attacker to execute arbitrary via the account_mgr.cgi->cgi_chg_adEPSS 0.4%CVE-2026-54090HIGHFile Browser: Command Allowlist Bypass via Shell Metacharacter InjectionEPSS 0.4%CVE-2025-52483HIGHRegistrator.jl Vulnerable to Argument Injection and Command InjectionEPSS 0.4%CVE-2024-56836HIGHA vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versions < V2.17.0), RUGGEEPSS 0.4%CVE-2026-35070MEDIUMDell SmartFabric Storage Software, versions prior to 1.4.5, contains an Improper Neutralization of Special Elements used in a Command ('CommEPSS 0.4%CVE-2026-21522MEDIUMMicrosoft ACI Confidential Containers Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2025-29155MEDIUMAn issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via the DELETE endpointEPSS 0.4%CVE-2024-48141HIGHA prompt injection vulnerability in the chatbox of Zhipu AI CodeGeeX v2.17.0 allows attackers to access and exfiltrate all previous and subsEPSS 0.4%CVE-2025-48979LOWAn Improper Input Validation in UISP Application could allow a Command Injection by a malicious actor with High Privileges and local access.EPSS 0.4%CVE-2024-51254HIGHDrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the EPSS 0.4%CVE-2024-51736NONECommand execution hijack on Windows with Process class in symfony/processEPSS 0.4%CVE-2025-15366MEDIUMIMAP command injection in user-controlled commandsEPSS 0.4%