Weaknesses of type CWE-77

2,829 results

Injeção de comando por entrada não neutralizada

O software monta um comando (shell, sistema operacional ou aplicação) usando dados recebidos de fora (entrada do usuário, API, banco de dados) sem remover ou neutralizar caracteres especiais que alteram a semântica do comando. Isso permite que um atacante injete comandos arbitrários que serão executados com as permissões da aplicação.

Example

Um script PHP que executa ping com o IP fornecido pelo usuário: `system('ping ' . $_GET['ip'])`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, porque o ponto-e-vírgula não foi escapado e o shell interpreta dois comandos sequenciais.

How to mitigate

Use APIs seguras que não envolvem interpretação de shell (ex: ProcessBuilder em Java, subprocess.run com shell=False em Python). Se imperativo usar shell, valide com whitelist rigorosa (apenas caracteres alfanuméricos/IPs válidos) e escape com funções específicas da linguagem (escapeshellarg em PHP, shlex.quote em Python).

CVE-2025-24049HIGHAzure Command Line Integration (CLI) Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2024-48140HIGHA prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica Your AI Copilot powered by ChatGPT4 v6.3.0 allows attackeEPSS 0.4%CVE-2024-48142HIGHA prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica ChatGPT AI Assistant v2.4.0 allows attackers to access anEPSS 0.4%CVE-2025-25794MEDIUMSeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_ping.php.EPSS 0.4%CVE-2025-25797MEDIUMSeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_smtp.php.EPSS 0.4%CVE-2025-25813MEDIUMSeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_files.php.EPSS 0.4%CVE-2025-25793MEDIUMSeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_notify.php.EPSS 0.4%CVE-2025-25796MEDIUMSeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_template.php.EPSS 0.4%CVE-2025-25802MEDIUMSeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_ip.php.EPSS 0.4%CVE-2024-34713LOWsshproxy vulnerable to SSH option injectionEPSS 0.4%CVE-2026-46529HIGHPDF /GoToR action argv injection enables single-click RCE via --gtk-module dlopenEPSS 0.4%CVE-2026-21638HIGHA malicious actor in Wi-Fi range of the affected product could leverage a vulnerability in the airMAX Wireless Protocol to achieve a remote EPSS 0.4%CVE-2024-38903MEDIUMH3C Magic R230 V100R002's udpserver opens port 9034, allowing attackers to execute arbitrary commands.EPSS 0.4%CVE-2024-56086HIGHAn issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads in Report Templates. These are executed when the bEPSS 0.4%CVE-2025-64090CRITICALAuthenticated Remote Code Execution in device hostnameEPSS 0.4%CVE-2024-22246HIGHVMware SD-WAN Edge contains an unauthenticated command injection vulnerability potentially leading to remote code execution. A malicious acEPSS 0.4%CVE-2024-53672MEDIUMAuthenticated Remote Command Injection in HPE Aruba Networking ClearPass Policy Manager Web-Based Management InterfaceEPSS 0.4%CVE-2024-51317MEDIUMAn issue in NetSurf v.3.11 allows a remote attacker to execute arbitrary code via the dom_node_normalize functionEPSS 0.4%CVE-2025-56426MEDIUMAn issue WebKul Bagisto v.2.3.6 allows a remote attacker to execute arbitrary code via the Cart/Checkout API endpoint, specifically, the priEPSS 0.4%CVE-2026-40061HIGHiControl REST and tmsh vulnerabilityEPSS 0.4%