Weaknesses of type CWE-77

2,829 results

Injeção de comando por entrada não neutralizada

O software monta um comando (shell, sistema operacional ou aplicação) usando dados recebidos de fora (entrada do usuário, API, banco de dados) sem remover ou neutralizar caracteres especiais que alteram a semântica do comando. Isso permite que um atacante injete comandos arbitrários que serão executados com as permissões da aplicação.

Example

Um script PHP que executa ping com o IP fornecido pelo usuário: `system('ping ' . $_GET['ip'])`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, porque o ponto-e-vírgula não foi escapado e o shell interpreta dois comandos sequenciais.

How to mitigate

Use APIs seguras que não envolvem interpretação de shell (ex: ProcessBuilder em Java, subprocess.run com shell=False em Python). Se imperativo usar shell, valide com whitelist rigorosa (apenas caracteres alfanuméricos/IPs válidos) e escape com funções específicas da linguagem (escapeshellarg em PHP, shlex.quote em Python).

CVE-2026-40698HIGHiControl REST and TMSH vulnerabilityEPSS 0.4%CVE-2023-49587MEDIUMCommand Injection vulnerability in SAP Solution ManagerEPSS 0.4%CVE-2026-41953HIGHBIG-IP Privilege Escalation vulnerabilityEPSS 0.4%CVE-2025-51472MEDIUMCode Injection in AgentTemplate.eval_agent_config in TransformerOptimus SuperAGI 0.0.14 allows remote attackers to execute arbitrary Python EPSS 0.4%CVE-2025-55848HIGHAn issue was discovered in DIR-823 firmware 20250416. There is an RCE vulnerability in the set_cassword settings interface, as the http_cassEPSS 0.4%CVE-2026-42850HIGHKitty has a shell command injectionEPSS 0.4%CVE-2025-61514MEDIUMAn arbitrary file upload vulnerability in SageMath, Inc CoCalc before commit 0d2ff58 allows attackers to execute arbitrary code via uploadinEPSS 0.4%CVE-2024-4712HIGHArbitrary File Creation in PaperCut NG/MF Web Print Image HandlerEPSS 0.4%CVE-2025-50891HIGHThe server-side backend for Adform Site Tracking before 2025-08-28 allows attackers to inject HTML or execute arbitrary code via cookie hijaEPSS 0.4%CVE-2024-9579HIGHCertain Poly Video Conference Devices – Potential Remote Code ExecutionEPSS 0.4%CVE-2024-57608MEDIUMAn issue in Via Browser 6.1.0 allows a a remote attacker to execute arbitrary code via the mark.via.Shell component.EPSS 0.4%CVE-2025-25792MEDIUMSeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the isopen parameter at admin_weixin.php.EPSS 0.4%CVE-2025-65657MEDIUMFeehiCMS version 2.1.1 has a Remote Code Execution via Unrestricted File Upload in Ad Management. FeehiCMS version 2.1.1 allows authenticateEPSS 0.4%CVE-2025-27146LOWMatrix IRC Bridge allows IRC command injection to own puppeted userEPSS 0.4%CVE-2026-73454HIGHSecurity Advisory 0165EPSS 0.4%CVE-2026-45628CRITICALDokploy: Command Injection via Unescaped Branch Fields in Deployment PipelineEPSS 0.4%CVE-2019-16011HIGHCisco IOS XE SD-WAN Software Command Injection VulnerabilityEPSS 0.4%CVE-2026-55946MEDIUMMicrosoft Copilot Information Disclosure VulnerabilityEPSS 0.4%CVE-2024-51257HIGHDrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the EPSS 0.4%CVE-2024-51255CRITICALDrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the EPSS 0.4%