Weaknesses of type CWE-77

2,829 results

Injeção de comando por entrada não neutralizada

O software monta um comando (shell, sistema operacional ou aplicação) usando dados recebidos de fora (entrada do usuário, API, banco de dados) sem remover ou neutralizar caracteres especiais que alteram a semântica do comando. Isso permite que um atacante injete comandos arbitrários que serão executados com as permissões da aplicação.

Example

Um script PHP que executa ping com o IP fornecido pelo usuário: `system('ping ' . $_GET['ip'])`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, porque o ponto-e-vírgula não foi escapado e o shell interpreta dois comandos sequenciais.

How to mitigate

Use APIs seguras que não envolvem interpretação de shell (ex: ProcessBuilder em Java, subprocess.run com shell=False em Python). Se imperativo usar shell, valide com whitelist rigorosa (apenas caracteres alfanuméricos/IPs válidos) e escape com funções específicas da linguagem (escapeshellarg em PHP, shlex.quote em Python).

CVE-2026-21639HIGHA malicious actor in Wi-Fi range of the affected product could leverage a vulnerability in the airMAX Wireless Protocol to achieve a remote EPSS 0.4%CVE-2024-23247HIGHThe issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5EPSS 0.4%CVE-2022-29256MEDIUMPossible vulnerability at 'npm install' time in sharp if an attacker has control over build environmentEPSS 0.4%CVE-2025-46365MEDIUMDell CloudLink, versions prior 8.1.1, contain a Command Injection vulnerability which can be exploited by an Authenticated attacker to causeEPSS 0.4%CVE-2025-29083MEDIUMSQL Injection vulnerability in CSZ-CMS v.1.3.0 allows a remote attacker to execute arbitrary code via the execSqlFile function in the PluginEPSS 0.4%CVE-2022-34432HIGHDell Hybrid Client below 1.8 version contains a gedit vulnerability. A guest attacker could potentially exploit this vulnerability, allowingEPSS 0.4%CVE-2024-12111HIGHPotential LDAP injection vulnerability in OpenText Privileged Access ManagerEPSS 0.4%CVE-2026-75004MEDIUMIn Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper rule name quoting could lead to managesieve_disabled_actions setting bypEPSS 0.4%CVE-2023-51295MEDIUMPHPJabbers Event Booking Calendar v4.0 is vulnerable to Multiple HTML Injection in the "name, plugin_sms_api_key, plugin_sms_country_code, tEPSS 0.4%CVE-2024-28328MEDIUMCSV Injection vulnerability in the Asus RT-N12+ router allows administrator users to inject arbitrary commands or formulas in the client namEPSS 0.4%CVE-2023-0978MEDIUM A command injection vulnerability in Trellix Intelligent Sandbox CLI for version 5.2 and earlier, allows a local user to inject and executeEPSS 0.4%CVE-2026-24169HIGHNVIDIA UFM Enterprise contains a vulnerability in the plugin management API, where an authenticated user with low privileges could inject coEPSS 0.4%CVE-2026-22601HIGHOpenProject is Vulnerable to Code Execution in E-Mail functionEPSS 0.4%CVE-2025-15367MEDIUMPOP3 command injection in user-controlled commandsEPSS 0.4%CVE-2025-46176MEDIUMHardcoded credentials in the Telnet service in D-Link DIR-605L v2.13B01 and DIR-816L v2.06B01 allow attackers to remotely execute arbitrary EPSS 0.4%CVE-2025-20306MEDIUMCisco Secure Firewall Management Center Software Command Injection VulnerabilityEPSS 0.4%CVE-2025-61584CRITICALserverless-dns is vulnerable to Command Injection through pr.yml GitHub Action WorkflowEPSS 0.4%CVE-2021-34726MEDIUMCisco SD-WAN Software Command Injection VulnerabilityEPSS 0.4%CVE-2025-27953MEDIUMAn issue in Clinical Collaboration Platform 12.2.1.5 allows a remote attacker to obtain sensitive information and execute arbitrary code viaEPSS 0.4%CVE-2024-55466MEDIUMAn arbitrary file upload vulnerability in the Image Gallery of ThingsBoard Community, ThingsBoard Cloud and ThingsBoard Professional v3.8.1 EPSS 0.4%