Weaknesses of type CWE-77

2,829 results

Injeção de comando por entrada não neutralizada

O software monta um comando (shell, sistema operacional ou aplicação) usando dados recebidos de fora (entrada do usuário, API, banco de dados) sem remover ou neutralizar caracteres especiais que alteram a semântica do comando. Isso permite que um atacante injete comandos arbitrários que serão executados com as permissões da aplicação.

Example

Um script PHP que executa ping com o IP fornecido pelo usuário: `system('ping ' . $_GET['ip'])`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, porque o ponto-e-vírgula não foi escapado e o shell interpreta dois comandos sequenciais.

How to mitigate

Use APIs seguras que não envolvem interpretação de shell (ex: ProcessBuilder em Java, subprocess.run com shell=False em Python). Se imperativo usar shell, valide com whitelist rigorosa (apenas caracteres alfanuméricos/IPs válidos) e escape com funções específicas da linguagem (escapeshellarg em PHP, shlex.quote em Python).

CVE-2025-45011MEDIUMA HTML Injection vulnerability was discovered in the foreigner-search.php file of PHPGurukul Park Ticketing Management System v2.0. This vulEPSS 0.3%CVE-2025-45009MEDIUMA HTML Injection vulnerability was discovered in the normal-search.php file of PHPGurukul Park Ticketing Management System v2.0. This vulnerEPSS 0.3%CVE-2025-45326MEDIUMAn issue in PocketVJ CP PocketVJ-CP-v3 pvj 3.9.1 allows remote attackers to execute arbitrary code via the submit_size.php component.EPSS 0.3%CVE-2024-20326HIGHA vulnerability in the ConfD CLI and the Cisco Crosswork Network Services Orchestrator CLI could allow an authenticated, low-privileged, loEPSS 0.3%CVE-2025-56769MEDIUMAn issue was discovered in chinabugotech hutool before 5.8.4 allowing attackers to execute arbitrary expressions that lead to arbitrary methEPSS 0.3%CVE-2026-20325CRITICALCisco Nexus Dashboard Software Security Hardening Release September 2026 - Improper Neutralization of Special Elements used in a CommandEPSS 0.3%CVE-2025-14031HIGHIBM Sterling B2B Integrator and IBM Sterling File Gateway Denial of ServiceEPSS 0.3%CVE-2025-25768MEDIUMMRCMS v3.1.2 was discovered to contain a server-side template injection (SSTI) vulnerability in the component \servlet\DispatcherServlet.javEPSS 0.3%CVE-2024-4944HIGHMobile VPN with SSL Local Privilege Escalation VulnerabilityEPSS 0.3%CVE-2022-47028MEDIUMAn issue discovered in Action Launcher for Android v50.5 allows an attacker to cause a denial of service via arbitary data injection to funcEPSS 0.3%CVE-2026-73078HIGHVim: Arbitrary Code Execution via Netrw Menu ConstructionEPSS 0.3%CVE-2026-73709HIGHUnauthenticated Remote Code Execution during HPE Networking Fabric Composer Installation ProcessEPSS 0.3%CVE-2026-35558HIGHImproper neutralization of special elements in authentication components in Amazon Athena ODBC driverEPSS 0.3%CVE-2024-56084HIGHAn issue was discovered in Logpoint UniversalNormalizer before 5.7.0. Authenticated users can inject payloads while creating Universal NormaEPSS 0.3%CVE-2022-25619LOWAuthenticated Command Injection to RCEEPSS 0.3%CVE-2026-30615HIGHA prompt injection vulnerability in Windsurf 1.9544.26 allows remote attackers to execute arbitrary commands on a victim system. When WindsuEPSS 0.3%CVE-2025-25766MEDIUMAn arbitrary file upload vulnerability in the component /file/savefile.do of MRCMS v3.1.2 allows attackers to execute arbitrary code via uplEPSS 0.3%CVE-2026-68792HIGHMicrosoft Office Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-69534HIGHWindows Program Compatibility Assistant Service Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-58635HIGHWindows Narrator Braille Elevation of Privilege VulnerabilityEPSS 0.3%