Weaknesses of type CWE-77

2,829 results

Injeção de comando por entrada não neutralizada

O software monta um comando (shell, sistema operacional ou aplicação) usando dados recebidos de fora (entrada do usuário, API, banco de dados) sem remover ou neutralizar caracteres especiais que alteram a semântica do comando. Isso permite que um atacante injete comandos arbitrários que serão executados com as permissões da aplicação.

Example

Um script PHP que executa ping com o IP fornecido pelo usuário: `system('ping ' . $_GET['ip'])`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, porque o ponto-e-vírgula não foi escapado e o shell interpreta dois comandos sequenciais.

How to mitigate

Use APIs seguras que não envolvem interpretação de shell (ex: ProcessBuilder em Java, subprocess.run com shell=False em Python). Se imperativo usar shell, valide com whitelist rigorosa (apenas caracteres alfanuméricos/IPs válidos) e escape com funções específicas da linguagem (escapeshellarg em PHP, shlex.quote em Python).

CVE-2024-56087MEDIUMAn issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while querying Search Template Dashboard. These arEPSS 0.3%CVE-2024-56085MEDIUMAn issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while creating Search Template Dashboard. These arEPSS 0.3%CVE-2024-38831HIGHLocal privilege escalation vulnerability (CVE-2024-38831)EPSS 0.3%CVE-2025-63674MEDIUMAn issue in Blurams Lumi Security Camera (A31C) v23.1227.472.2926 allows local physical attackers to execute arbitrary code via overriding tEPSS 0.3%CVE-2024-54681LOWOssur Mobile Logic Application Command InjectionEPSS 0.3%CVE-2025-50817MEDIUMA vulnerability in the Python-Future 1.0.0 module allows for arbitrary code execution via the unintended import of a file named test.py. WheEPSS 0.3%CVE-2024-29435MEDIUMAn issue discovered in Alldata v0.4.6 allows attacker to run arbitrary commands via the processId parameter.EPSS 0.3%CVE-2022-46361MEDIUMPhysical access to the WDM enables use of USB device to gain access to the WDMEPSS 0.3%CVE-2022-20934MEDIUMA vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software and Cisco FXOS Software could allow an authenticated, local attaEPSS 0.3%CVE-2025-20258MEDIUMA vulnerability in the self-service portal of Cisco Duo could allow an unauthenticated, remote attacker to inject arbitrary commands into emEPSS 0.3%CVE-2025-5264MEDIUMPotential local code execution in “Copy as cURL” commandEPSS 0.3%CVE-2026-24167MEDIUMNVIDIA UFM Enterprise contains a vulnerability in the user management component, where an authenticated administrator could inject commands EPSS 0.3%CVE-2025-55372MEDIUMAn arbitrary file upload vulnerability in Beakon Application before v5.4.3 allows attackers to execute arbitrary code via uploading a crafteEPSS 0.3%CVE-2025-68432HIGHZed IDE LSP Binary Configuration Arbitrary Code ExecutionEPSS 0.3%CVE-2025-68433HIGHZed IDE MCP Context Server Configuration Arbitrary Code ExecutionEPSS 0.3%CVE-2026-76328MEDIUMSPL Injection through Splunk Web in Splunk EnterpriseEPSS 0.3%CVE-2025-29628CRITICALA Gardyn Azure IoT Hub connection string is downloaded over an insecure HTTP connection in Gardyn Home Kit firmware before master.619, Home EPSS 0.3%CVE-2025-57733MEDIUMIn JetBrains TeamCity before 2025.07.1 sMTP injection was possible allowing modification of email contentEPSS 0.3%CVE-2025-6945LOWImproper Neutralization of Special Elements used in a Command ('Command Injection') in GitLabEPSS 0.3%CVE-2025-51650MEDIUMAn arbitrary file upload vulnerability in the component /controller/PicManager.php of FoxCMS v1.2.6 allows attackers to execute arbitrary coEPSS 0.3%