Weaknesses of type CWE-77

2,831 results

Injeção de comando por entrada não neutralizada

O software monta um comando (shell, sistema operacional ou aplicação) usando dados recebidos de fora (entrada do usuário, API, banco de dados) sem remover ou neutralizar caracteres especiais que alteram a semântica do comando. Isso permite que um atacante injete comandos arbitrários que serão executados com as permissões da aplicação.

Example

Um script PHP que executa ping com o IP fornecido pelo usuário: `system('ping ' . $_GET['ip'])`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, porque o ponto-e-vírgula não foi escapado e o shell interpreta dois comandos sequenciais.

How to mitigate

Use APIs seguras que não envolvem interpretação de shell (ex: ProcessBuilder em Java, subprocess.run com shell=False em Python). Se imperativo usar shell, valide com whitelist rigorosa (apenas caracteres alfanuméricos/IPs válidos) e escape com funções específicas da linguagem (escapeshellarg em PHP, shlex.quote em Python).

CVE-2025-59815HIGHAuthenticated Remote Code Execution in the Billing Administration portalEPSS 0.3%CVE-2023-0628MEDIUMDocker Desktop before 4.17.0 allows an attacker to execute an arbitrary command inside a Dev Environments container during initialization by tricking a user to open a crafted malicious docker-desktop:// URLEPSS 0.3%CVE-2024-47562CRITICALA vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly neutralizeEPSS 0.3%CVE-2025-43858CRITICALYoutubeDLSharp allows command injection on windows system due to non sanitized argumentsEPSS 0.3%CVE-2025-50515MEDIUMAn issue was discovered in phome Empirebak 2010 in ebak2008/upload/class/config.php allowing attackers to execute arbitrary code when the coEPSS 0.3%CVE-2025-60838MEDIUMAn arbitrary file upload vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary code via uploading a crafted file.EPSS 0.3%CVE-2025-1910MEDIUMWatchGuard Mobile VPN with SSL Local Privilege Escalation via Update PackageEPSS 0.3%CVE-2021-1488MEDIUMCisco Adaptive Security Appliance Software and Firepower Threat Defense Software for Firepower 1000 and 2100 Series Appliances Command Injection VulnerabilityEPSS 0.3%CVE-2024-40070MEDIUMSourcecodester Online ID Generator System 1.0 was discovered to contain an arbitrary file upload vulnerability via id_generator/classes/UserEPSS 0.3%CVE-2025-55824MEDIUMModStartCMS v9.5.0 has an arbitrary file write vulnerability, which allows attackers to write malicious files and execute malicious commandsEPSS 0.3%CVE-2026-46709HIGHTabby: Drag-and-drop path injection still allows RCE via shell command substitution (incomplete fix for CVE-2026-45038)EPSS 0.3%CVE-2024-9773LOWImproper Neutralization of Special Elements used in a Command ('Command Injection') in GitLabEPSS 0.2%CVE-2025-31951HIGHHCL BigFix RunBookAI is affected by a Unvalidated Command Input / Potential Command Smuggling vulnerabilityEPSS 0.2%CVE-2025-59817HIGHAuthenticated Remote Code Execution in zForm_auto_configEPSS 0.2%CVE-2026-65111HIGHNVIDIA NeMo Speech for all platforms contains a vulnerability where malicious input created by an attacker could cause a code injection. A sEPSS 0.2%CVE-2025-67508HIGHgardenctl is vulnerable to Command Injection when used with non‑POSIX shellsEPSS 0.2%CVE-2025-54393MEDIUMNetwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows Static Code Injection. Authenticated users can obtEPSS 0.2%CVE-2021-21595MEDIUMDell EMC PowerScale OneFS versions 8.2.x - 9.1.1.x contain an improper neutralization of special elements used in an OS command. This vulnerEPSS 0.2%CVE-2024-8405MEDIUMArbitrary File Creation in PaperCut NG/MF Web Print leading to a Denial of Service attackEPSS 0.2%CVE-2025-66715MEDIUMA DLL hijacking vulnerability in Axtion ODISSAAS ODIS v1.8.4 allows attackers to execute arbitrary code via a crafted DLL file.EPSS 0.2%