Weaknesses of type CWE-77

2,831 results

Injeção de comando por entrada não neutralizada

O software monta um comando (shell, sistema operacional ou aplicação) usando dados recebidos de fora (entrada do usuário, API, banco de dados) sem remover ou neutralizar caracteres especiais que alteram a semântica do comando. Isso permite que um atacante injete comandos arbitrários que serão executados com as permissões da aplicação.

Example

Um script PHP que executa ping com o IP fornecido pelo usuário: `system('ping ' . $_GET['ip'])`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, porque o ponto-e-vírgula não foi escapado e o shell interpreta dois comandos sequenciais.

How to mitigate

Use APIs seguras que não envolvem interpretação de shell (ex: ProcessBuilder em Java, subprocess.run com shell=False em Python). Se imperativo usar shell, valide com whitelist rigorosa (apenas caracteres alfanuméricos/IPs válidos) e escape com funções específicas da linguagem (escapeshellarg em PHP, shlex.quote em Python).

CVE-2025-70296MEDIUMA stored HTML injection vulnerability in the Recipe Notes rendering component in Mealie 3.3.1 allows remote authenticated users to inject arEPSS 0.2%CVE-2025-25791MEDIUMAn arbitrary file upload vulnerability in the plugin installation feature of YZNCMS v2.0.1 allows attackers to execute arbitrary code via upEPSS 0.2%CVE-2024-8402LOWImproper Neutralization of Special Elements used in a Command ('Command Injection') in GitLabEPSS 0.2%CVE-2026-46508HIGHTurborepo: VSCode Extension command injectionEPSS 0.2%CVE-2023-20097MEDIUMCisco Access Point Software Command Injection VulnerabilityEPSS 0.2%CVE-2026-34259HIGHOS Command Injection Vulnerability in SAP Forecasting & ReplenishmentEPSS 0.2%CVE-2023-33806HIGHInsecure default configurations in Hikvision Interactive Tablet DS-D5B86RB/B V2.3.0 build220119, allows attackers to execute arbitrary commaEPSS 0.2%CVE-2024-27763MEDIUMXPixelGroup BasicSR through 1.4.2 might locally allow code execution in contrived situations where "scontrol show hostname" is executed in tEPSS 0.2%CVE-2026-27001HIGHOpenClaw: Unsanitized CWD path injection into LLM promptsEPSS 0.2%CVE-2026-76339MEDIUMSPL Injection through the geostats Command in Splunk EnterpriseEPSS 0.2%CVE-2025-52687LOWJavaScript Injection Vulnerability in the OmniAccess Stellar Web Management InterfaceEPSS 0.2%CVE-2025-6522MEDIUMTrendMakers Sight Bulb Pro Command InjectionEPSS 0.2%CVE-2026-43990HIGHJunoClaw: plugin-shell shell-metacharacter injection via shell wrapperEPSS 0.2%CVE-2025-26237HIGHD-Link DI-7001 MINI_5G 19.10.31A1 contains a code execution vulnerability in the flag parameter of msp_info, which can be exploited to run aEPSS 0.2%CVE-2023-40396HIGHThe issue was addressed with improved memory handling. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14, watchOS 10, tvOS 17. AnEPSS 0.2%CVE-2023-36642MEDIUMAn improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface of FortiTester 3.0.0EPSS 0.2%CVE-2026-20169MEDIUMCisco IoT Field Network Director Command Injection VulnerabilityEPSS 0.2%CVE-2024-57695HIGHAn issue in Agnitum Outpost Security Suite 7.5.3 (3942.608.1810) and 7.6 (3984.693.1842) allows a local attacker to execute arbitrary code vEPSS 0.2%CVE-2026-57453MEDIUMVim: PowerShell Command Injection via Unescaped Filename in zip.vim ExtractionEPSS 0.2%CVE-2026-72913HIGHKitty: Command injection into the child shell via chained @kitty-echo + @kitty-ssh DCS escape sequencesEPSS 0.2%