Weaknesses of type CWE-77

2,831 results

Injeção de comando por entrada não neutralizada

O software monta um comando (shell, sistema operacional ou aplicação) usando dados recebidos de fora (entrada do usuário, API, banco de dados) sem remover ou neutralizar caracteres especiais que alteram a semântica do comando. Isso permite que um atacante injete comandos arbitrários que serão executados com as permissões da aplicação.

Example

Um script PHP que executa ping com o IP fornecido pelo usuário: `system('ping ' . $_GET['ip'])`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, porque o ponto-e-vírgula não foi escapado e o shell interpreta dois comandos sequenciais.

How to mitigate

Use APIs seguras que não envolvem interpretação de shell (ex: ProcessBuilder em Java, subprocess.run com shell=False em Python). Se imperativo usar shell, valide com whitelist rigorosa (apenas caracteres alfanuméricos/IPs válidos) e escape com funções específicas da linguagem (escapeshellarg em PHP, shlex.quote em Python).

CVE-2025-5265MEDIUMPotential local code execution in “Copy as cURL” commandEPSS 0.2%CVE-2022-39084MEDIUMIn network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges nEPSS 0.2%CVE-2022-39081MEDIUMIn network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges nEPSS 0.2%CVE-2022-39086MEDIUMIn network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges nEPSS 0.2%CVE-2022-39083MEDIUMIn network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges nEPSS 0.2%CVE-2022-39082MEDIUMIn network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges nEPSS 0.2%CVE-2022-39085MEDIUMIn network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges nEPSS 0.2%CVE-2022-39088MEDIUMIn network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges nEPSS 0.2%CVE-2022-39087MEDIUMIn network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges nEPSS 0.2%CVE-2023-20121MEDIUMCisco Evolved Programmable Network Manager, Cisco Identity Services Engine, and Cisco Prime Infrastructure Command Injection VulnerabilitiesEPSS 0.2%CVE-2025-41721LOWSauter: Command InjectionEPSS 0.2%CVE-2026-36365HIGHAn issue in Lymphatus caesium-image-compressor All versions up to and including commit 02da2c6 allows a local attacker to execute arbitrary EPSS 0.2%CVE-2023-20122MEDIUMCisco Evolved Programmable Network Manager, Cisco Identity Services Engine, and Cisco Prime Infrastructure Command Injection VulnerabilitiesEPSS 0.2%CVE-2024-46062HIGHMiniconda3 macOS installers before 23.11.0-1 contain a local privilege escalation vulnerability when installed outside the user's home direcEPSS 0.2%CVE-2024-46060HIGHAnaconda3 macOS installers before 2024.06-1 contain a local privilege escalation vulnerability when installed outside the user's home directEPSS 0.2%CVE-2024-33469HIGHAn issue in Team Amaze Amaze File Manager v.3.8.5 and fixed in v.3.10 allows a local attacker to execute arbitrary code via the onCreate metEPSS 0.2%CVE-2026-73250MEDIUMNotepad++: Install-time PowerShell command injection through installation pathEPSS 0.2%CVE-2025-54564HIGHuploadsm in ChargePoint Home Flex 5.5.4.13 does not validate a user-controlled string for bz2 decompression, which allows command execution EPSS 0.2%CVE-2025-20117MEDIUMCisco Application Policy Infrastructure Controller Authenticated Command Injection VulnerabilityEPSS 0.2%CVE-2025-4089MEDIUMPotential local code execution in "copy as cURL" commandEPSS 0.2%