Weaknesses of type CWE-77

2,831 results

Injeção de comando por entrada não neutralizada

O software monta um comando (shell, sistema operacional ou aplicação) usando dados recebidos de fora (entrada do usuário, API, banco de dados) sem remover ou neutralizar caracteres especiais que alteram a semântica do comando. Isso permite que um atacante injete comandos arbitrários que serão executados com as permissões da aplicação.

Example

Um script PHP que executa ping com o IP fornecido pelo usuário: `system('ping ' . $_GET['ip'])`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, porque o ponto-e-vírgula não foi escapado e o shell interpreta dois comandos sequenciais.

How to mitigate

Use APIs seguras que não envolvem interpretação de shell (ex: ProcessBuilder em Java, subprocess.run com shell=False em Python). Se imperativo usar shell, valide com whitelist rigorosa (apenas caracteres alfanuméricos/IPs válidos) e escape com funções específicas da linguagem (escapeshellarg em PHP, shlex.quote em Python).

CVE-2026-47242MEDIUMNet::IMAP: Command Injection via ID command argumentEPSS 0.2%CVE-2025-22237MEDIUMCVE-2025-22237 salt advisoryEPSS 0.2%CVE-2025-33249HIGHNVIDIA NeMo Framework for all platforms contains a vulnerability in a voice-preprocessing script, where malicious input created by an attackEPSS 0.2%CVE-2025-20278MEDIUMCisco Unified Communications Products Command Injection VulnerabilityEPSS 0.2%CVE-2026-75052LOWIn JetBrains IntelliJ IDEA before 2026.2.1 command execution via crafted Markdown preview content was possible in trusted projectsEPSS 0.2%CVE-2026-21709MEDIUMA vulnerability allowing a local attacker with administrator privileges to bypass Windows Driver Signature Enforcement.EPSS 0.2%CVE-2025-27233MEDIUMZabbix Agent 2 smartctl plugin argument injection in Zabbix 6.0 and later.EPSS 0.2%CVE-2025-24333MEDIUMAdministrative user shell input validation faultEPSS 0.2%CVE-2025-56814HIGHA code injection vulnerability in the wxExecute() function of OpenCPN v5.12.0 allows attackers to execute arbitrary code via embedding shellEPSS 0.2%CVE-2026-59846LOWLibssh: libssh: information disclosure via proxycommand %r username expansionEPSS 0.2%CVE-2025-57521MEDIUMBambu Studio 2.1.1.52 and earlier is affected by a vulnerability that allows arbitrary code execution during application startup. The applicEPSS 0.2%CVE-2025-49823NONEConda Constructor Command Injection via Unsanitized User Input (Low)EPSS 0.2%CVE-2025-1549MEDIUMWatchGuard Mobile VPN with SSL Local Privilege EscallationEPSS 0.1%CVE-2025-65885MEDIUMAn issue was discovered in the Delight Custom Firmware (CFW) for Nokia Symbian Belle devices on Nokia 808 (Delight v1.8), Nokia N8 (Delight EPSS 0.1%CVE-2026-25046LOW[Kimi VS Code] Command Injection in publish scripts vsix-publish.js and ovsx-publish.jsEPSS 0.1%CVE-2025-60855MEDIUMReolink Video Doorbell WiFi DB_566128M5MP_W performs insufficient validation of firmware update signatures. This allows attackers to load maEPSS 0.1%CVE-2026-102827HIGHsimple-git: unsafe-operations plugin bypass via git long-option abbreviation (--receive-p/--exe) -> command execution (residual of CVE-2026-28291)EPSS —CVE-2026-102240CRITICALNetcore NAP930 Network Tools CGI network_tools eval os command injectionEPSS —CVE-2026-101262CRITICALZiroom ZHOME A0101 set_online_client command injectionEPSS —CVE-2026-101187CRITICALZiroom ZHOME A0101 USB Device Management API zrUsb.lua pop_usb_device command injectionEPSS —