Weaknesses of type CWE-77

2,810 results

Injeção de comando por entrada não neutralizada

O software monta um comando (shell, sistema operacional ou aplicação) usando dados recebidos de fora (entrada do usuário, API, banco de dados) sem remover ou neutralizar caracteres especiais que alteram a semântica do comando. Isso permite que um atacante injete comandos arbitrários que serão executados com as permissões da aplicação.

Example

Um script PHP que executa ping com o IP fornecido pelo usuário: `system('ping ' . $_GET['ip'])`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, porque o ponto-e-vírgula não foi escapado e o shell interpreta dois comandos sequenciais.

How to mitigate

Use APIs seguras que não envolvem interpretação de shell (ex: ProcessBuilder em Java, subprocess.run com shell=False em Python). Se imperativo usar shell, valide com whitelist rigorosa (apenas caracteres alfanuméricos/IPs válidos) e escape com funções específicas da linguagem (escapeshellarg em PHP, shlex.quote em Python).

CVE-2025-22630CRITICALWordPress Widget Options Plugin <= 4.1.0 - Arbitrary Code Execution vulnerabilityEPSS 1.1%CVE-2023-26130HIGHVersions of the package yhirose/cpp-httplib before 0.12.4 are vulnerable to CRLF Injection when untrusted user input is used to set the contEPSS 1.1%CVE-2023-41334HIGHastropy vulnerable to RCE in TranformGraph().to_dot_graph functionEPSS 1.1%CVE-2025-54377HIGHRoo Code Lacks Line Break Validation in its Command Execution ToolEPSS 1.1%CVE-2025-10767LOWCosmodiumCS OnlyRAT Configuration File main.py remote_download os command injectionEPSS 1.1%CVE-2024-48659CRITICALAn issue in DCME-320-L <=9.3.2.114 allows a remote attacker to execute arbitrary code via the log_u_umount.php component.EPSS 1.1%CVE-2023-45025CRITICALQTS, QuTS hero, QuTScloudEPSS 1.1%CVE-2023-47560HIGHQuMagieEPSS 1.1%CVE-2025-62696MEDIUMMultiple critical security issues in SpringboardEPSS 1.1%CVE-2020-15874HIGHAn issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can execute arbitrary shell commands througEPSS 1.1%CVE-2020-36198MEDIUMCommand Injection Vulnerability in Malware RemoverEPSS 1.1%CVE-2025-52903HIGHFile Browser Allows Execution of Shell Commands That Can Spawn Other CommandsEPSS 1.1%CVE-2025-46122CRITICALAn issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the authenticated diagnostics API eEPSS 1.1%CVE-2024-55063HIGHMultiple Code Injection vulnerabilities in EasyVirt DC NetScope <= 8.7.0 allows remote authenticated attackers to execute arbitrary code viaEPSS 1.1%CVE-2026-20094HIGHCisco Integrated Management Controller Command Injection VulnerabilityEPSS 1.1%CVE-2024-29737HIGHApache StreamPark (incubating): maven build params could trigger remote command executionEPSS 1.1%CVE-2024-55414CRITICALA vulnerability exits in driver SmSerl64.sys in Motorola SM56 Modem WDM Driver v6.12.23.0, which allows low-privileged users to mapping physEPSS 1.1%CVE-2024-57590CRITICALTRENDnet TEW-632BRP v1.010B31 devices have an OS command injection vulnerability in the CGl interface "ntp_sync.cgi",which allows remote attEPSS 1.1%CVE-2025-61141HIGHsqls-server/sqls 0.2.28 is vulnerable to command injection in the config command because the openEditor function passes the EDITOR environmeEPSS 1.1%CVE-2026-11408MEDIUMvertex-app vertex Log Viewer Endpoint LogMod.js os command injectionEPSS 1.1%