Fallos del tipo CWE-77
2816 resultadosInjeção de comando via entrada não sanitizada
O software constrói comandos (shell, SQL, LDAP, etc.) usando dados de entrada do usuário sem neutralizar caracteres especiais que alteram a semântica do comando. Um atacante injeta metacaracteres (como `;`, `|`, `$()`) para executar instruções não previstas.
Ejemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validação. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos, porque o ponto-e-vírgula encadeia comandos no shell.
Cómo mitigar
Use APIs de execução que separam dados de comando (ex: `execvp()` com array de argumentos em vez de shell, prepared statements para SQL). Se shell for inevitável, whitelist rigoroso de entrada e escape apropriado com `escapeshellarg()` ou equivalente na linguagem.
CVE-2024-26298HIGHVulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands onEPSS 0.9%CVE-2024-26296HIGHVulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands onEPSS 0.9%CVE-2024-4078CRITICALArbitrary Code Execution in parisneo/lollmsEPSS 0.9%CVE-2024-26297HIGHVulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands onEPSS 0.9%CVE-2026-11487MEDIUMNeovim View Branch secure.lua M.read command injectionEPSS 0.9%CVE-2026-42827MEDIUMM365 Copilot Information Disclosure VulnerabilityEPSS 0.9%CVE-2026-42824MEDIUMM365 Copilot Information Disclosure VulnerabilityEPSS 0.9%CVE-2026-26136MEDIUMMicrosoft Copilot Information Disclosure VulnerabilityEPSS 0.9%CVE-2026-47285MEDIUMVisual Studio Code Information Disclosure VulnerabilityEPSS 0.9%CVE-2026-24712HIGHNorthern.tech CFEngine Enterprise and Community before 3.21.8, 3.24.3, and 3.27.0 allows Command injection.EPSS 0.9%CVE-2026-7246HIGH[DISPUTED] Pallets Click contains a command injection via Unsanitized Filename "click.edit()"EPSS 0.9%CVE-2025-55319HIGHAgentic AI and Visual Studio Code Remote Code Execution VulnerabilityEPSS 0.9%CVE-2024-39577HIGHDell SmartFabric OS10 Software, versions 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contains an Improper Neutralization of Special Elements useEPSS 0.9%CVE-2023-23149CRITICALDEK-1705 <=Firmware:34.23.1 device was discovered to have a command execution vulnerability.EPSS 0.9%CVE-2022-36786CRITICALDLINK - DSL-224 Post-auth RCE.EPSS 0.9%CVE-2024-41136MEDIUMAuthenticated Command Injection in HPE Aruba Networking EdgeConnect SD-WAN Command Line InterfaceEPSS 0.9%CVE-2025-48492HIGHGetSimple CMS RCE in Edit componentEPSS 0.9%CVE-2026-20761HIGHEnOcean SmartServer IoT Command InjectionEPSS 0.9%CVE-2025-30264HIGHQTS, QuTS heroEPSS 0.9%CVE-2025-41451HIGHPost-Authentication OS Command Injection RCE in Danfoss AK-SM8xxA SeriesEPSS 0.9%