Fallos del tipo CWE-77
2819 resultadosInjeção de comando via entrada não sanitizada
O software constrói comandos (shell, SQL, LDAP, etc.) usando dados de entrada do usuário sem neutralizar caracteres especiais que alteram a semântica do comando. Um atacante injeta metacaracteres (como `;`, `|`, `$()`) para executar instruções não previstas.
Ejemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validação. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos, porque o ponto-e-vírgula encadeia comandos no shell.
Cómo mitigar
Use APIs de execução que separam dados de comando (ex: `execvp()` com array de argumentos em vez de shell, prepared statements para SQL). Se shell for inevitável, whitelist rigoroso de entrada e escape apropriado com `escapeshellarg()` ou equivalente na linguagem.
CVE-2024-21903MEDIUMQTS, QuTS heroEPSS 0.8%CVE-2025-33180HIGHNVIDIA Cumulus Linux and NVOS products contain a vulnerability in the NVUE interface, where a low-privileged user could inject a command. A EPSS 0.8%CVE-2026-22708HIGHCursor has a Terminal Tool Allowlist Bypass via Environment VariablesEPSS 0.8%CVE-2024-46084HIGHScriptcase 9.10.023 and before is vulnerable to Remote Code Execution (RCE) via the nm_unzip function.EPSS 0.8%CVE-2023-26429LOWControl characters were not removed when exporting user feedback content. This allowed attackers to include unexpected content via user feedEPSS 0.8%CVE-2025-25604MEDIUMTotolink X5000R V9.1.0u.6369_B20230113 is vulnerable to command injection via the vif_disable function in mtkwifi.lua.EPSS 0.8%CVE-2025-25605MEDIUMTotolink X5000R V9.1.0u.6369_B20230113 is vulnerable to command injection via the apcli_wps_gen_pincode function in mtkwifi.lua.EPSS 0.8%CVE-2026-22785CRITICALorval MCP client is vulnerable to a code injection attack.EPSS 0.8%CVE-2026-45558CRITICALRoxy-WI: Authenticated RCE on every managed HAProxy load balancer via `option` field config injection in section saveEPSS 0.8%CVE-2024-43693CRITICALDover Fueling Solutions ProGauge MAGLINK LX CONSOLE Command InjectionEPSS 0.8%CVE-2024-45066CRITICALDover Fueling Solutions ProGauge MAGLINK LX CONSOLE Command InjectionEPSS 0.8%CVE-2026-54680CRITICALLogging operator has Fluentd configuration injection that allows remote code executionEPSS 0.8%CVE-2025-64093CRITICALUnauthenticated Remote Code Execution via the device hostnameEPSS 0.8%CVE-2024-7700MEDIUMForeman: command injection in "host init config" template via "install packages" field on foremanEPSS 0.8%CVE-2025-0593HIGHSICK Lector8xx and InspectorP8xx vulnerable for code executionEPSS 0.8%CVE-2026-20176CRITICALCisco Identity Services Engine Remote Code Execution VulnerabilityEPSS 0.8%CVE-2024-36073HIGHNetwrix CoSoSys Endpoint Protector through 5.9.3 and CoSoSys Unify through 7.0.6 contain a remote code execution vulnerability in the shadowEPSS 0.8%CVE-2023-28677CRITICALJenkins Convert To Pipeline Plugin 1.0 and earlier uses basic string concatenation to convert Freestyle projects' Build Environment, Build SEPSS 0.8%CVE-2025-50722CRITICALInsecure Permissions vulnerability in sparkshop v.1.1.7 allows a remote attacker to execute arbitrary code via the Common.php componentEPSS 0.8%CVE-2025-29230HIGHLinksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.emailReg function. The vulnerability can EPSS 0.8%