Fallos del tipo CWE-77
2819 resultadosInjeção de comando via entrada não sanitizada
O software constrói comandos (shell, SQL, LDAP, etc.) usando dados de entrada do usuário sem neutralizar caracteres especiais que alteram a semântica do comando. Um atacante injeta metacaracteres (como `;`, `|`, `$()`) para executar instruções não previstas.
Ejemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validação. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos, porque o ponto-e-vírgula encadeia comandos no shell.
Cómo mitigar
Use APIs de execução que separam dados de comando (ex: `execvp()` com array de argumentos em vez de shell, prepared statements para SQL). Se shell for inevitável, whitelist rigoroso de entrada e escape apropriado com `escapeshellarg()` ou equivalente na linguagem.
CVE-2018-19013—An attacker could inject commands to delete files and/or delete the contents of a file on CX-Supervisor (Versions 3.42 and prior) through a EPSS 0.8%CVE-2020-29547MEDIUMAn issue was discovered in Citadel through webcit-926. Meddler-in-the-middle attackers can pipeline commands after POP3 STLS, IMAP STARTTLS,EPSS 0.8%CVE-2023-26430LOWAttackers with access to user accounts can inject arbitrary control characters to SIEVE mail-filter rules. This could be abused to access SIEPSS 0.8%CVE-2024-28136HIGHPHOENIX CONTACT: command injection gains root privileges using the OCPP remote serviceEPSS 0.8%CVE-2025-62222HIGHAgentic AI and Visual Studio Code Remote Code Execution VulnerabilityEPSS 0.7%CVE-2026-24132HIGHOrval Mock Generation Code Injection via constEPSS 0.7%CVE-2024-7679HIGHImproper neutralization special element in hyperlinksEPSS 0.7%CVE-2025-63406HIGHAn issue in Intermesh BV GroupOffice vulnerable before v.25.0.47 and 6.8.136 allows a remote attacker to execute arbitrary code via the dbToEPSS 0.7%CVE-2022-26415HIGHOn F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior EPSS 0.7%CVE-2026-23653MEDIUMGitHub Copilot and Visual Studio Code Information Disclosure VulnerabilityEPSS 0.7%CVE-2023-21805HIGHWindows MSHTML Platform Remote Code Execution VulnerabilityEPSS 0.7%CVE-2023-49565HIGHRemote Code ExecutionEPSS 0.7%CVE-2024-48830HIGHDell SmartFabric OS10 Software, version(s) 10.5.4.x, 10.5.5.x, 10.5.6.x, 10.6.0.x, contain(s) an Improper Neutralization of Special ElementsEPSS 0.7%CVE-2026-30461HIGHDaylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the /controllers/InsEPSS 0.7%CVE-2024-27818HIGHThe issue was addressed with improved memory handling. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS EPSS 0.7%CVE-2026-93967MEDIUMaiyiyi121 SxDevOps Command services.py generate_host_task command injectionEPSS 0.7%CVE-2024-39703HIGHIn ThreatQuotient ThreatQ before 5.29.3, authenticated users are able to execute arbitrary commands by sending a crafted request to an API eEPSS 0.7%CVE-2025-56425CRITICALAn issue was discovered in the AppConnector component version 10.10.0.183 and earlier of enaio 10.10, in the AppConnector component version EPSS 0.7%CVE-2021-32692CRITICALActivity Watch vulnerable to command execution on macOS via printAppTitle.scptEPSS 0.7%CVE-2022-4009HIGHIn affected versions of Octopus Deploy it is possible for a user to introduce code via offline package creationEPSS 0.7%