Fallos del tipo CWE-77
2828 resultadosInjeção de comando via entrada não sanitizada
O software constrói comandos (shell, SQL, LDAP, etc.) usando dados de entrada do usuário sem neutralizar caracteres especiais que alteram a semântica do comando. Um atacante injeta metacaracteres (como `;`, `|`, `$()`) para executar instruções não previstas.
Ejemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validação. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos, porque o ponto-e-vírgula encadeia comandos no shell.
Cómo mitigar
Use APIs de execução que separam dados de comando (ex: `execvp()` com array de argumentos em vez de shell, prepared statements para SQL). Se shell for inevitável, whitelist rigoroso de entrada e escape apropriado com `escapeshellarg()` ou equivalente na linguagem.
CVE-2018-0481—Cisco IOS XE Software Command Injection VulnerabilitiesEPSS 0.5%CVE-2026-45585MEDIUMWindows BitLocker Security Feature Bypass VulnerabilityEPSS 0.5%CVE-2024-23971HIGHChargePoint Home Flex OCPP bswitch Command InjectionEPSS 0.5%CVE-2024-4578HIGHPrivilege escalation in Arista Wireless Access PointsEPSS 0.5%CVE-2025-29154MEDIUMHTML injection vulnerability in lemeconsultoria HCM galera.app v.4.58.0 allows an attacker to execute arbitrary code via the .galera.app/tedEPSS 0.5%CVE-2026-4786HIGHIncomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open()EPSS 0.5%CVE-2025-59458HIGHIn JetBrains Junie before 252.284.66,
251.284.66,
243.284.66,
252.284.61,
251.284.61,
243.284.61,
252.284.50,
252.284.54,
251.284.54,
251.28EPSS 0.5%CVE-2024-48139HIGHA prompt injection vulnerability in the chatbox of Blackbox AI v1.3.95 allows attackers to access and exfiltrate all previous and subsequentEPSS 0.5%CVE-2025-54131MEDIUMCursor bypasses its allow list to execute arbitrary commandsEPSS 0.5%CVE-2023-42136HIGHPAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow the execution of arbitrary commands witEPSS 0.5%CVE-2019-1795MEDIUMCisco FXOS and NX-OS Software Command Injection VulnerabilityEPSS 0.5%CVE-2019-1783MEDIUMCisco NX-OS Software Command Injection VulnerabilityEPSS 0.5%CVE-2019-1784MEDIUMCisco NX-OS Software Command Injection VulnerabilityEPSS 0.5%CVE-2025-56406HIGHAn issue was discovered in mcp-neo4j 0.3.0 allowing attackers to obtain sensitive information or execute arbitrary commands via the SSE servEPSS 0.5%CVE-2019-1923MEDIUMCisco Small Business SPA500 Series IP Phones Local Command Execution VulnerabilityEPSS 0.5%CVE-2023-5752MEDIUMMercurial configuration injectable in repo revision when installing via pipEPSS 0.5%CVE-2026-73763HIGHUnauthenticated Remote Command Execution in Management ComponentEPSS 0.5%CVE-2024-44570HIGHRELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a code injection vulnerability via the getParams function in phpinf.php.EPSS 0.5%CVE-2019-1606MEDIUMCisco NX-OS Software CLI Command Injection Vulnerability (CVE-2019-1606)EPSS 0.5%CVE-2018-0347—A vulnerability in the Zero Touch Provisioning (ZTP) subsystem of the Cisco SD-WAN Solution could allow an authenticated, local attacker to EPSS 0.5%