Fallos del tipo CWE-77
2829 resultadosInjeção de comando via entrada não sanitizada
O software constrói comandos (shell, SQL, LDAP, etc.) usando dados de entrada do usuário sem neutralizar caracteres especiais que alteram a semântica do comando. Um atacante injeta metacaracteres (como `;`, `|`, `$()`) para executar instruções não previstas.
Ejemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validação. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos, porque o ponto-e-vírgula encadeia comandos no shell.
Cómo mitigar
Use APIs de execução que separam dados de comando (ex: `execvp()` com array de argumentos em vez de shell, prepared statements para SQL). Se shell for inevitável, whitelist rigoroso de entrada e escape apropriado com `escapeshellarg()` ou equivalente na linguagem.
CVE-2025-24049HIGHAzure Command Line Integration (CLI) Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2024-48140HIGHA prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica Your AI Copilot powered by ChatGPT4 v6.3.0 allows attackeEPSS 0.4%CVE-2024-48142HIGHA prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica ChatGPT AI Assistant v2.4.0 allows attackers to access anEPSS 0.4%CVE-2025-25794MEDIUMSeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_ping.php.EPSS 0.4%CVE-2025-25797MEDIUMSeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_smtp.php.EPSS 0.4%CVE-2025-25813MEDIUMSeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_files.php.EPSS 0.4%CVE-2025-25793MEDIUMSeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_notify.php.EPSS 0.4%CVE-2025-25796MEDIUMSeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_template.php.EPSS 0.4%CVE-2025-25802MEDIUMSeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component admin_ip.php.EPSS 0.4%CVE-2024-34713LOWsshproxy vulnerable to SSH option injectionEPSS 0.4%CVE-2026-46529HIGHPDF /GoToR action argv injection enables single-click RCE via --gtk-module dlopenEPSS 0.4%CVE-2026-21638HIGHA malicious actor in Wi-Fi range of the affected product could leverage a vulnerability in the airMAX Wireless Protocol to achieve a remote EPSS 0.4%CVE-2024-38903MEDIUMH3C Magic R230 V100R002's udpserver opens port 9034, allowing attackers to execute arbitrary commands.EPSS 0.4%CVE-2024-56086HIGHAn issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads in Report Templates. These are executed when the bEPSS 0.4%CVE-2025-64090CRITICALAuthenticated Remote Code Execution in device hostnameEPSS 0.4%CVE-2024-22246HIGHVMware SD-WAN Edge contains an unauthenticated command injection vulnerability potentially leading to remote code execution.
A malicious acEPSS 0.4%CVE-2024-53672MEDIUMAuthenticated Remote Command Injection in HPE Aruba Networking ClearPass Policy Manager Web-Based Management InterfaceEPSS 0.4%CVE-2024-51317MEDIUMAn issue in NetSurf v.3.11 allows a remote attacker to execute arbitrary code via the dom_node_normalize functionEPSS 0.4%CVE-2025-56426MEDIUMAn issue WebKul Bagisto v.2.3.6 allows a remote attacker to execute arbitrary code via the Cart/Checkout API endpoint, specifically, the priEPSS 0.4%CVE-2026-40061HIGHiControl REST and tmsh vulnerabilityEPSS 0.4%