Fallos del tipo CWE-77
2829 resultadosInjeção de comando via entrada não sanitizada
O software constrói comandos (shell, SQL, LDAP, etc.) usando dados de entrada do usuário sem neutralizar caracteres especiais que alteram a semântica do comando. Um atacante injeta metacaracteres (como `;`, `|`, `$()`) para executar instruções não previstas.
Ejemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validação. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos, porque o ponto-e-vírgula encadeia comandos no shell.
Cómo mitigar
Use APIs de execução que separam dados de comando (ex: `execvp()` com array de argumentos em vez de shell, prepared statements para SQL). Se shell for inevitável, whitelist rigoroso de entrada e escape apropriado com `escapeshellarg()` ou equivalente na linguagem.
CVE-2026-69534HIGHWindows Program Compatibility Assistant Service Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-50523HIGHMicrosoft PowerShell Remote Code Execution VulnerabilityEPSS 0.3%CVE-2024-21117MEDIUMVulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). Supported versions thatEPSS 0.3%CVE-2025-63296MEDIUMKERUI K259 5MP Wi-Fi / Tuya Smart Security Camera firmware v33.53.87 contains a code execution vulnerability in its boot/update logic: durinEPSS 0.3%CVE-2022-3086HIGHCradlepoint IBR600 Command InjectionEPSS 0.3%CVE-2025-45512MEDIUMA lack of signature verification in the bootloader of DENX Software Engineering Das U-Boot (U-Boot) v1.1.3 allows attackers to install craftEPSS 0.3%CVE-2025-45317MEDIUMA zip slip vulnerability in the /modules/ImportModule.php component of hortusfox-web v4.4 allows attackers to execute arbitrary code via a cEPSS 0.3%CVE-2024-45989MEDIUMMonica AI Assistant desktop application v2.3.0 is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor. A prompt injectiEPSS 0.3%CVE-2025-54964HIGHAn issue was discovered in BAE SOCET GXP before 4.6.0.2. An attacker with the ability to interact with the GXP Job Service may inject arbitrEPSS 0.3%CVE-2025-52337MEDIUMAn authenticated arbitrary file upload vulnerability in the Content Explorer feature of LogicData eCommerce Framework v5.0.9.7000 allows attEPSS 0.3%CVE-2021-27702HIGHSercomm Router Etisalat Model S3- AC2100 is affected by Incorrect Access Control via the diagnostic utility in the router dashboard.EPSS 0.3%CVE-2022-20665MEDIUMCisco StarOS Command Injection VulnerabilityEPSS 0.3%CVE-2025-43948HIGHCodemers KLIMS 1.6.DEV allows Python code injection. A user can provide Python code as an input value for a parameter or qualifier (such as EPSS 0.3%CVE-2024-57337MEDIUMAn arbitrary file upload vulnerability in the opcode 500 functionality of M2Soft CROWNIX Report & ERS v5.x to v5.5.14.1070, v7.x to v7.4.3.9EPSS 0.3%CVE-2024-57338MEDIUMAn arbitrary file upload vulnerability in M2Soft CROWNIX Report & ERS v5.x to v5.5.14.1070, v7.x to v7.4.3.960, and v8.x to v8.2.0.345 allowEPSS 0.3%CVE-2025-26262MEDIUMAn issue in the component /internals/functions of R-fx Networks Linux Malware Detect v1.6.5 allows attackers to escalate privileges and execEPSS 0.3%CVE-2025-59376LOWfeiskyer mcp-kubernetes-server through 0.1.11 does not consider chained commands in the implementation of --disable-write and --disable-deleEPSS 0.3%CVE-2026-52473MEDIUMAn issue in Wgcloud 3.6.4 allows a remote attacker to escalate privileges via the content parameter is directly concatenated to the ProcessBEPSS 0.3%CVE-2025-60595HIGHSPH Engineering UgCS 5.13.0 is vulnerable to Arbitary code execution.EPSS 0.3%CVE-2025-59337MEDIUMDiscourse: Cross-Site Data Exposure via Backup Restore Metacommand Injection in Multisite DeploymentsEPSS 0.3%