Fallos del tipo CWE-77
2831 resultadosInjeção de comando via entrada não sanitizada
O software constrói comandos (shell, SQL, LDAP, etc.) usando dados de entrada do usuário sem neutralizar caracteres especiais que alteram a semântica do comando. Um atacante injeta metacaracteres (como `;`, `|`, `$()`) para executar instruções não previstas.
Ejemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validação. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos, porque o ponto-e-vírgula encadeia comandos no shell.
Cómo mitigar
Use APIs de execução que separam dados de comando (ex: `execvp()` com array de argumentos em vez de shell, prepared statements para SQL). Se shell for inevitável, whitelist rigoroso de entrada e escape apropriado com `escapeshellarg()` ou equivalente na linguagem.
CVE-2026-47242MEDIUMNet::IMAP: Command Injection via ID command argumentEPSS 0.2%CVE-2025-22237MEDIUMCVE-2025-22237 salt advisoryEPSS 0.2%CVE-2025-33249HIGHNVIDIA NeMo Framework for all platforms contains a vulnerability in a voice-preprocessing script, where malicious input created by an attackEPSS 0.2%CVE-2025-20278MEDIUMCisco Unified Communications Products Command Injection VulnerabilityEPSS 0.2%CVE-2026-75052LOWIn JetBrains IntelliJ IDEA before 2026.2.1 command execution via crafted Markdown preview content was possible in trusted projectsEPSS 0.2%CVE-2026-21709MEDIUMA vulnerability allowing a local attacker with administrator privileges to bypass Windows Driver Signature Enforcement.EPSS 0.2%CVE-2025-27233MEDIUMZabbix Agent 2 smartctl plugin argument injection in Zabbix 6.0 and later.EPSS 0.2%CVE-2025-24333MEDIUMAdministrative user shell input validation faultEPSS 0.2%CVE-2025-56814HIGHA code injection vulnerability in the wxExecute() function of OpenCPN v5.12.0 allows attackers to execute arbitrary code via embedding shellEPSS 0.2%CVE-2026-59846LOWLibssh: libssh: information disclosure via proxycommand %r username expansionEPSS 0.2%CVE-2025-57521MEDIUMBambu Studio 2.1.1.52 and earlier is affected by a vulnerability that allows arbitrary code execution during application startup. The applicEPSS 0.2%CVE-2025-49823NONEConda Constructor Command Injection via Unsanitized User Input (Low)EPSS 0.2%CVE-2025-1549MEDIUMWatchGuard Mobile VPN with SSL Local Privilege EscallationEPSS 0.1%CVE-2025-65885MEDIUMAn issue was discovered in the Delight Custom Firmware (CFW) for Nokia Symbian Belle devices on Nokia 808 (Delight v1.8), Nokia N8 (Delight EPSS 0.1%CVE-2026-25046LOW[Kimi VS Code] Command Injection in publish scripts vsix-publish.js and ovsx-publish.jsEPSS 0.1%CVE-2025-60855MEDIUMReolink Video Doorbell WiFi DB_566128M5MP_W performs insufficient validation of firmware update signatures. This allows attackers to load maEPSS 0.1%CVE-2026-102827HIGHsimple-git: unsafe-operations plugin bypass via git long-option abbreviation (--receive-p/--exe) -> command execution (residual of CVE-2026-28291)EPSS —CVE-2026-102240CRITICALNetcore NAP930 Network Tools CGI network_tools eval os command injectionEPSS —CVE-2026-101262CRITICALZiroom ZHOME A0101 set_online_client command injectionEPSS —CVE-2026-101187CRITICALZiroom ZHOME A0101 USB Device Management API zrUsb.lua pop_usb_device command injectionEPSS —