Fallos del tipo CWE-77
2810 resultadosInjeção de comando via entrada não sanitizada
O software constrói comandos (shell, SQL, LDAP, etc.) usando dados de entrada do usuário sem neutralizar caracteres especiais que alteram a semântica do comando. Um atacante injeta metacaracteres (como `;`, `|`, `$()`) para executar instruções não previstas.
Ejemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validação. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos, porque o ponto-e-vírgula encadeia comandos no shell.
Cómo mitigar
Use APIs de execução que separam dados de comando (ex: `execvp()` com array de argumentos em vez de shell, prepared statements para SQL). Se shell for inevitável, whitelist rigoroso de entrada e escape apropriado com `escapeshellarg()` ou equivalente na linguagem.
CVE-2025-22630CRITICALWordPress Widget Options Plugin <= 4.1.0 - Arbitrary Code Execution vulnerabilityEPSS 1.1%CVE-2023-26130HIGHVersions of the package yhirose/cpp-httplib before 0.12.4 are vulnerable to CRLF Injection when untrusted user input is used to set the contEPSS 1.1%CVE-2023-41334HIGHastropy vulnerable to RCE in TranformGraph().to_dot_graph functionEPSS 1.1%CVE-2025-54377HIGHRoo Code Lacks Line Break Validation in its Command Execution ToolEPSS 1.1%CVE-2025-10767LOWCosmodiumCS OnlyRAT Configuration File main.py remote_download os command injectionEPSS 1.1%CVE-2024-48659CRITICALAn issue in DCME-320-L <=9.3.2.114 allows a remote attacker to execute arbitrary code via the log_u_umount.php component.EPSS 1.1%CVE-2023-45025CRITICALQTS, QuTS hero, QuTScloudEPSS 1.1%CVE-2023-47560HIGHQuMagieEPSS 1.1%CVE-2025-62696MEDIUMMultiple critical security issues in SpringboardEPSS 1.1%CVE-2020-15874HIGHAn issue was discovered in LibreNMS 1.65. A remote authenticated attacker with normal privileges can execute arbitrary shell commands througEPSS 1.1%CVE-2020-36198MEDIUMCommand Injection Vulnerability in Malware RemoverEPSS 1.1%CVE-2025-52903HIGHFile Browser Allows Execution of Shell Commands That Can Spawn Other CommandsEPSS 1.1%CVE-2025-46122CRITICALAn issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, where the authenticated diagnostics API eEPSS 1.1%CVE-2024-55063HIGHMultiple Code Injection vulnerabilities in EasyVirt DC NetScope <= 8.7.0 allows remote authenticated attackers to execute arbitrary code viaEPSS 1.1%CVE-2026-20094HIGHCisco Integrated Management Controller Command Injection VulnerabilityEPSS 1.1%CVE-2024-29737HIGHApache StreamPark (incubating): maven build params could trigger remote command executionEPSS 1.1%CVE-2024-55414CRITICALA vulnerability exits in driver SmSerl64.sys in Motorola SM56 Modem WDM Driver v6.12.23.0, which allows low-privileged users to mapping physEPSS 1.1%CVE-2024-57590CRITICALTRENDnet TEW-632BRP v1.010B31 devices have an OS command injection vulnerability in the CGl interface "ntp_sync.cgi",which allows remote attEPSS 1.1%CVE-2025-61141HIGHsqls-server/sqls 0.2.28 is vulnerable to command injection in the config command because the openEditor function passes the EDITOR environmeEPSS 1.1%CVE-2026-11408MEDIUMvertex-app vertex Log Viewer Endpoint LogMod.js os command injectionEPSS 1.1%