Fallos del tipo CWE-77

2825 resultados

Injeção de comando via entrada não sanitizada

O software constrói comandos (shell, SQL, LDAP, etc.) usando dados de entrada do usuário sem neutralizar caracteres especiais que alteram a semântica do comando. Um atacante injeta metacaracteres (como `;`, `|`, `$()`) para executar instruções não previstas.

Ejemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validação. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos, porque o ponto-e-vírgula encadeia comandos no shell.

Cómo mitigar

Use APIs de execução que separam dados de comando (ex: `execvp()` com array de argumentos em vez de shell, prepared statements para SQL). Se shell for inevitável, whitelist rigoroso de entrada e escape apropriado com `escapeshellarg()` ou equivalente na linguagem.

CVE-2025-9161HIGHRockwell Automation FactoryTalk Optix Remote Code Execution VulnerabilityEPSS 0.5%CVE-2026-42000MEDIUMInsufficient Validation of Names During AXFREPSS 0.5%CVE-2026-48116HIGHAnythingLLM: RCE via ripgrep --pre argument injection in filesystem-search-files agent skillEPSS 0.5%CVE-2022-35503HIGHImproper verification of a user input in Open Source MANO v7-v12 allows an authenticated attacker to execute arbitrary code within the LCM mEPSS 0.5%CVE-2026-73704HIGHAuthenticated Command Injection Leading to Administrative Access in HPE Networking Fabric Composer APIEPSS 0.5%CVE-2021-38120MEDIUMRemote Code Execution using Bash command Injection in backup scheduling functionality in NetIQ Advance AuthenticationEPSS 0.5%CVE-2021-0252HIGHJunos OS: NFX Series: Local Code Execution Vulnerability in JDMD Leads to Privilege EscalationEPSS 0.5%CVE-2025-29157MEDIUMAn issue in petstore v.1.0.7 allows a remote attacker to execute arbitrary code via accessing a non-existent endpoint/cart, the server returEPSS 0.5%CVE-2022-37704MEDIUMAmanda 3.5.1 allows privilege escalation from the regular user backup to root. The SUID binary located at /lib/amanda/rundump will execute /EPSS 0.5%CVE-2025-52365HIGHA command injection vulnerability in the szc script of the ccurtsinger/stabilizer repository allows remote attackers to execute arbitrary syEPSS 0.5%CVE-2024-44383HIGHWAYOS FBM-291W v19.09.11 is vulnerable to Command Execution via msp_info_htm.EPSS 0.5%CVE-2024-12251HIGHImproper neutralization special element in hyperlinksEPSS 0.5%CVE-2026-55145MEDIUMOutlook Copilot Tampering VulnerabilityEPSS 0.5%CVE-2026-53533MEDIUMaiosmtplib: SMTP command injection via CR/LF in sender/recipient addressEPSS 0.5%CVE-2026-47708CRITICALMCP-for-Stata: Command injection via log_file_name parameter in Stata command wrapperEPSS 0.5%CVE-2026-47690HIGHMeltanoHub vulnerable to command injection in the `test_dispatcher` GitHub Actions workflowEPSS 0.5%CVE-2026-23779MEDIUMDell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release verEPSS 0.5%CVE-2019-1735MEDIUMCisco NX-OS Software Command Injection Vulnerability (CVE-2019-1735)EPSS 0.5%CVE-2024-38817MEDIUMVMware NSX contains a command injection vulnerability.  A malicious actor with access to the NSX Edge CLI terminal may be able to craft malEPSS 0.5%CVE-2026-42257MEDIUMnet-imap: Command Injection via "raw" arguments to multiple commandsEPSS 0.5%