Fallos del tipo CWE-77

2829 resultados

Injeção de comando via entrada não sanitizada

O software constrói comandos (shell, SQL, LDAP, etc.) usando dados de entrada do usuário sem neutralizar caracteres especiais que alteram a semântica do comando. Um atacante injeta metacaracteres (como `;`, `|`, `$()`) para executar instruções não previstas.

Ejemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validação. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos, porque o ponto-e-vírgula encadeia comandos no shell.

Cómo mitigar

Use APIs de execução que separam dados de comando (ex: `execvp()` com array de argumentos em vez de shell, prepared statements para SQL). Se shell for inevitável, whitelist rigoroso de entrada e escape apropriado com `escapeshellarg()` ou equivalente na linguagem.

CVE-2018-0351—A vulnerability in the command-line tcpdump utility in the Cisco SD-WAN Solution could allow an authenticated, local attacker to inject arbiEPSS 0.5%CVE-2023-37154HIGHcheck_by_ssh in Nagios nagios-plugins 2.4.5 allows arbitrary command execution via ProxyCommand, LocalCommand, and PermitLocalCommand with \EPSS 0.5%CVE-2024-29404HIGHAn issue in Razer Synapse 3 v.3.9.131.20813 and Synapse 3 App v.20240213 allows a local attacker to execute arbitrary code via the export paEPSS 0.5%CVE-2019-1781MEDIUMCisco FXOS and NX-OS Software Command Injection VulnerabilityEPSS 0.5%CVE-2019-1790MEDIUMCisco NX-OS Software Command Injection VulnerabilityEPSS 0.5%CVE-2019-1782MEDIUMCisco FXOS and NX-OS Software Command Injection VulnerabilityEPSS 0.5%CVE-2024-41815HIGHStarship vulnerable to shell injection via undocumented, unpredictable shell expansion in custom commandsEPSS 0.5%CVE-2025-60801HIGHjshERP up to commit fbda24da was discovered to contain an unauthenticated remote code execution (RCE) vulnerability via the jsh_erp functionEPSS 0.5%CVE-2026-57130HIGHPraisonAI: IMAP Command Injection via Unsanitized Email Search ParametersEPSS 0.5%CVE-2026-20163HIGHRemote Command Execution (RCE) through the '/splunkd/__upload/indexing/preview' REST endpoint in Splunk EnterpriseEPSS 0.5%CVE-2026-32183HIGHWindows Snipping Tool Remote Code Execution VulnerabilityEPSS 0.5%CVE-2023-20170MEDIUMA vulnerability in a specific Cisco ISE CLI command could allow an authenticated, local attacker to perform command injection attacks on theEPSS 0.5%CVE-2026-65656HIGHMicrosoft Office Remote Code Execution VulnerabilityEPSS 0.5%CVE-2023-2491HIGHA flaw was found in the Emacs text editor. Processing a specially crafted org-mode code with the "org-babel-execute:latex" function in ob-laEPSS 0.5%CVE-2026-72904CRITICALFirecrawl: Arbitrary file read via JSON Schema $ref expansionEPSS 0.5%CVE-2024-51772MEDIUMAuthenticated Deserialization Vulnerability in ClearPass Policy Manager Web-Based Management Interface Leading to a Remote Command Execution (RCE)EPSS 0.5%CVE-2021-3515—A shell injection flaw was found in pglogical in versions before 2.3.4 and before 3.6.26. An attacker with CREATEDB privileges on a PostgreSEPSS 0.5%CVE-2025-69201HIGHTugtainer has RCE in Agent Command Execution ApiEPSS 0.5%CVE-2019-1612MEDIUMCisco NX-OS Software CLI Command Injection Vulnerability (CVE-2019-1612)EPSS 0.5%CVE-2022-20345MEDIUMIn l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote coEPSS 0.5%