Falhas do tipo CWE-77

2.829 resultados

Injeção de comando

O software monta comandos do sistema ou de interpretadores (shell, SQL, etc.) usando dados que vêm de fora (entrada do usuário, requisição HTTP, arquivo) sem sanitizar ou sanitizando incorretamente caracteres especiais. Um atacante consegue 'fechar' o comando legítimo e injetar comandos arbitrários que serão executados com os mesmos privilégios da aplicação.

Exemplo

Um script que executa `ping` no endereço fornecido pelo usuário: `system('ping ' + user_input)`. Se o usuário digita `8.8.8.8; rm -rf /`, o comando executado vira dois: primeiro o ping, depois a deleção de arquivos. A maioria das CVEs de injeção de comando vêm deste padrão.

Como mitigar

Use APIs que aceitam argumentos como lista (não concatenação de strings) — ex: subprocess.run(['ping', user_input]) em Python ou parameterized queries em banco de dados. Se precisar de interpretador, valide rigorosamente a entrada com lista branca (aceita apenas IP/domínio válido) e evite shells intermediários.

CVE-2024-39577HIGHDell SmartFabric OS10 Software, versions 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contains an Improper Neutralization of Special Elements useEPSS 0.9%CVE-2022-36786CRITICALDLINK - DSL-224 Post-auth RCE.EPSS 0.9%CVE-2025-48492HIGHGetSimple CMS RCE in Edit componentEPSS 0.9%CVE-2024-41136MEDIUMAuthenticated Command Injection in HPE Aruba Networking EdgeConnect SD-WAN Command Line InterfaceEPSS 0.9%CVE-2026-20761HIGHEnOcean SmartServer IoT Command InjectionEPSS 0.9%CVE-2025-41451HIGHPost-Authentication OS Command Injection RCE in Danfoss AK-SM8xxA SeriesEPSS 0.9%CVE-2025-30264HIGHQTS, QuTS heroEPSS 0.9%CVE-2023-28430HIGHOneSignal repository github action command injectionEPSS 0.9%CVE-2023-26125MEDIUMVersions of the package github.com/gin-gonic/gin before 1.9.0 are vulnerable to Improper Input Validation by allowing an attacker to use a sEPSS 0.9%CVE-2026-79682HIGHDell PowerStore contains a Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulEPSS 0.9%CVE-2026-78177LOWTanStack devtools-vite Development Devtools Event Bus package-manager.ts installPackage os command injectionEPSS 0.9%CVE-2024-39568HIGHA vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 HF1). The system service of affected applications iEPSS 0.9%CVE-2024-39567HIGHA vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 HF1). The system service of affected applications iEPSS 0.9%CVE-2023-29475CRITICALinventory in Atos Unify OpenScape 4000 Platform and OpenScape 4000 Manager Platform 10 R1 before 10 R1.34.4 allows an unauthenticated attackEPSS 0.9%CVE-2025-45493MEDIUMNetgear EX8000 V1.0.0.126 is vulnerable to Command Injection via the iface parameter in the action_bandwidth function.EPSS 0.9%CVE-2025-44015LOWHybridDesk StationEPSS 0.9%CVE-2026-78501HIGHMicrosoft 365 Copilot Business Chat Information Disclosure VulnerabilityEPSS 0.9%CVE-2025-25364HIGHA command injection vulnerability in the me.connectify.SMJobBlessHelper XPC service of Speedify VPN up to v15.0.0 allows attackers to executEPSS 0.9%CVE-2025-65720CRITICALAn issue in Open Source GPT Researcher v3.3.7 allows attackers to execute arbitrary commands on a victim system via user interaction with a EPSS 0.9%CVE-2024-20365MEDIUMCisco Integrated Management Controller Redfish Command Injection VulnerabilityEPSS 0.9%