Falhas do tipo CWE-77

2.829 resultados

Injeção de comando

O software monta comandos do sistema ou de interpretadores (shell, SQL, etc.) usando dados que vêm de fora (entrada do usuário, requisição HTTP, arquivo) sem sanitizar ou sanitizando incorretamente caracteres especiais. Um atacante consegue 'fechar' o comando legítimo e injetar comandos arbitrários que serão executados com os mesmos privilégios da aplicação.

Exemplo

Um script que executa `ping` no endereço fornecido pelo usuário: `system('ping ' + user_input)`. Se o usuário digita `8.8.8.8; rm -rf /`, o comando executado vira dois: primeiro o ping, depois a deleção de arquivos. A maioria das CVEs de injeção de comando vêm deste padrão.

Como mitigar

Use APIs que aceitam argumentos como lista (não concatenação de strings) — ex: subprocess.run(['ping', user_input]) em Python ou parameterized queries em banco de dados. Se precisar de interpretador, valide rigorosamente a entrada com lista branca (aceita apenas IP/domínio válido) e evite shells intermediários.

CVE-2025-0593HIGHSICK Lector8xx and InspectorP8xx vulnerable for code executionEPSS 0.8%CVE-2026-20176CRITICALCisco Identity Services Engine Remote Code Execution VulnerabilityEPSS 0.8%CVE-2024-36073HIGHNetwrix CoSoSys Endpoint Protector through 5.9.3 and CoSoSys Unify through 7.0.6 contain a remote code execution vulnerability in the shadowEPSS 0.8%CVE-2023-28677CRITICALJenkins Convert To Pipeline Plugin 1.0 and earlier uses basic string concatenation to convert Freestyle projects' Build Environment, Build SEPSS 0.8%CVE-2025-50722CRITICALInsecure Permissions vulnerability in sparkshop v.1.1.7 allows a remote attacker to execute arbitrary code via the Common.php componentEPSS 0.8%CVE-2025-29230HIGHLinksys E5600 v1.1.0.26 was discovered to contain a command injection vulnerability in the runtime.emailReg function. The vulnerability can EPSS 0.8%CVE-2026-75161HIGHAn issue in the ugw-restart method of /cgi-bin/wwwugw.cgi in MBS-Solutions X-Serie Gateway firmware V6_00_05 allows a remote authenticated uEPSS 0.8%CVE-2025-25691MEDIUMA PHAR deserialization vulnerability in the component /themes/import of PrestaShop v8.2.0 allows attackers to execute arbitrary code via a cEPSS 0.8%CVE-2026-32622HIGHSQLBot: Remote Code Execution via Terminology PoisoningEPSS 0.8%CVE-2023-52038CRITICALAn issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415C80 function.EPSS 0.8%CVE-2023-52039CRITICALAn issue discovered in TOTOLINK X6000R v9.4.0cu.852_B20230719 allows attackers to run arbitrary commands via the sub_415AA4 function.EPSS 0.8%CVE-2024-48746CRITICALAn issue in Lens Visual integration with Power BI v.4.0.0.3 allows a remote attacker to execute arbitrary code via the Natural language procEPSS 0.8%CVE-2024-9145HIGHLocal command injection in Wiz Code Visual Studio Code extensionEPSS 0.8%CVE-2026-41497CRITICALIncomplete fix for CVE-2026-34935: Command Injection in MervinPraison/PraisonAIEPSS 0.8%CVE-2024-13871CRITICALUnauthenticated Command Injection in Bitdefender BOX v1EPSS 0.8%CVE-2025-67397CRITICALAn issue in Passy v.1.6.3 allows a remote authenticated attacker to execute arbitrary commands via a crafted HTTP request using a specific pEPSS 0.8%CVE-2024-51771HIGHAuthenticated Remote Code Execution (RCE) via OGNL Injection in HPE Aruba Networking ClearPass Web-Based Management InterfaceEPSS 0.8%CVE-2025-23239HIGHBIG-IP iControl REST vulnerabilityEPSS 0.8%CVE-2024-48861HIGHQHoraEPSS 0.8%CVE-2026-41090CRITICALMicrosoft Copilot Tampering VulnerabilityEPSS 0.8%