Falhas do tipo CWE-77

2.829 resultados

Injeção de comando

O software monta comandos do sistema ou de interpretadores (shell, SQL, etc.) usando dados que vêm de fora (entrada do usuário, requisição HTTP, arquivo) sem sanitizar ou sanitizando incorretamente caracteres especiais. Um atacante consegue 'fechar' o comando legítimo e injetar comandos arbitrários que serão executados com os mesmos privilégios da aplicação.

Exemplo

Um script que executa `ping` no endereço fornecido pelo usuário: `system('ping ' + user_input)`. Se o usuário digita `8.8.8.8; rm -rf /`, o comando executado vira dois: primeiro o ping, depois a deleção de arquivos. A maioria das CVEs de injeção de comando vêm deste padrão.

Como mitigar

Use APIs que aceitam argumentos como lista (não concatenação de strings) — ex: subprocess.run(['ping', user_input]) em Python ou parameterized queries em banco de dados. Se precisar de interpretador, valide rigorosamente a entrada com lista branca (aceita apenas IP/domínio válido) e evite shells intermediários.

CVE-2024-51260CRITICALDrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the EPSS 0.6%CVE-2021-38116HIGHPossible Command injection Vulnerability in OpenText iManagerEPSS 0.6%CVE-2026-81380MEDIUMGitHub Copilot and Visual Studio Code Information Disclosure VulnerabilityEPSS 0.6%CVE-2025-11921HIGHiStat Menus 7.10.4 - Local Privilege EscalationEPSS 0.6%CVE-2024-34347HIGH@hoppscotch/cli affected by Sandbox Escape in @hoppscotch/js-sandbox leads to RCEEPSS 0.6%CVE-2025-55283CRITICALaiven-db-migrate allows Privilege Escalation through use of psql during migrationEPSS 0.6%CVE-2025-32702HIGHVisual Studio Remote Code Execution VulnerabilityEPSS 0.6%CVE-2024-51296HIGHIn Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the piEPSS 0.6%CVE-2024-51299HIGHIn Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the duEPSS 0.6%CVE-2024-51301HIGHIn Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the paEPSS 0.6%CVE-2026-30616HIGHJaaz 1.0.30 contains a remote code execution vulnerability in its MCP STDIO command execution handling. A remote attacker can send crafted nEPSS 0.6%CVE-2024-51300HIGHIn Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the geEPSS 0.6%CVE-2024-51304HIGHIn Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the ldEPSS 0.6%CVE-2018-5412—Imperva SecureSphere running v12.0.0.50 is vulnerable to local arbitrary code execution, escaping sealed-mode.EPSS 0.6%CVE-2020-3207MEDIUMCisco IOS XE Software Command Injection VulnerabilityEPSS 0.6%CVE-2025-53774MEDIUMMicrosoft 365 Copilot BizChat Information Disclosure VulnerabilityEPSS 0.6%CVE-2025-54416CRITICALtj-actions/branch-names Contains Command Injection VulnerabilityEPSS 0.6%CVE-2026-45497HIGHMicrosoft M365 Copilot Remote Code Execution VulnerabilityEPSS 0.6%CVE-2026-86427HIGHLibreNMS before 26.8.0 Argument Injection via graph_titleEPSS 0.6%CVE-2024-28729HIGHAn issue in DLink DWR 2000M 5G CPE With Wifi 6 Ax1800 and Dlink DWR 5G CPE DWR-2000M_1.34ME allows a local attacker to execute arbitrary codEPSS 0.6%