Falhas do tipo CWE-77

2.829 resultados

Injeção de comando

O software monta comandos do sistema ou de interpretadores (shell, SQL, etc.) usando dados que vêm de fora (entrada do usuário, requisição HTTP, arquivo) sem sanitizar ou sanitizando incorretamente caracteres especiais. Um atacante consegue 'fechar' o comando legítimo e injetar comandos arbitrários que serão executados com os mesmos privilégios da aplicação.

Exemplo

Um script que executa `ping` no endereço fornecido pelo usuário: `system('ping ' + user_input)`. Se o usuário digita `8.8.8.8; rm -rf /`, o comando executado vira dois: primeiro o ping, depois a deleção de arquivos. A maioria das CVEs de injeção de comando vêm deste padrão.

Como mitigar

Use APIs que aceitam argumentos como lista (não concatenação de strings) — ex: subprocess.run(['ping', user_input]) em Python ou parameterized queries em banco de dados. Se precisar de interpretador, valide rigorosamente a entrada com lista branca (aceita apenas IP/domínio válido) e evite shells intermediários.

CVE-2026-86427HIGHLibreNMS before 26.8.0 Argument Injection via graph_titleEPSS 0.6%CVE-2025-26331HIGHDell ThinOS 2411 and prior, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. AEPSS 0.6%CVE-2026-43830CRITICALtbcEPSS 0.6%CVE-2024-35401MEDIUMTOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a command injection vulnerability via the FileName parameter in the UploadFEPSS 0.6%CVE-2026-83948HIGHMicrosoft Azure CLI Remote Code Execution VulnerabilityEPSS 0.6%CVE-2025-4010HIGHArbitrary Command Injection in Netcom NTC-6200 & NWL-222EPSS 0.6%CVE-2025-52995HIGHFile Browser vulnerable to command execution allowlist bypassEPSS 0.6%CVE-2025-23170MEDIUMThe Versa Director SD-WAN orchestration platform includes functionality to initiate SSH sessions to remote CPEs and the Director shell via SEPSS 0.6%CVE-2026-30624HIGHAgent Zero 0.9.8 contains a remote code execution vulnerability in its External MCP Servers configuration feature. The application allows usEPSS 0.6%CVE-2024-53526MEDIUMcomposio >=0.5.40 is vulnerable to Command Execution in composio_openai, composio_claude, and composio_julep via the handle_tool_calls functEPSS 0.6%CVE-2025-67436MEDIUMAuthenticated Remote Code Execution (RCE) in PluXml CMS 5.8.22 allows an attacker with administrator panel access to inject a malicious PHP EPSS 0.6%CVE-2024-42348CRITICALFOG leaks sensitive information (AD domain, username and password)EPSS 0.6%CVE-2020-13712HIGHMGOS Command InjectionEPSS 0.6%CVE-2025-40937HIGHA vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected application do not properly validate input paraEPSS 0.6%CVE-2024-42360CRITICALCommand Injection in sequenceserverEPSS 0.6%CVE-2024-53305HIGHAn issue in the component /models/config.py of Whoogle search v0.9.0 allows attackers to execute arbitrary code via supplying a crafted searEPSS 0.6%CVE-2025-27211HIGHAn Improper Input Validation in EdgeMAX EdgeSwitch (Version 1.10.4 and earlier) could allow a Command Injection by a malicious actor with acEPSS 0.6%CVE-2025-29509HIGHJan v0.5.14 and before is vulnerable to remote code execution (RCE) when the user clicks on a rendered link in the conversation, due to openEPSS 0.6%CVE-2026-23652CRITICALMicrosoft Power Pages Remote Code Execution VulnerabilityEPSS 0.6%CVE-2024-46089MEDIUM74cms <=3.33 is vulnerable to remote code execution (RCE) in the background interface apiadmin.EPSS 0.6%