Falhas do tipo CWE-77

2.831 resultados

Injeção de comando

O software monta comandos do sistema ou de interpretadores (shell, SQL, etc.) usando dados que vêm de fora (entrada do usuário, requisição HTTP, arquivo) sem sanitizar ou sanitizando incorretamente caracteres especiais. Um atacante consegue 'fechar' o comando legítimo e injetar comandos arbitrários que serão executados com os mesmos privilégios da aplicação.

Exemplo

Um script que executa `ping` no endereço fornecido pelo usuário: `system('ping ' + user_input)`. Se o usuário digita `8.8.8.8; rm -rf /`, o comando executado vira dois: primeiro o ping, depois a deleção de arquivos. A maioria das CVEs de injeção de comando vêm deste padrão.

Como mitigar

Use APIs que aceitam argumentos como lista (não concatenação de strings) — ex: subprocess.run(['ping', user_input]) em Python ou parameterized queries em banco de dados. Se precisar de interpretador, valide rigorosamente a entrada com lista branca (aceita apenas IP/domínio válido) e evite shells intermediários.

CVE-2018-0477—Cisco IOS XE Software Command Injection VulnerabilitiesEPSS 0.5%CVE-2026-45585MEDIUMWindows BitLocker Security Feature Bypass VulnerabilityEPSS 0.5%CVE-2024-23971HIGHChargePoint Home Flex OCPP bswitch Command InjectionEPSS 0.5%CVE-2024-4578HIGHPrivilege escalation in Arista Wireless Access PointsEPSS 0.5%CVE-2025-29154MEDIUMHTML injection vulnerability in lemeconsultoria HCM galera.app v.4.58.0 allows an attacker to execute arbitrary code via the .galera.app/tedEPSS 0.5%CVE-2026-4786HIGHIncomplete mitigation of CVE-2026-4519, %action expansion for command injection to webbrowser.open()EPSS 0.5%CVE-2025-59458HIGHIn JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54, 251.284.54, 251.28EPSS 0.5%CVE-2023-42136HIGHPAX Android based POS devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow the execution of arbitrary commands witEPSS 0.5%CVE-2024-48139HIGHA prompt injection vulnerability in the chatbox of Blackbox AI v1.3.95 allows attackers to access and exfiltrate all previous and subsequentEPSS 0.5%CVE-2025-54131MEDIUMCursor bypasses its allow list to execute arbitrary commandsEPSS 0.5%CVE-2019-1795MEDIUMCisco FXOS and NX-OS Software Command Injection VulnerabilityEPSS 0.5%CVE-2019-1784MEDIUMCisco NX-OS Software Command Injection VulnerabilityEPSS 0.5%CVE-2019-1783MEDIUMCisco NX-OS Software Command Injection VulnerabilityEPSS 0.5%CVE-2025-56406HIGHAn issue was discovered in mcp-neo4j 0.3.0 allowing attackers to obtain sensitive information or execute arbitrary commands via the SSE servEPSS 0.5%CVE-2023-5752MEDIUMMercurial configuration injectable in repo revision when installing via pipEPSS 0.5%CVE-2019-1923MEDIUMCisco Small Business SPA500 Series IP Phones Local Command Execution VulnerabilityEPSS 0.5%CVE-2026-73763HIGHUnauthenticated Remote Command Execution in Management ComponentEPSS 0.5%CVE-2024-44570HIGHRELY-PCIe v22.2.1 to v23.1.0 was discovered to contain a code injection vulnerability via the getParams function in phpinf.php.EPSS 0.5%CVE-2019-1606MEDIUMCisco NX-OS Software CLI Command Injection Vulnerability (CVE-2019-1606)EPSS 0.5%CVE-2018-0351—A vulnerability in the command-line tcpdump utility in the Cisco SD-WAN Solution could allow an authenticated, local attacker to inject arbiEPSS 0.5%