Falhas do tipo CWE-77

2.831 resultados

Injeção de comando

O software monta comandos do sistema ou de interpretadores (shell, SQL, etc.) usando dados que vêm de fora (entrada do usuário, requisição HTTP, arquivo) sem sanitizar ou sanitizando incorretamente caracteres especiais. Um atacante consegue 'fechar' o comando legítimo e injetar comandos arbitrários que serão executados com os mesmos privilégios da aplicação.

Exemplo

Um script que executa `ping` no endereço fornecido pelo usuário: `system('ping ' + user_input)`. Se o usuário digita `8.8.8.8; rm -rf /`, o comando executado vira dois: primeiro o ping, depois a deleção de arquivos. A maioria das CVEs de injeção de comando vêm deste padrão.

Como mitigar

Use APIs que aceitam argumentos como lista (não concatenação de strings) — ex: subprocess.run(['ping', user_input]) em Python ou parameterized queries em banco de dados. Se precisar de interpretador, valide rigorosamente a entrada com lista branca (aceita apenas IP/domínio válido) e evite shells intermediários.

CVE-2018-0347—A vulnerability in the Zero Touch Provisioning (ZTP) subsystem of the Cisco SD-WAN Solution could allow an authenticated, local attacker to EPSS 0.5%CVE-2023-37154HIGHcheck_by_ssh in Nagios nagios-plugins 2.4.5 allows arbitrary command execution via ProxyCommand, LocalCommand, and PermitLocalCommand with \EPSS 0.5%CVE-2024-29404HIGHAn issue in Razer Synapse 3 v.3.9.131.20813 and Synapse 3 App v.20240213 allows a local attacker to execute arbitrary code via the export paEPSS 0.5%CVE-2019-1781MEDIUMCisco FXOS and NX-OS Software Command Injection VulnerabilityEPSS 0.5%CVE-2019-1782MEDIUMCisco FXOS and NX-OS Software Command Injection VulnerabilityEPSS 0.5%CVE-2024-41815HIGHStarship vulnerable to shell injection via undocumented, unpredictable shell expansion in custom commandsEPSS 0.5%CVE-2019-1790MEDIUMCisco NX-OS Software Command Injection VulnerabilityEPSS 0.5%CVE-2026-65656HIGHMicrosoft Office Remote Code Execution VulnerabilityEPSS 0.5%CVE-2025-60801HIGHjshERP up to commit fbda24da was discovered to contain an unauthenticated remote code execution (RCE) vulnerability via the jsh_erp functionEPSS 0.5%CVE-2023-20170MEDIUMA vulnerability in a specific Cisco ISE CLI command could allow an authenticated, local attacker to perform command injection attacks on theEPSS 0.5%CVE-2026-57130HIGHPraisonAI: IMAP Command Injection via Unsanitized Email Search ParametersEPSS 0.5%CVE-2026-20163HIGHRemote Command Execution (RCE) through the '/splunkd/__upload/indexing/preview' REST endpoint in Splunk EnterpriseEPSS 0.5%CVE-2026-32183HIGHWindows Snipping Tool Remote Code Execution VulnerabilityEPSS 0.5%CVE-2023-2491HIGHA flaw was found in the Emacs text editor. Processing a specially crafted org-mode code with the "org-babel-execute:latex" function in ob-laEPSS 0.5%CVE-2026-72904CRITICALFirecrawl: Arbitrary file read via JSON Schema $ref expansionEPSS 0.5%CVE-2025-69201HIGHTugtainer has RCE in Agent Command Execution ApiEPSS 0.5%CVE-2024-51772MEDIUMAuthenticated Deserialization Vulnerability in ClearPass Policy Manager Web-Based Management Interface Leading to a Remote Command Execution (RCE)EPSS 0.5%CVE-2021-3515—A shell injection flaw was found in pglogical in versions before 2.3.4 and before 3.6.26. An attacker with CREATEDB privileges on a PostgreSEPSS 0.5%CVE-2019-1612MEDIUMCisco NX-OS Software CLI Command Injection Vulnerability (CVE-2019-1612)EPSS 0.5%CVE-2022-20345MEDIUMIn l2cble_process_sig_cmd of l2c_ble.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote coEPSS 0.5%