Falhas do tipo CWE-77

2.834 resultados

Injeção de comando

O software monta comandos do sistema ou de interpretadores (shell, SQL, etc.) usando dados que vêm de fora (entrada do usuário, requisição HTTP, arquivo) sem sanitizar ou sanitizando incorretamente caracteres especiais. Um atacante consegue 'fechar' o comando legítimo e injetar comandos arbitrários que serão executados com os mesmos privilégios da aplicação.

Exemplo

Um script que executa `ping` no endereço fornecido pelo usuário: `system('ping ' + user_input)`. Se o usuário digita `8.8.8.8; rm -rf /`, o comando executado vira dois: primeiro o ping, depois a deleção de arquivos. A maioria das CVEs de injeção de comando vêm deste padrão.

Como mitigar

Use APIs que aceitam argumentos como lista (não concatenação de strings) — ex: subprocess.run(['ping', user_input]) em Python ou parameterized queries em banco de dados. Se precisar de interpretador, valide rigorosamente a entrada com lista branca (aceita apenas IP/domínio válido) e evite shells intermediários.

CVE-2026-40061HIGHiControl REST and tmsh vulnerabilityEPSS 0.4%CVE-2023-49587MEDIUMCommand Injection vulnerability in SAP Solution ManagerEPSS 0.4%CVE-2026-40698HIGHiControl REST and TMSH vulnerabilityEPSS 0.4%CVE-2025-55848HIGHAn issue was discovered in DIR-823 firmware 20250416. There is an RCE vulnerability in the set_cassword settings interface, as the http_cassEPSS 0.4%CVE-2025-51472MEDIUMCode Injection in AgentTemplate.eval_agent_config in TransformerOptimus SuperAGI 0.0.14 allows remote attackers to execute arbitrary Python EPSS 0.4%CVE-2025-61514MEDIUMAn arbitrary file upload vulnerability in SageMath, Inc CoCalc before commit 0d2ff58 allows attackers to execute arbitrary code via uploadinEPSS 0.4%CVE-2025-50891HIGHThe server-side backend for Adform Site Tracking before 2025-08-28 allows attackers to inject HTML or execute arbitrary code via cookie hijaEPSS 0.4%CVE-2024-4712HIGHArbitrary File Creation in PaperCut NG/MF Web Print Image HandlerEPSS 0.4%CVE-2026-42850HIGHKitty has a shell command injectionEPSS 0.4%CVE-2024-9579HIGHCertain Poly Video Conference Devices – Potential Remote Code ExecutionEPSS 0.4%CVE-2025-25792MEDIUMSeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the isopen parameter at admin_weixin.php.EPSS 0.4%CVE-2024-57608MEDIUMAn issue in Via Browser 6.1.0 allows a a remote attacker to execute arbitrary code via the mark.via.Shell component.EPSS 0.4%CVE-2025-27146LOWMatrix IRC Bridge allows IRC command injection to own puppeted userEPSS 0.4%CVE-2025-65657MEDIUMFeehiCMS version 2.1.1 has a Remote Code Execution via Unrestricted File Upload in Ad Management. FeehiCMS version 2.1.1 allows authenticateEPSS 0.4%CVE-2026-45628CRITICALDokploy: Command Injection via Unescaped Branch Fields in Deployment PipelineEPSS 0.4%CVE-2026-73454HIGHSecurity Advisory 0165EPSS 0.4%CVE-2019-16011HIGHCisco IOS XE SD-WAN Software Command Injection VulnerabilityEPSS 0.4%CVE-2026-55946MEDIUMMicrosoft Copilot Information Disclosure VulnerabilityEPSS 0.4%CVE-2024-51257HIGHDrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the EPSS 0.4%CVE-2024-51255CRITICALDrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the EPSS 0.4%