Falhas do tipo CWE-77

2.834 resultados

Injeção de comando

O software monta comandos do sistema ou de interpretadores (shell, SQL, etc.) usando dados que vêm de fora (entrada do usuário, requisição HTTP, arquivo) sem sanitizar ou sanitizando incorretamente caracteres especiais. Um atacante consegue 'fechar' o comando legítimo e injetar comandos arbitrários que serão executados com os mesmos privilégios da aplicação.

Exemplo

Um script que executa `ping` no endereço fornecido pelo usuário: `system('ping ' + user_input)`. Se o usuário digita `8.8.8.8; rm -rf /`, o comando executado vira dois: primeiro o ping, depois a deleção de arquivos. A maioria das CVEs de injeção de comando vêm deste padrão.

Como mitigar

Use APIs que aceitam argumentos como lista (não concatenação de strings) — ex: subprocess.run(['ping', user_input]) em Python ou parameterized queries em banco de dados. Se precisar de interpretador, valide rigorosamente a entrada com lista branca (aceita apenas IP/domínio válido) e evite shells intermediários.

CVE-2026-21639HIGHA malicious actor in Wi-Fi range of the affected product could leverage a vulnerability in the airMAX Wireless Protocol to achieve a remote EPSS 0.4%CVE-2024-23247HIGHThe issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS Ventura 13.6.5EPSS 0.4%CVE-2025-46365MEDIUMDell CloudLink, versions prior 8.1.1, contain a Command Injection vulnerability which can be exploited by an Authenticated attacker to causeEPSS 0.4%CVE-2025-29083MEDIUMSQL Injection vulnerability in CSZ-CMS v.1.3.0 allows a remote attacker to execute arbitrary code via the execSqlFile function in the PluginEPSS 0.4%CVE-2022-29256MEDIUMPossible vulnerability at 'npm install' time in sharp if an attacker has control over build environmentEPSS 0.4%CVE-2022-34432HIGHDell Hybrid Client below 1.8 version contains a gedit vulnerability. A guest attacker could potentially exploit this vulnerability, allowingEPSS 0.4%CVE-2024-12111HIGHPotential LDAP injection vulnerability in OpenText Privileged Access ManagerEPSS 0.4%CVE-2026-75004MEDIUMIn Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper rule name quoting could lead to managesieve_disabled_actions setting bypEPSS 0.4%CVE-2023-51295MEDIUMPHPJabbers Event Booking Calendar v4.0 is vulnerable to Multiple HTML Injection in the "name, plugin_sms_api_key, plugin_sms_country_code, tEPSS 0.4%CVE-2024-28328MEDIUMCSV Injection vulnerability in the Asus RT-N12+ router allows administrator users to inject arbitrary commands or formulas in the client namEPSS 0.4%CVE-2023-0978MEDIUM A command injection vulnerability in Trellix Intelligent Sandbox CLI for version 5.2 and earlier, allows a local user to inject and executeEPSS 0.4%CVE-2026-24169HIGHNVIDIA UFM Enterprise contains a vulnerability in the plugin management API, where an authenticated user with low privileges could inject coEPSS 0.4%CVE-2025-15367MEDIUMPOP3 command injection in user-controlled commandsEPSS 0.4%CVE-2026-22601HIGHOpenProject is Vulnerable to Code Execution in E-Mail functionEPSS 0.4%CVE-2025-20306MEDIUMCisco Secure Firewall Management Center Software Command Injection VulnerabilityEPSS 0.4%CVE-2025-46176MEDIUMHardcoded credentials in the Telnet service in D-Link DIR-605L v2.13B01 and DIR-816L v2.06B01 allow attackers to remotely execute arbitrary EPSS 0.4%CVE-2025-61584CRITICALserverless-dns is vulnerable to Command Injection through pr.yml GitHub Action WorkflowEPSS 0.4%CVE-2021-34726MEDIUMCisco SD-WAN Software Command Injection VulnerabilityEPSS 0.4%CVE-2025-27953MEDIUMAn issue in Clinical Collaboration Platform 12.2.1.5 allows a remote attacker to obtain sensitive information and execute arbitrary code viaEPSS 0.4%CVE-2024-55466MEDIUMAn arbitrary file upload vulnerability in the Image Gallery of ThingsBoard Community, ThingsBoard Cloud and ThingsBoard Professional v3.8.1 EPSS 0.4%