Falhas do tipo CWE-77

2.836 resultados

Injeção de comando

O software monta comandos do sistema ou de interpretadores (shell, SQL, etc.) usando dados que vêm de fora (entrada do usuário, requisição HTTP, arquivo) sem sanitizar ou sanitizando incorretamente caracteres especiais. Um atacante consegue 'fechar' o comando legítimo e injetar comandos arbitrários que serão executados com os mesmos privilégios da aplicação.

Exemplo

Um script que executa `ping` no endereço fornecido pelo usuário: `system('ping ' + user_input)`. Se o usuário digita `8.8.8.8; rm -rf /`, o comando executado vira dois: primeiro o ping, depois a deleção de arquivos. A maioria das CVEs de injeção de comando vêm deste padrão.

Como mitigar

Use APIs que aceitam argumentos como lista (não concatenação de strings) — ex: subprocess.run(['ping', user_input]) em Python ou parameterized queries em banco de dados. Se precisar de interpretador, valide rigorosamente a entrada com lista branca (aceita apenas IP/domínio válido) e evite shells intermediários.

CVE-2022-34432HIGHDell Hybrid Client below 1.8 version contains a gedit vulnerability. A guest attacker could potentially exploit this vulnerability, allowingEPSS 0.4%CVE-2026-75004MEDIUMIn Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper rule name quoting could lead to managesieve_disabled_actions setting bypEPSS 0.4%CVE-2023-51295MEDIUMPHPJabbers Event Booking Calendar v4.0 is vulnerable to Multiple HTML Injection in the "name, plugin_sms_api_key, plugin_sms_country_code, tEPSS 0.4%CVE-2024-28328MEDIUMCSV Injection vulnerability in the Asus RT-N12+ router allows administrator users to inject arbitrary commands or formulas in the client namEPSS 0.4%CVE-2023-0978MEDIUM A command injection vulnerability in Trellix Intelligent Sandbox CLI for version 5.2 and earlier, allows a local user to inject and executeEPSS 0.4%CVE-2025-15367MEDIUMPOP3 command injection in user-controlled commandsEPSS 0.4%CVE-2026-24169HIGHNVIDIA UFM Enterprise contains a vulnerability in the plugin management API, where an authenticated user with low privileges could inject coEPSS 0.4%CVE-2026-22601HIGHOpenProject is Vulnerable to Code Execution in E-Mail functionEPSS 0.4%CVE-2025-46176MEDIUMHardcoded credentials in the Telnet service in D-Link DIR-605L v2.13B01 and DIR-816L v2.06B01 allow attackers to remotely execute arbitrary EPSS 0.4%CVE-2025-61584CRITICALserverless-dns is vulnerable to Command Injection through pr.yml GitHub Action WorkflowEPSS 0.4%CVE-2021-34726MEDIUMCisco SD-WAN Software Command Injection VulnerabilityEPSS 0.4%CVE-2025-27953MEDIUMAn issue in Clinical Collaboration Platform 12.2.1.5 allows a remote attacker to obtain sensitive information and execute arbitrary code viaEPSS 0.4%CVE-2024-55466MEDIUMAn arbitrary file upload vulnerability in the Image Gallery of ThingsBoard Community, ThingsBoard Cloud and ThingsBoard Professional v3.8.1 EPSS 0.4%CVE-2026-24685CRITICALOpenProject has Argument Injection on Repository module that allows Arbitrary File WriteEPSS 0.4%CVE-2025-64671HIGHGitHub Copilot for Jetbrains Remote Code Execution VulnerabilityEPSS 0.4%CVE-2025-60268MEDIUMAn arbitrary file upload vulnerability exists in JeeWMS 20250820, which is caused by the lack of file checking in the saveFiles function in EPSS 0.4%CVE-2025-31710MEDIUMIn engineermode service, there is a possible command injection due to improper input validation. This could lead to local escalation of privEPSS 0.4%CVE-2025-25504MEDIUMAn issue in the /usr/local/bin/jncs.sh script of Gefen WebFWC (In AV over IP products) v1.85h, v1.86v, and v1.70 allows attackers with netwoEPSS 0.4%CVE-2024-7110MEDIUMImproper Neutralization of Special Elements used in a Command ('Command Injection') in GitLabEPSS 0.4%CVE-2026-40034HIGHgitoxide - Command Injection via Partial .gitmodules Override in gix-submoduleEPSS 0.4%