Falhas do tipo CWE-77

2.837 resultados

Injeção de comando

O software monta comandos do sistema ou de interpretadores (shell, SQL, etc.) usando dados que vêm de fora (entrada do usuário, requisição HTTP, arquivo) sem sanitizar ou sanitizando incorretamente caracteres especiais. Um atacante consegue 'fechar' o comando legítimo e injetar comandos arbitrários que serão executados com os mesmos privilégios da aplicação.

Exemplo

Um script que executa `ping` no endereço fornecido pelo usuário: `system('ping ' + user_input)`. Se o usuário digita `8.8.8.8; rm -rf /`, o comando executado vira dois: primeiro o ping, depois a deleção de arquivos. A maioria das CVEs de injeção de comando vêm deste padrão.

Como mitigar

Use APIs que aceitam argumentos como lista (não concatenação de strings) — ex: subprocess.run(['ping', user_input]) em Python ou parameterized queries em banco de dados. Se precisar de interpretador, valide rigorosamente a entrada com lista branca (aceita apenas IP/domínio válido) e evite shells intermediários.

CVE-2025-25768MEDIUMMRCMS v3.1.2 was discovered to contain a server-side template injection (SSTI) vulnerability in the component \servlet\DispatcherServlet.javEPSS 0.3%CVE-2024-4944HIGHMobile VPN with SSL Local Privilege Escalation VulnerabilityEPSS 0.3%CVE-2026-73078HIGHVim: Arbitrary Code Execution via Netrw Menu ConstructionEPSS 0.3%CVE-2022-47028MEDIUMAn issue discovered in Action Launcher for Android v50.5 allows an attacker to cause a denial of service via arbitary data injection to funcEPSS 0.3%CVE-2026-73709HIGHUnauthenticated Remote Code Execution during HPE Networking Fabric Composer Installation ProcessEPSS 0.3%CVE-2026-35558HIGHImproper neutralization of special elements in authentication components in Amazon Athena ODBC driverEPSS 0.3%CVE-2022-25619LOWAuthenticated Command Injection to RCEEPSS 0.3%CVE-2024-56084HIGHAn issue was discovered in Logpoint UniversalNormalizer before 5.7.0. Authenticated users can inject payloads while creating Universal NormaEPSS 0.3%CVE-2026-30615HIGHA prompt injection vulnerability in Windsurf 1.9544.26 allows remote attackers to execute arbitrary commands on a victim system. When WindsuEPSS 0.3%CVE-2025-25766MEDIUMAn arbitrary file upload vulnerability in the component /file/savefile.do of MRCMS v3.1.2 allows attackers to execute arbitrary code via uplEPSS 0.3%CVE-2026-50523HIGHMicrosoft PowerShell Remote Code Execution VulnerabilityEPSS 0.3%CVE-2026-69534HIGHWindows Program Compatibility Assistant Service Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-68792HIGHMicrosoft Office Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-50488HIGHClipboard User Service Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-58635HIGHWindows Narrator Braille Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2024-21117MEDIUMVulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Outside In Core). Supported versions thatEPSS 0.3%CVE-2025-63296MEDIUMKERUI K259 5MP Wi-Fi / Tuya Smart Security Camera firmware v33.53.87 contains a code execution vulnerability in its boot/update logic: durinEPSS 0.3%CVE-2025-60595HIGHSPH Engineering UgCS 5.13.0 is vulnerable to Arbitary code execution.EPSS 0.3%CVE-2022-3086HIGHCradlepoint IBR600 Command InjectionEPSS 0.3%CVE-2025-45317MEDIUMA zip slip vulnerability in the /modules/ImportModule.php component of hortusfox-web v4.4 allows attackers to execute arbitrary code via a cEPSS 0.3%