Falhas do tipo CWE-77

2.837 resultados

Injeção de comando

O software monta comandos do sistema ou de interpretadores (shell, SQL, etc.) usando dados que vêm de fora (entrada do usuário, requisição HTTP, arquivo) sem sanitizar ou sanitizando incorretamente caracteres especiais. Um atacante consegue 'fechar' o comando legítimo e injetar comandos arbitrários que serão executados com os mesmos privilégios da aplicação.

Exemplo

Um script que executa `ping` no endereço fornecido pelo usuário: `system('ping ' + user_input)`. Se o usuário digita `8.8.8.8; rm -rf /`, o comando executado vira dois: primeiro o ping, depois a deleção de arquivos. A maioria das CVEs de injeção de comando vêm deste padrão.

Como mitigar

Use APIs que aceitam argumentos como lista (não concatenação de strings) — ex: subprocess.run(['ping', user_input]) em Python ou parameterized queries em banco de dados. Se precisar de interpretador, valide rigorosamente a entrada com lista branca (aceita apenas IP/domínio válido) e evite shells intermediários.

CVE-2025-45512MEDIUMA lack of signature verification in the bootloader of DENX Software Engineering Das U-Boot (U-Boot) v1.1.3 allows attackers to install craftEPSS 0.3%CVE-2024-45989MEDIUMMonica AI Assistant desktop application v2.3.0 is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor. A prompt injectiEPSS 0.3%CVE-2025-54964HIGHAn issue was discovered in BAE SOCET GXP before 4.6.0.2. An attacker with the ability to interact with the GXP Job Service may inject arbitrEPSS 0.3%CVE-2025-52337MEDIUMAn authenticated arbitrary file upload vulnerability in the Content Explorer feature of LogicData eCommerce Framework v5.0.9.7000 allows attEPSS 0.3%CVE-2022-20665MEDIUMCisco StarOS Command Injection VulnerabilityEPSS 0.3%CVE-2021-27702HIGHSercomm Router Etisalat Model S3- AC2100 is affected by Incorrect Access Control via the diagnostic utility in the router dashboard.EPSS 0.3%CVE-2025-43948HIGHCodemers KLIMS 1.6.DEV allows Python code injection. A user can provide Python code as an input value for a parameter or qualifier (such as EPSS 0.3%CVE-2024-57338MEDIUMAn arbitrary file upload vulnerability in M2Soft CROWNIX Report & ERS v5.x to v5.5.14.1070, v7.x to v7.4.3.960, and v8.x to v8.2.0.345 allowEPSS 0.3%CVE-2024-57337MEDIUMAn arbitrary file upload vulnerability in the opcode 500 functionality of M2Soft CROWNIX Report & ERS v5.x to v5.5.14.1070, v7.x to v7.4.3.9EPSS 0.3%CVE-2025-26262MEDIUMAn issue in the component /internals/functions of R-fx Networks Linux Malware Detect v1.6.5 allows attackers to escalate privileges and execEPSS 0.3%CVE-2025-59376LOWfeiskyer mcp-kubernetes-server through 0.1.11 does not consider chained commands in the implementation of --disable-write and --disable-deleEPSS 0.3%CVE-2026-52473MEDIUMAn issue in Wgcloud 3.6.4 allows a remote attacker to escalate privileges via the content parameter is directly concatenated to the ProcessBEPSS 0.3%CVE-2024-56087MEDIUMAn issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while querying Search Template Dashboard. These arEPSS 0.3%CVE-2025-59337MEDIUMDiscourse: Cross-Site Data Exposure via Backup Restore Metacommand Injection in Multisite DeploymentsEPSS 0.3%CVE-2024-56085MEDIUMAn issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while creating Search Template Dashboard. These arEPSS 0.3%CVE-2024-38831HIGHLocal privilege escalation vulnerability (CVE-2024-38831)EPSS 0.3%CVE-2024-54681LOWOssur Mobile Logic Application Command InjectionEPSS 0.3%CVE-2025-63674MEDIUMAn issue in Blurams Lumi Security Camera (A31C) v23.1227.472.2926 allows local physical attackers to execute arbitrary code via overriding tEPSS 0.3%CVE-2025-50817MEDIUMA vulnerability in the Python-Future 1.0.0 module allows for arbitrary code execution via the unintended import of a file named test.py. WheEPSS 0.3%CVE-2022-46361MEDIUMPhysical access to the WDM enables use of USB device to gain access to the WDMEPSS 0.3%