Falhas do tipo CWE-77

2.837 resultados

Injeção de comando

O software monta comandos do sistema ou de interpretadores (shell, SQL, etc.) usando dados que vêm de fora (entrada do usuário, requisição HTTP, arquivo) sem sanitizar ou sanitizando incorretamente caracteres especiais. Um atacante consegue 'fechar' o comando legítimo e injetar comandos arbitrários que serão executados com os mesmos privilégios da aplicação.

Exemplo

Um script que executa `ping` no endereço fornecido pelo usuário: `system('ping ' + user_input)`. Se o usuário digita `8.8.8.8; rm -rf /`, o comando executado vira dois: primeiro o ping, depois a deleção de arquivos. A maioria das CVEs de injeção de comando vêm deste padrão.

Como mitigar

Use APIs que aceitam argumentos como lista (não concatenação de strings) — ex: subprocess.run(['ping', user_input]) em Python ou parameterized queries em banco de dados. Se precisar de interpretador, valide rigorosamente a entrada com lista branca (aceita apenas IP/domínio válido) e evite shells intermediários.

CVE-2022-46361MEDIUMPhysical access to the WDM enables use of USB device to gain access to the WDMEPSS 0.3%CVE-2025-5264MEDIUMPotential local code execution in “Copy as cURL” commandEPSS 0.3%CVE-2022-20934MEDIUMA vulnerability in the CLI of Cisco Firepower Threat Defense (FTD) Software and Cisco FXOS Software could allow an authenticated, local attaEPSS 0.3%CVE-2025-20258MEDIUMA vulnerability in the self-service portal of Cisco Duo could allow an unauthenticated, remote attacker to inject arbitrary commands into emEPSS 0.3%CVE-2026-24167MEDIUMNVIDIA UFM Enterprise contains a vulnerability in the user management component, where an authenticated administrator could inject commands EPSS 0.3%CVE-2025-68433HIGHZed IDE MCP Context Server Configuration Arbitrary Code ExecutionEPSS 0.3%CVE-2025-68432HIGHZed IDE LSP Binary Configuration Arbitrary Code ExecutionEPSS 0.3%CVE-2025-55372MEDIUMAn arbitrary file upload vulnerability in Beakon Application before v5.4.3 allows attackers to execute arbitrary code via uploading a crafteEPSS 0.3%CVE-2026-76328MEDIUMSPL Injection through Splunk Web in Splunk EnterpriseEPSS 0.3%CVE-2025-29628CRITICALA Gardyn Azure IoT Hub connection string is downloaded over an insecure HTTP connection in Gardyn Home Kit firmware before master.619, Home EPSS 0.3%CVE-2025-57733MEDIUMIn JetBrains TeamCity before 2025.07.1 sMTP injection was possible allowing modification of email contentEPSS 0.3%CVE-2025-6945LOWImproper Neutralization of Special Elements used in a Command ('Command Injection') in GitLabEPSS 0.3%CVE-2025-51650MEDIUMAn arbitrary file upload vulnerability in the component /controller/PicManager.php of FoxCMS v1.2.6 allows attackers to execute arbitrary coEPSS 0.3%CVE-2025-59815HIGHAuthenticated Remote Code Execution in the Billing Administration portalEPSS 0.3%CVE-2024-47562CRITICALA vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application does not properly neutralizeEPSS 0.3%CVE-2023-0628MEDIUMDocker Desktop before 4.17.0 allows an attacker to execute an arbitrary command inside a Dev Environments container during initialization by tricking a user to open a crafted malicious docker-desktop:// URLEPSS 0.3%CVE-2025-43858CRITICALYoutubeDLSharp allows command injection on windows system due to non sanitized argumentsEPSS 0.3%CVE-2025-50515MEDIUMAn issue was discovered in phome Empirebak 2010 in ebak2008/upload/class/config.php allowing attackers to execute arbitrary code when the coEPSS 0.3%CVE-2025-60838MEDIUMAn arbitrary file upload vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary code via uploading a crafted file.EPSS 0.3%CVE-2025-1910MEDIUMWatchGuard Mobile VPN with SSL Local Privilege Escalation via Update PackageEPSS 0.3%