Falhas do tipo CWE-77

2.837 resultados

Injeção de comando

O software monta comandos do sistema ou de interpretadores (shell, SQL, etc.) usando dados que vêm de fora (entrada do usuário, requisição HTTP, arquivo) sem sanitizar ou sanitizando incorretamente caracteres especiais. Um atacante consegue 'fechar' o comando legítimo e injetar comandos arbitrários que serão executados com os mesmos privilégios da aplicação.

Exemplo

Um script que executa `ping` no endereço fornecido pelo usuário: `system('ping ' + user_input)`. Se o usuário digita `8.8.8.8; rm -rf /`, o comando executado vira dois: primeiro o ping, depois a deleção de arquivos. A maioria das CVEs de injeção de comando vêm deste padrão.

Como mitigar

Use APIs que aceitam argumentos como lista (não concatenação de strings) — ex: subprocess.run(['ping', user_input]) em Python ou parameterized queries em banco de dados. Se precisar de interpretador, valide rigorosamente a entrada com lista branca (aceita apenas IP/domínio válido) e evite shells intermediários.

CVE-2021-1488MEDIUMCisco Adaptive Security Appliance Software and Firepower Threat Defense Software for Firepower 1000 and 2100 Series Appliances Command Injection VulnerabilityEPSS 0.3%CVE-2024-40070MEDIUMSourcecodester Online ID Generator System 1.0 was discovered to contain an arbitrary file upload vulnerability via id_generator/classes/UserEPSS 0.3%CVE-2025-55824MEDIUMModStartCMS v9.5.0 has an arbitrary file write vulnerability, which allows attackers to write malicious files and execute malicious commandsEPSS 0.3%CVE-2026-46709HIGHTabby: Drag-and-drop path injection still allows RCE via shell command substitution (incomplete fix for CVE-2026-45038)EPSS 0.3%CVE-2024-9773LOWImproper Neutralization of Special Elements used in a Command ('Command Injection') in GitLabEPSS 0.2%CVE-2025-59817HIGHAuthenticated Remote Code Execution in zForm_auto_configEPSS 0.2%CVE-2025-31951HIGHHCL BigFix RunBookAI is affected by a Unvalidated Command Input / Potential Command Smuggling vulnerabilityEPSS 0.2%CVE-2026-65111HIGHNVIDIA NeMo Speech for all platforms contains a vulnerability where malicious input created by an attacker could cause a code injection. A sEPSS 0.2%CVE-2025-67508HIGHgardenctl is vulnerable to Command Injection when used with non‑POSIX shellsEPSS 0.2%CVE-2025-54393MEDIUMNetwrix Directory Manager (formerly Imanami GroupID) 11.0.0.0 before 11.1.25162.02 allows Static Code Injection. Authenticated users can obtEPSS 0.2%CVE-2024-8405MEDIUMArbitrary File Creation in PaperCut NG/MF Web Print leading to a Denial of Service attackEPSS 0.2%CVE-2021-21595MEDIUMDell EMC PowerScale OneFS versions 8.2.x - 9.1.1.x contain an improper neutralization of special elements used in an OS command. This vulnerEPSS 0.2%CVE-2025-66715MEDIUMA DLL hijacking vulnerability in Axtion ODISSAAS ODIS v1.8.4 allows attackers to execute arbitrary code via a crafted DLL file.EPSS 0.2%CVE-2025-25791MEDIUMAn arbitrary file upload vulnerability in the plugin installation feature of YZNCMS v2.0.1 allows attackers to execute arbitrary code via upEPSS 0.2%CVE-2025-70296MEDIUMA stored HTML injection vulnerability in the Recipe Notes rendering component in Mealie 3.3.1 allows remote authenticated users to inject arEPSS 0.2%CVE-2026-34259HIGHOS Command Injection Vulnerability in SAP Forecasting & ReplenishmentEPSS 0.2%CVE-2023-20097MEDIUMCisco Access Point Software Command Injection VulnerabilityEPSS 0.2%CVE-2026-46508HIGHTurborepo: VSCode Extension command injectionEPSS 0.2%CVE-2024-8402LOWImproper Neutralization of Special Elements used in a Command ('Command Injection') in GitLabEPSS 0.2%CVE-2023-33806HIGHInsecure default configurations in Hikvision Interactive Tablet DS-D5B86RB/B V2.3.0 build220119, allows attackers to execute arbitrary commaEPSS 0.2%