CWE-77 在命令中使用的特殊元素转义处理不恰当(命令注入) 类弱点 1260 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-77即命令注入,属于输入验证缺陷。攻击者通过构造包含特殊字符的恶意输入,篡改后端系统命令,从而执行任意指令或获取敏感数据。开发者应避免直接拼接用户输入,需采用白名单过滤、参数化调用或安全API替代系统命令执行,确保输入被严格限制在预期范围内,从源头阻断注入风险。
prompt = "Explain the difference between {} and {}".format(arg1, arg2) result = invokeChatbot(prompt) resultHTML = encodeForHTML(result) print resultHTMLExplain the difference between CWE-77 and CWE-78my $arg = GetArgument("filename"); do_listing($arg); sub do_listing { my($fname) = @_; if (! validate_name($fname)) { print "Error: name is not well-formed!\n"; return; } # build command my $cmd = "/bin/ls -l $fname"; system($cmd); } sub validate_name { my($name) = @_; if ($name =~ /^[\w\-]+$/) { return(1); } else { return(0); } }if ($name =~ /^\w[\w\-]+$/) ...| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2026-8774 | Edimax BR-6228NC 注入漏洞 — BR-6228NC | 6.3 | Medium | 2026-05-18 |
| CVE-2026-8753 | Kalcaddle Kodbox 注入漏洞 — Kodbox | 6.3 | Medium | 2026-05-17 |
| CVE-2026-46508 | Turborepo 命令注入漏洞 — turborepo | - | - | 2026-05-15 |
| CVE-2026-40698 | F5 BIG-IP和F5 BIG-IQ 命令注入漏洞 — BIG-IP | 6.5 | Medium | 2026-05-13 |
| CVE-2026-41953 | F5 BIG-IP 命令注入漏洞 — BIG-IP | 6.5 | Medium | 2026-05-13 |
| CVE-2026-40061 | F5 BIG-IP 命令注入漏洞 — BIG-IP | 8.7 | High | 2026-05-13 |
| CVE-2026-44257 | EFW Framework 命令注入漏洞 — efw4.X | - | - | 2026-05-12 |
| CVE-2026-8431 | MongoDB Ops Manager 命令注入漏洞 — Ops Manager | 7.2 | High | 2026-05-12 |
| CVE-2026-42893 | Microsoft M365 Copilot 命令注入漏洞 — Microsoft Outlook for iOS | 7.4 | High | 2026-05-12 |
| CVE-2026-43990 | JunoClaw 命令注入漏洞 — junoclaw | 8.4 | High | 2026-05-12 |
| CVE-2026-40135 | SAP NetWeaver ABAP Platform和SAP NetWeaver Application Server for ABAP 命令注入漏洞 — SAP NetWeaver Application Server for ABAP and ABAP Platform | 6.5 | Medium | 2026-05-12 |
| CVE-2026-34259 | SAP Forecasting and Replenishment 命令注入漏洞 — SAP Forecasting & Replenishment | 8.2 | High | 2026-05-12 |
| CVE-2026-8346 | D-Link DIR-816 注入漏洞 — DIR-816 | 6.3 | Medium | 2026-05-11 |
| CVE-2026-8345 | D-Link DIR-816 注入漏洞 — DIR-816 | 6.3 | Medium | 2026-05-11 |
| CVE-2026-8344 | D-Link DIR-816 注入漏洞 — DIR-816 | 6.3 | Medium | 2026-05-11 |
| CVE-2026-8210 | tgpt 注入漏洞 — tgpt | 5.3 | Medium | 2026-05-09 |
| CVE-2026-42258 | Net::IMAP 命令注入漏洞 — net-imap | 9.4 | - | 2026-05-09 |
| CVE-2026-42453 | Termix 命令注入漏洞 — Termix | 9.8AI | CriticalAI | 2026-05-08 |
| CVE-2026-42271 | LiteLLM 命令注入漏洞 — litellm | 9.8AI | CriticalAI | 2026-05-08 |
| CVE-2026-41500 | Electerm 命令注入漏洞 — electerm | 9.8 | Critical | 2026-05-08 |
| CVE-2026-41501 | Electerm 命令注入漏洞 — electerm | 9.8 | Critical | 2026-05-08 |
| CVE-2026-35428 | Microsoft Azure Cloud Shell 命令注入漏洞 — Azure Cloud Shell | 9.6 | Critical | 2026-05-07 |
| CVE-2026-33111 | Microsoft Copilot Chat 命令注入漏洞 — Copilot Chat (Microsoft Edge) | 7.5 | High | 2026-05-07 |
| CVE-2026-20169 | Cisco IoT Field Network Director 命令注入漏洞 — Cisco IoT Field Network Director (IoT-FND) | 6.4 | Medium | 2026-05-06 |
| CVE-2025-31951 | HCL BigFix RunBookAI 命令注入漏洞 — BigFix RunBookAI | 8.8 | High | 2026-05-06 |
| CVE-2026-7833 | EFM ipTIME C200 注入漏洞 — ipTIME C200 | 7.2 | High | 2026-05-05 |
| CVE-2026-7812 | Code-MCP 注入漏洞 — code-mcp | 7.3 | High | 2026-05-05 |
| CVE-2026-7721 | TOTOLINK WA300 注入漏洞 — WA300 | 6.3 | Medium | 2026-05-04 |
| CVE-2026-7720 | TOTOLINK WA300 注入漏洞 — WA300 | 6.3 | Medium | 2026-05-04 |
| CVE-2026-7718 | TOTOLINK WA300 注入漏洞 — WA300 | 6.3 | Medium | 2026-05-04 |
CWE-77(在命令中使用的特殊元素转义处理不恰当(命令注入)) 是常见的弱点类别,本平台收录该类弱点关联的 1260 条 CVE 漏洞。