Weaknesses of type CWE-78

4,623 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2026-0787HIGHALGO 8180 IP Audio Alerter SAC Command Injection Remote Code Execution VulnerabilityEPSS 1.4%CVE-2026-1961HIGHForman: foreman: remote code execution via command injection in websocket proxyEPSS 1.4%CVE-2026-20305CRITICALCisco Identity Services Engine Command Injection VulnerabilityEPSS 1.4%CVE-2023-39297HIGHQTS, QuTS hero, QuTScloudEPSS 1.4%CVE-2026-0261MEDIUMPAN-OS: Authenticated Admin Command Injection VulnerabilityEPSS 1.4%CVE-2012-10028HIGHNetwin SurgeFTP <= v23c8 Authenticated RCEEPSS 1.4%CVE-2022-23611HIGHOS command injection in iTunesRPC-RemasteredEPSS 1.4%CVE-2026-57499CRITICALLiman: OS Command Injection in LogRotationController allows authenticated admin to execute arbitrary commands (RCE)EPSS 1.4%CVE-2026-24893HIGHopenITCOCKPIT has Authenticated Command Injection Leading to Remote Code Execution via Host Address Macro ExpansionEPSS 1.4%CVE-2026-80127HIGHDell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper NeutraliEPSS 1.4%CVE-2026-28209HIGHFreePBX: Command Injection leading to Remote Code Execution in FreePBX ElevenLabs Text-to-Speech integrationEPSS 1.4%CVE-2026-6849HIGHOS Command Injection in TUBITAK BILGEM's Pardus OS My ComputerEPSS 1.4%CVE-2025-37171HIGHAuthenticated Command Injection Vulnerabilities in AOS-8 Web-Based Management InterfaceEPSS 1.4%CVE-2026-1428HIGHWellChoose|Single Sign-On Portal System - OS Command InjectionEPSS 1.4%CVE-2026-48732HIGHWarp: Remote SSH cwd can lead to unauthorized remote command executionEPSS 1.4%CVE-2023-35893CRITICALIBM Security Guardium command executionEPSS 1.4%CVE-2023-51585HIGHVoltronic Power ViewPower USBCommEx shutdown Command Injection Remote Code Execution VulnerabilityEPSS 1.4%CVE-2024-45763CRITICALDell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS CommEPSS 1.4%CVE-2024-45765CRITICALDell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS CommEPSS 1.4%CVE-2025-33228HIGHNVIDIA Nsight Systems contains a vulnerability in the gfx_hotspot recipe, where an attacker could cause an OS command injection by supplyingEPSS 1.4%