Weaknesses of type CWE-78

4,627 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2026-0630HIGHCommand Injection Vulnerability on TP-Link Archer BE230 v1.2 and AXE75 v1.0EPSS 1.3%CVE-2023-37213HIGH Synel SYnergy Fingerprint Terminals - CWE-78: 'OS Command Injection'EPSS 1.3%CVE-2024-21532HIGHAll versions of the package ggit are vulnerable to Command Injection via the fetchTags(branch) API, which allows user input to specify the bEPSS 1.3%CVE-2023-41348HIGHASUS RT-AX55 - command injection - 4EPSS 1.3%CVE-2023-41345HIGHASUS RT-AX55 - command injection - 1EPSS 1.3%CVE-2023-41347HIGHASUS RT-AX55 - command injection - 3EPSS 1.3%CVE-2026-67394CRITICALA critical local privilege escalation via OS command injection vulnerability has been discovered in Plesk for Linux, affecting all versions EPSS 1.3%CVE-2026-85979HIGHCommand Injection in Puppet EnterpriseEPSS 1.3%CVE-2025-34148CRITICALShenzhen Aitemi M300 Wi-Fi Repeater OS Command Injection via WISP SSIDEPSS 1.3%CVE-2025-0110HIGHPAN-OS OpenConfig Plugin: Command Injection Vulnerability in OpenConfig PluginEPSS 1.3%CVE-2022-33869HIGHAn improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface of FortiWAN 4.0.0 thEPSS 1.3%CVE-2026-40933CRITICALFlowise: Authenticated RCE Via MCP AdaptersEPSS 1.3%CVE-2022-34883HIGHOS Command Injection Vulnerability in RAID Manager Storage Replication AdapterEPSS 1.3%CVE-2022-47616HIGHHitron Technologies Inc. CODA-5310 - Remote Command ExecutionEPSS 1.3%CVE-2025-20061CRITICALmySCADA myPRO Manager OS Command InjectionEPSS 1.3%CVE-2025-20014CRITICALmySCADA myPRO Manager OS Command InjectionEPSS 1.3%CVE-2024-50372CRITICALA CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the followingEPSS 1.3%CVE-2024-50373CRITICALA CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the followingEPSS 1.3%CVE-2025-24382HIGHDell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command InjectionEPSS 1.3%CVE-2024-50371CRITICALA CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the followingEPSS 1.3%