Weaknesses of type CWE-78

4,641 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2026-77521CRITICALMaxKB: Prompt-injectable agent can lead to command executionEPSS 1.0%CVE-2026-41553CRITICALRemote Code Execution in PDF Export ModuleEPSS 1.0%CVE-2023-34975MEDIUMQTS, QuTS hero, QuTScloudEPSS 1.0%CVE-2025-1036HIGHCommand injection vulnerability exists in the “Logging” page of the web-based configuration utility. An authenticated user with low privilegEPSS 1.0%CVE-2025-34147CRITICALShenzhen Aitemi M300 Wi-Fi Repeater OS Command Injection via SSIDEPSS 1.0%CVE-2025-3022CRITICALOS Command Injection vulnerability in e-management of e-solutionsEPSS 1.0%CVE-2026-22035HIGHGreenshot Vulnerable to OS Command Injection via ExternalCommand PluginEPSS 1.0%CVE-2023-3572CRITICALPHOENIX CONTACT: OS Command Injection in WP 6xxx Web panelsEPSS 1.0%CVE-2025-63261HIGHAWStats 8.0 is vulnerable to Command Injection via the open functionEPSS 1.0%CVE-2025-30479HIGHDell CloudLink, versions prior to 8.2, contain a vulnerability where a privileged user with known password can run command injection to gainEPSS 1.0%CVE-2026-11341MEDIUMD-Link DWR-M920 formIMEISetup sub_412DA0 os command injectionEPSS 1.0%CVE-2023-47709CRITICALIBM Security Guardium command injectionEPSS 1.0%CVE-2026-41015HIGHradare2 before 9236f44, when configured on UNIX without SSL, allows command injection via a PDB name to rabin2 -PP. NOTE: although users areEPSS 1.0%CVE-2024-35519HIGHNetgear EX6120 v1.0.0.68, Netgear EX6100 v1.0.2.28, and Netgear EX3700 v1.0.0.96 are vulnerable to command injection in operating_mode.cgi vEPSS 1.0%CVE-2026-11572HIGHVersions of the package degit before 2.8.6, from 3.0.0 and before 3.3.1 are vulnerable to Command Injection due to improper sanitisation of EPSS 1.0%CVE-2026-32056HIGHOpenClaw < 2026.2.22 - Remote Code Execution via Shell Startup Environment Variable Injection in system.runEPSS 1.0%CVE-2025-7145HIGHTeamT5|ThreatSonar Anti-Ransomware - OS Command InjectionEPSS 1.0%CVE-2024-9461HIGHTotal Upkeep <= 1.16.6 - Authenticated (Administrator+) Remote Code Execution via Backup SettingsEPSS 1.0%CVE-2026-35518HIGHPi-hole FTL affected by Remote Code Execution (RCE) via dns.cnameRecords Newline InjectionEPSS 1.0%CVE-2026-35520HIGHPi-hole FTL affected by Remote Code Execution (RCE) via dhcp.leaseTime Newline InjectionEPSS 1.0%