Weaknesses of type CWE-78

4,641 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2026-35517HIGHPi-hole FTL affected by Remote Code Execution (RCE) via dns.upstreams Newline InjectionEPSS 1.0%CVE-2026-35518HIGHPi-hole FTL affected by Remote Code Execution (RCE) via dns.cnameRecords Newline InjectionEPSS 1.0%CVE-2026-57124CRITICALPraisonAI UI MCP connect endpoint allows unauthenticated local command executionEPSS 1.0%CVE-2026-41449HIGHUAC < 3.3.0 Command Injection via run_command.shEPSS 1.0%CVE-2024-8281HIGHAn input validation weakness was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform commEPSS 1.0%CVE-2024-8280HIGHAn input validation weakness was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform commEPSS 1.0%CVE-2021-3727HIGHOS Command Injection in ohmyzsh/ohmyzshEPSS 1.0%CVE-2024-50390HIGHQHoraEPSS 1.0%CVE-2023-44416MEDIUMD-Link DAP-2622 Telnet CLI Command Injection Remote Code Execution VulnerabilityEPSS 1.0%CVE-2024-48895HIGHImproper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Rakuten Turbo 5G firmware versionEPSS 1.0%CVE-2022-43464HIGHHidden functionality vulnerability in UDR-JA1604/UDR-JA1608/UDR-JA1616 firmware versions 71x10.1.107112.43A and earlier allows a remote authEPSS 1.0%CVE-2024-23961MEDIUMAlpine Halo9 UPDM_wemCmdUpdFSpeDecomp Command Injection Remote Code Execution VulnerabilityEPSS 1.0%CVE-2024-23924MEDIUMAlpine Halo9 UPDM_wemCmdCreatSHA256Hash Command Injection Remote Code Execution VulnerabilityEPSS 1.0%CVE-2026-94367HIGHOpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains an OS command injection vulnerability in recbackup. An authenticated aEPSS 1.0%CVE-2025-67447CRITICALThe network diagnosis (ping) module in Neterbit NW-431F Router 20241014-IR03 and before is vulnerable to OS command injection. The applicatiEPSS 1.0%CVE-2025-64124HIGHNuvation Energy Multi-Stack Controller OS Command InjectionEPSS 1.0%CVE-2018-20106MEDIUMSMB printer settings don't escape characters in passwords properlyEPSS 1.0%CVE-2026-31019HIGHIn the Website module of Dolibarr ERP & CRM 22.0.4 and below, the application uses blacklist-based filtering to restrict dangerous PHP functEPSS 1.0%CVE-2010-20059CRITICALFreeNAS < 0.7.2 rev 5543 exec_raw.php Arbitrary Command ExecutionEPSS 1.0%CVE-2026-18284HIGHSony XAV-9500ES Crash Dump Handler Command Injection Local Privilege Escalation VulnerabilityEPSS 1.0%