Weaknesses of type CWE-78

4,645 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2023-50204HIGHD-Link G416 flupl pythonapp Command Injection Remote Code Execution VulnerabilityEPSS 0.9%CVE-2023-50215HIGHD-Link G416 nodered gz File Handling Command Injection Remote Code Execution VulnerabilityEPSS 0.9%CVE-2023-50214HIGHD-Link G416 nodered tar File Handling Command Injection Remote Code Execution VulnerabilityEPSS 0.9%CVE-2024-21531MEDIUMAll versions of the package git-shallow-clone are vulnerable to Command injection due to missing sanitization or mitigation flags in the proEPSS 0.9%CVE-2023-50203HIGHD-Link G416 nodered chmod Command Injection Remote Code Execution VulnerabilityEPSS 0.9%CVE-2023-7093MEDIUMKylinSoft kylin-system-updater com.kylin.systemupgrade Service UpgradeStrategiesDbus.py os command injectionEPSS 0.9%CVE-2025-0457HIGHNetVision Information airPASS - OS Command InjectionEPSS 0.9%CVE-2023-23356MEDIUMQuFirewallEPSS 0.9%CVE-2026-12940CRITICALLangflow is affected by remote code execution due to multiple unauthenticated and insufficiently authorized API endpointsEPSS 0.9%CVE-2025-14737HIGHCommand Injection Vulnerability in TP-Link WA850REEPSS 0.9%CVE-2023-3314HIGH A vulnerability arises out of a failure to comprehensively sanitize the processing of a zip file(s). Incomplete neutralization of external EPSS 0.9%CVE-2026-80379HIGHDataStage on Cloud Pak for Data has several vulnerabilitiesEPSS 0.9%CVE-2026-80425HIGHDataStage on Cloud Pak for Data has several vulnerabilitiesEPSS 0.9%CVE-2024-45880HIGHA command injection vulnerability exists in Motorola CX2L router v1.0.2 and below. The vulnerability is present in the SetStationSettings fuEPSS 0.9%CVE-2025-8629MEDIUMKenwood DMX958XR Firmware Update Command Injection VulnerabilityEPSS 0.9%CVE-2025-8631MEDIUMKenwood DMX958XR Firmware Update Command Injection VulnerabilityEPSS 0.9%CVE-2025-8630MEDIUMKenwood DMX958XR Firmware Update Command Injection VulnerabilityEPSS 0.9%CVE-2025-8628MEDIUMKenwood DMX958XR Firmware Update Command Injection VulnerabilityEPSS 0.9%CVE-2024-28138HIGHOS Command InjectionEPSS 0.9%CVE-2026-26191MEDIUMFleet vulnerable to OS command injection in software packagesEPSS 0.9%