Weaknesses of type CWE-78

4,645 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2025-6562HIGHHunt Electronic Hybrid DVR - OS Command InjectionEPSS 0.9%CVE-2023-37407HIGHIBM Aspera Orchestrator command executionEPSS 0.9%CVE-2025-30264HIGHQTS, QuTS heroEPSS 0.9%CVE-2026-0709HIGHSome Hikvision Wireless Access Points are vulnerable to authenticated command execution due to insufficient input validation. Attackers withEPSS 0.9%CVE-2025-59534HIGHCryptoLib command Injection vulnerability in initialize_kerberos_keytab_file_login()EPSS 0.9%CVE-2026-58571HIGHDell PowerStore contains an OS Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit thisEPSS 0.9%CVE-2026-58567HIGHDell PowerStore contains an OS Command Injection vulnerability. An authenticated user with limited privileges could potentially exploit thisEPSS 0.9%CVE-2026-35463HIGHpyLoad has Improper Neutralization of Special Elements used in an OS CommandEPSS 0.9%CVE-2026-33208HIGHRoxy-WI Vulnerable to Authenticated Remote Code Execution via OS Command Injection in find-in-config EndpointEPSS 0.9%CVE-2026-35581HIGHEmissary has a Command Injection via PLACE_NAME Configuration in ExecutrixEPSS 0.9%CVE-2026-78177LOWTanStack devtools-vite Development Devtools Event Bus package-manager.ts installPackage os command injectionEPSS 0.9%CVE-2026-31994MEDIUMOpenClaw < 2026.2.19 - Local Command Injection via Unsafe cmd Argument Handling in Windows Scheduled Task Script GenerationEPSS 0.9%CVE-2026-26009CRITICALCatalyst Affected by Remote Code Execution as Root via Containerized Install Script ExecutionEPSS 0.9%CVE-2023-6260HIGHWeb UI OS Command Injection in Brivo ACS100, ACS300EPSS 0.9%CVE-2025-9976CRITICALOS Command Injection vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2025xEPSS 0.9%CVE-2024-33529HIGHILIAS 7 before 7.30 and ILIAS 8 before 8.11 as well as ILIAS 9.0 allow remote authenticated attackers with administrative privileges to execEPSS 0.9%CVE-2026-25546HIGHGodot MCP is vulnerable to Command Injection via unsanitized projectPathEPSS 0.9%CVE-2025-8644MEDIUMKenwood DMX958XR Firmware Update Command Injection VulnerabilityEPSS 0.9%CVE-2025-8647MEDIUMKenwood DMX958XR Firmware Update Command Injection VulnerabilityEPSS 0.9%CVE-2025-8645MEDIUMKenwood DMX958XR Firmware Update Command Injection VulnerabilityEPSS 0.9%