Weaknesses of type CWE-78

4,647 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2025-34186CRITICALIlevia EVE X1/X5 Server 4.7.18.0.eden Authentication BypassEPSS 0.9%CVE-2023-38056HIGHCode execution via System Configuration EPSS 0.9%CVE-2025-26320MEDIUMt0mer BroadlinkManager v5.9.1 was discovered to contain an OS command injection vulnerability via the IP Address parameter at /device/ping.EPSS 0.9%CVE-2026-19136HIGHA potential command injection vulnerability was reported in the Tianxi AI Agent PC Application, distributed exclusively in the Chinese markeEPSS 0.9%CVE-2026-45152HIGHuniget: Command Injection in tool.Check Leading to Arbitrary Code ExecutionEPSS 0.9%CVE-2026-58195HIGHAgentic-Flow: OS Command Injection in agentic-flow MCP server tools via unsanitized tool-parameter interpolation into execSyncEPSS 0.9%CVE-2023-22816MEDIUMLimited Post-Authentication Remote Command Injection in My Cloud ProductsEPSS 0.9%CVE-2025-20186HIGHA vulnerability in the web-based management interface of the Wireless LAN Controller feature of Cisco IOS XE Software could allow an authentEPSS 0.9%CVE-2024-30314HIGHDreamweaver Desktop | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)EPSS 0.9%CVE-2025-2257HIGHTotal Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid <= 1.16.10 - Authenticated (Admin+) Command InjectionEPSS 0.9%CVE-2026-69320HIGHVisual Studio Code Remote Code Execution VulnerabilityEPSS 0.9%CVE-2026-28384CRITICALAuthenticated RCE via unsanitized compression_algorithmEPSS 0.9%CVE-2023-35895MEDIUMIBM Informix JDBC code executionEPSS 0.9%CVE-2023-49695MEDIUMOS command injection vulnerability in WRC-X3000GSN v1.0.2, WRC-X3000GS v1.0.24 and earlier, and WRC-X3000GSA v1.0.24 and earlier allows a neEPSS 0.9%CVE-2023-25507HIGHNVIDIA DGX-1 BMC contains a vulnerability in the SPX REST API, where an attacker with the appropriate level of authorization can inject arbiEPSS 0.9%CVE-2026-16956CRITICALIBM Db2 Mirror for i is vulnerable to OS command injection []EPSS 0.9%CVE-2026-67965CRITICALAn issue in Tneda W20E v.16.01.0.6(2782) allows a remote attacker to execute arbitrary code via the url_need_login functionEPSS 0.9%CVE-2026-16882CRITICALVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.9%CVE-2025-59783HIGHOS Command Injection over APIEPSS 0.9%CVE-2021-3061MEDIUMPAN-OS: OS Command Injection Vulnerability in the Command Line Interface (CLI)EPSS 0.9%