Weaknesses of type CWE-78

4,652 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2020-37012CRITICALTea LaTex 1.0 - Remote Code ExecutionEPSS 0.9%CVE-2022-43628MEDIUMThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. AlEPSS 0.9%CVE-2026-71963HIGHHermes Agent 0.18.2 - 0.21.0 RCE via git core.fsmonitor Config InjectionEPSS 0.9%CVE-2026-40187HIGHAuthenticated RCE via Malicious eTemplate Upload in EGroupwareEPSS 0.9%CVE-2026-28673HIGHxiaoheiFS Vulnerable to RCE via Unrestricted Plugin Installation (Manifest Manipulation)EPSS 0.9%CVE-2026-73667HIGHOpenChoreo: Authenticated OS command injection via OpenChoreo Workflow Plane templates enables code execution in privileged podsEPSS 0.9%CVE-2026-81545HIGHDataStage on Cloud Pak for Data has several vulnerabilitiesEPSS 0.9%CVE-2022-25597HIGHASUS RT-AC86U - Command InjectionEPSS 0.9%CVE-2024-39607MEDIUMOS command injection vulnerability exists in ELECOM wireless LAN routers. A specially crafted request may be sent to the affected product byEPSS 0.9%CVE-2025-8890CRITICALAuthenticated RCE in SDMC NE6037 routerEPSS 0.9%CVE-2026-79423HIGHAn authenticated remote code execution (RCE) vulnerability in the admin_config.php component of seacms v13.6 allows attackers to execute arbEPSS 0.9%CVE-2026-42454CRITICALTermix: OS Command Injection in Docker Container Management EndpointsEPSS 0.9%CVE-2026-55378CRITICALJS Recon: Command injection in PR Branch Checker workflow via untrusted pull request context valuesEPSS 0.8%CVE-2026-0711MEDIUMA post-authentication command injection vulnerability in the EasyMesh-related APIs of Zyxel DX3300-T0 firmware versions through 5.50(ABVY.7.EPSS 0.8%CVE-2024-51021HIGHNetgear XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 was discovered to contain a command injection vulnerability via the wan_gEPSS 0.8%CVE-2021-0218HIGHJunos OS: Command injection vulnerability in license-check daemonEPSS 0.8%CVE-2024-10035CRITICALCode Injection in BG-TEK's CoslatV3EPSS 0.8%CVE-2023-44092HIGHOS Command InjectionEPSS 0.8%CVE-2026-6281HIGHA potential vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remote authenticated user on the locEPSS 0.8%CVE-2026-84694HIGHCoolify before 4.2.0 Remote Code Execution via Environment Variable KeyEPSS 0.8%