Weaknesses of type CWE-78

4,652 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2025-42892MEDIUMOS Command Injection vulnerability in SAP Business ConnectorEPSS 0.8%CVE-2025-34160CRITICALAnyShare ServiceAgent API Unauthenticated RCEEPSS 0.8%CVE-2026-59734HIGHCoolify: OS Command Injection in Health Check Configuration Allows Remote Code ExecutionEPSS 0.8%CVE-2022-43443HIGHOS command injection vulnerability in Buffalo network devices allows an network-adjacent attacker to execute an arbitrary OS command if a spEPSS 0.8%CVE-2023-28726HIGHPanasonic AiSEG2 versions 2.80F through 2.93A allows remote attackers to execute arbitrary OS commands.EPSS 0.8%CVE-2026-72875HIGHDokploy: Remote Code Execution (RCE) via Command Injection in settings.readTraefikFileEPSS 0.8%CVE-2026-72902CRITICALDokploy: Authenticated RCE via Command Injection in registry.testRegistry / registry.testRegistryByIdEPSS 0.8%CVE-2026-45172HIGHIdira Privileged Session Manager for SSH (PSMP): Arbitrary Command Execution via Improper Neutralization of Special Elements used in an OS CommandEPSS 0.8%CVE-2026-64837HIGHICEcoder through 8.1 OS Command Injection via lib/properties.phpEPSS 0.8%CVE-2025-57283HIGHThe Node.js package browserstack-local 1.5.8 contains a command injection vulnerability. This occurs because the logfile variable is not proEPSS 0.8%CVE-2021-3726HIGHOS Command Injection in ohmyzsh/ohmyzshEPSS 0.8%CVE-2024-51245HIGHIn DrayTek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the reEPSS 0.8%CVE-2026-44656MEDIUMVim: OS Command Injection via 'path' completionEPSS 0.8%CVE-2026-49190CRITICALMissing Per-Instruction Authorization ChecksEPSS 0.8%CVE-2026-81550HIGHDataStage on Cloud Pak for Data has several vulnerabilities due to open source softwareEPSS 0.8%CVE-2026-7461HIGHOS Command Injection in Amazon ECS Agent via FSx Windows File Server Volume CredentialsEPSS 0.8%CVE-2024-51247HIGHIn Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doEPSS 0.8%CVE-2026-41036HIGHCommand Injection Vulnerability in Quantum Networks Router QN-I-470EPSS 0.8%CVE-2024-51248HIGHIn Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the moEPSS 0.8%CVE-2024-51244HIGHIn Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doEPSS 0.8%