Weaknesses of type CWE-78

4,654 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2024-51253HIGHIn Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doEPSS 0.7%CVE-2024-51249HIGHIn Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the reEPSS 0.7%CVE-2026-33613HIGHMB connect line mbCONNECT24 vulnerable to RCE in generateSrpArrayEPSS 0.7%CVE-2026-55607HIGHClaude Code: Sandbox Escape via Git Worktree Path Confusion Allows Unsandboxed Code ExecutionEPSS 0.7%CVE-2024-30414HIGHCommand injection vulnerability in the AccountManager module. Impact: Successful exploitation of this vulnerability may affect service confiEPSS 0.7%CVE-2024-58376HIGHRenovate 37.158.0 before 37.199.0 Command Injection via helmv3EPSS 0.7%CVE-2024-50361HIGHA CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the followingEPSS 0.7%CVE-2025-6541HIGHOS command injection using information obtained from the web management interfaceEPSS 0.7%CVE-2023-34141HIGHA command injection vulnerability in the access point (AP) management feature of the Zyxel ATP series firmware versions 5.00 through 5.36 PaEPSS 0.7%CVE-2023-34138HIGHA command injection vulnerability in the hotspot management feature of the Zyxel ATP series firmware versions 4.60 through 5.36 Patch 2, USGEPSS 0.7%CVE-2026-16524HIGHPcp: pcp linux_sockets pmda: arbitrary command execution via command injectionEPSS 0.7%CVE-2017-20236CRITICALProSoft Technology ICX35-HWC Command Injection via Web InterfaceEPSS 0.7%CVE-2026-93289CRITICALOS command injection in Eufy Omni C20, Omni X10 ProEPSS 0.7%CVE-2026-25763CRITICALCommand Injection on OpenProject repositories leads to Remote Code ExecutionEPSS 0.7%CVE-2024-47821CRITICALpyLoad vulnerable to remote code execution by download to /.pyload/scripts using /flashgot APIEPSS 0.7%CVE-2025-66626HIGHargoproj/argo-workflows is vulnerable to RCE via ZipSlip and symbolic linksEPSS 0.7%CVE-2026-11325HIGHcloudflare/pages-action is deprecated — migration required by September 18th, 2026EPSS 0.7%CVE-2025-0255HIGHHCL DevOps Deploy / HCL Launch is susceptible to command injection vulnerabilityEPSS 0.7%CVE-2026-33414MEDIUMPowerShell Command Injection in Podman HyperV MachineEPSS 0.7%CVE-2025-3881HIGHeCharge Hardy Barth cPH2 check_req.php ntp Command Injection Remote Code Execution VulnerabilityEPSS 0.7%