Weaknesses of type CWE-78

4,660 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2026-73224HIGHElecterm check folder size function may get attacked by unsafe folder nameEPSS 0.7%CVE-2025-45379HIGHDell CloudLink, versions prior to 8.2, contain a vulnerability where a privileged user with known password can run command injection from coEPSS 0.7%CVE-2026-84440HIGHIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 0.7%CVE-2025-8650MEDIUMKenwood DMX958XR libSystemLib Command Injection Remote Code Execution VulnerabilityEPSS 0.7%CVE-2025-8651MEDIUMKenwood DMX958XR JKWifiService Command Injection Remote Code Execution VulnerabilityEPSS 0.7%CVE-2025-8652MEDIUMKenwood DMX958XR JKWifiService Command Injection Remote Code Execution VulnerabilityEPSS 0.7%CVE-2025-8649MEDIUMKenwood DMX958XR JKWifiService Command Injection Remote Code Execution VulnerabilityEPSS 0.7%CVE-2025-8655MEDIUMKenwood DMX958XR libSystemLib Command injection Remote Code Execution VulnerabilityEPSS 0.7%CVE-2024-20459MEDIUMCisco ATA 190 Series Analog Telephone Adapter Muliplatform Firmware Command Injection VulnerabilityEPSS 0.7%CVE-2026-55578HIGHPheditor: Incomplete command sanitization in terminal feature allows RCE via pipe operator, backtick substitution, and newline injectionEPSS 0.7%CVE-2021-1421HIGHCisco Enterprise NFV Infrastructure Software Command Injection VulnerabilityEPSS 0.7%CVE-2026-77120HIGHCWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause priEPSS 0.7%CVE-2026-54051CRITICALNetwork-AI has an an OS Command Injection issueEPSS 0.7%CVE-2026-79755HIGHNuclio: Unauthenticated OS command injection via function namespace in docker ps --filter label (local Docker platform)EPSS 0.7%CVE-2026-44444CRITICALLumiverse: Spindle extension install runs untrusted lifecycle scripts before security scanEPSS 0.7%CVE-2026-73753HIGHAuthenticated Remote Command Injection Vulnerabilities in AOS-CX Command Line InterfaceEPSS 0.7%CVE-2026-20099MEDIUMCisco UCS Manager and FXOS Software Command Injection VulnerabilityEPSS 0.7%CVE-2026-14499HIGHLangflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpointsEPSS 0.7%CVE-2026-18683HIGHIBM i is Affected By privilege escalation in Navigator for iEPSS 0.7%CVE-2023-4856HIGH A format string vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user to execute arbitrary commands on a EPSS 0.7%