Weaknesses of type CWE-78

4,664 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2026-55743CRITICALOpenHuman desktop agent shell tool sandbox bypass leads to arbitrary command executionEPSS 0.6%CVE-2025-24386HIGHDell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command InjectionEPSS 0.6%CVE-2025-11774HIGHMalicious Code Execution Vulnerability in the Software Keyboard Function of GENESIS64, ICONICS Suite, Mobile HMI, and MC Works64EPSS 0.6%CVE-2026-13249CRITICALUnauthenticated RCE Arbitrary File Upload Honeywell PD45 Industrial Printer version F10.19.010040EPSS 0.6%CVE-2024-31481MEDIUMUnauthenticated Denial of Service (DoS) vulnerabilities exist in the CLI service accessed via the PAPI protocol. Successful exploitation of EPSS 0.6%CVE-2026-31862CRITICALCloud CLI has Command Injection via Multiple ParametersEPSS 0.6%CVE-2024-31479MEDIUMUnauthenticated Denial of Service (DoS) vulnerabilities exist in the Central Communications service accessed via the PAPI protocol. SuccessfEPSS 0.6%CVE-2025-30044CRITICALRCE on uhcapache user permissionsEPSS 0.6%CVE-2024-31480MEDIUMUnauthenticated Denial of Service (DoS) vulnerabilities exist in the CLI service accessed via the PAPI protocol. Successful exploitation of EPSS 0.6%CVE-2026-3692HIGHUnintended command execution during report generation in Progress FlowmonEPSS 0.6%CVE-2026-77080HIGHn8n before 1.123.69 Arbitrary File Read and Write via SnowflakeEPSS 0.6%CVE-2025-0127HIGHPAN-OS: Authenticated Admin Command Injection Vulnerability in PAN-OS VM-SeriesEPSS 0.6%CVE-2018-0182—Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to inject arbitrary commandEPSS 0.6%CVE-2018-0194—Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to inject arbitrary commandEPSS 0.6%CVE-2018-0193—Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to inject arbitrary commandEPSS 0.6%CVE-2026-35072MEDIUMDell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release versions 8.3.1.0 throughEPSS 0.6%CVE-2018-0185—Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to inject arbitrary commandEPSS 0.6%CVE-2024-43387HIGHPhoenix Contact: Access files due to improper neutralization of special elements in MGUARD devicesEPSS 0.6%CVE-2026-49185CRITICALInstruction Injection via FieldX MDMEPSS 0.6%CVE-2022-1513HIGHA potential vulnerability was reported in Lenovo PCManager prior to version 5.0.10.4191 that may allow code execution when visiting a speciaEPSS 0.6%