Weaknesses of type CWE-78

4,664 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2024-49281MEDIUMWordPress Click to Chat – WP Support All-in-One Floating Widget plugin <= 2.3.3 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.5%CVE-2024-31482MEDIUMAn unauthenticated Denial-of-Service (DoS) vulnerability exists in the ANSI escape code service accessed via the PAPI protocol. Successful eEPSS 0.5%CVE-2026-54149HIGHMaxKB MCP tool import validation bypass allows post-authentication remote code executionEPSS 0.5%CVE-2026-22622HIGHImproper input validation in one of the session management interface of Eaton's Tripp Lite series PADM firmware could allow an authenticatedEPSS 0.5%CVE-2026-27441CRITICALPDF Password CMDiEPSS 0.5%CVE-2026-84361HIGHComposer: Perforce source URL permits P4PORT `rsh:` command executionEPSS 0.5%CVE-2020-21583—An issue was discovered in hwclock.13-v2.27 allows attackers to gain escalated privlidges or execute arbitrary commands via the path parametEPSS 0.5%CVE-2026-57136HIGHPraisonAI SandboxExecutor allowedCommands bypass via shell chainingEPSS 0.5%CVE-2025-56590CRITICALAn issue was discovered in the InsertFromURL() function of the Apryse HTML2PDF SDK thru 11.10. This vulnerability could allow an attacker toEPSS 0.5%CVE-2026-5935HIGHTSSC/IMC is vulnerable to OS Command InjectionEPSS 0.5%CVE-2026-18235HIGHIBM i is Affected By Multiple Vulnerabilities in Navigator for iEPSS 0.5%CVE-2026-80412HIGHDataStage on Cloud Pak for Data has several vulnerabilitiesEPSS 0.5%CVE-2024-38641HIGHQTS, QuTS heroEPSS 0.5%CVE-2026-88272HIGHGV-LPC2011/LPC2211 - Stored Administrator-Username Command InjectionEPSS 0.5%CVE-2026-88282HIGHGV-LPCLPC2011/2211 - Stored FTP-Username Command InjectionEPSS 0.5%CVE-2025-40947HIGHA vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versions < V2.17.1), RUGGEEPSS 0.5%CVE-2025-24377HIGHDell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command InjectionEPSS 0.5%CVE-2026-12005HIGHSecurity vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify AccessEPSS 0.5%CVE-2026-42994HIGHBitwarden CLI 2026.4.0 from 2026-04-22T21:57Z to 2026-04-22T23:30Z, when obtained from npm, had embedded malicious code. This is related to EPSS 0.5%CVE-2021-4466HIGHIPCop <= 2.1.9 Authenticated RCEEPSS 0.5%