Weaknesses of type CWE-78

4,668 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2026-45393HIGHLocal privilege escalation to SYSTEM in Cribl Edge for WindowsEPSS 0.4%CVE-2026-27955MEDIUMCoolify: Command Injection via Single-Quote Breakout in `executeInDocker()`EPSS 0.4%CVE-2026-90444HIGHOS Command Injection in MalcolmEPSS 0.4%CVE-2026-8654HIGHImproper input validation in Delphix Continuous Data connectors allows an authenticated user to execute arbitrary operating system commands EPSS 0.4%CVE-2026-34955HIGHPraisonAI: Sandbox Escape via shell=True and Bypassable Blocklist in SubprocessSandboxEPSS 0.4%CVE-2025-67037HIGHLantronix EDS5000, G520, and X300 OS Command InjectionEPSS 0.4%CVE-2025-67036HIGHLantronix EDS5000, G520, and X300 OS Command InjectionEPSS 0.4%CVE-2026-79766CRITICALTermix: OS command injection in ACME/Let's Encrypt certificate-request handler via admin-controlled domain/emailEPSS 0.4%CVE-2025-3189MEDIUMStored Cross-Site Scripting (XSS) in DoWISPEPSS 0.4%CVE-2026-84256HIGHAn argument parsing issue in OpenVPN 2.1_rc10 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows remote authenticated users to exEPSS 0.4%CVE-2026-102422CRITICALshell-quote `quote()` command injection via a line terminator in a token after a `{ comment }` tokenEPSS 0.4%CVE-2025-43908MEDIUMDell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2025 releasEPSS 0.4%CVE-2025-10239HIGHUnintended command execution via troubleshooting scripts in Progress FlowmonEPSS 0.4%CVE-2026-85439HIGHMOOS-IvP through 24.8.1 alogsplit Command Injection via Input PathnameEPSS 0.4%CVE-2024-10896MEDIUMLogo Slider < 4.5.0 - Contributor+ Stored XSSEPSS 0.4%CVE-2020-3459MEDIUMCisco FXOS Software for Firepower 4100/9300 Series Command Injection VulnerabilityEPSS 0.4%CVE-2025-70039CRITICALAn issue pertaining to CWE-78: Improper Neutralization of Special Elements used in an OS Command was discovered in linagora Twake v2023.Q1.1EPSS 0.4%CVE-2026-33030HIGHNginx UI: Unencrypted Storage of DNS API Tokens and ACME Private KeysEPSS 0.4%CVE-2021-1370HIGHCisco IOS XR Software for Cisco 8000 Series Routers and Network Convergence System 540 Series Routers Privilege Escalation VulnerabilityEPSS 0.4%CVE-2026-9560CRITICALPrivilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands wEPSS 0.4%