Weaknesses of type CWE-78

4,668 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2026-45255HIGHRemote code execution via installer Wi-Fi access point scansEPSS 0.3%CVE-2025-46334HIGHGit GUI malicious command injection on WindowsEPSS 0.3%CVE-2025-54430CRITICALdedupe is vulnerable to secret exfiltration via `issue_comment`EPSS 0.3%CVE-2022-20865MEDIUMCisco FXOS Software Command Injection VulnerabilityEPSS 0.3%CVE-2024-20326HIGHA vulnerability in the ConfD CLI and the Cisco Crosswork Network Services Orchestrator CLI could allow an authenticated, low-privileged, loEPSS 0.3%CVE-2024-32477HIGHRace condition when flushing input stream leads to permission prompt bypassEPSS 0.3%CVE-2026-40111CRITICALPraisonAIAgents has an OS Command Injection via shell=True in Memory Hooks Executor (memory/hooks.py)EPSS 0.3%CVE-2025-36143MEDIUMIBM watsonx.data command executionEPSS 0.3%CVE-2023-29120CRITICALUnauthorized Remote Command Execution in Enel X JuiceboxEPSS 0.3%CVE-2024-29189HIGHansys-geometry-core OS Command Injection vulnerabilityEPSS 0.3%CVE-2026-71567HIGHUser-controlled variables inserted unescaped into shell scripts and Kubernetes manifestsEPSS 0.3%CVE-2023-34642HIGHKioWare for Windows through v8.33 was discovered to contain an incomplete blacklist filter for blocked dialog boxes on Windows 10. This issuEPSS 0.3%CVE-2022-24753HIGHCode injection in Stripe CLI on windowsEPSS 0.3%CVE-2025-36354HIGHIBM Security Verify Access command executionEPSS 0.3%CVE-2021-32556LOWapport get_modified_conffiles() function command injectionEPSS 0.3%CVE-2025-10568MEDIUMHyperX NGENUITY - Arbitrary Code ExecutionEPSS 0.3%CVE-2025-27398LOWA vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0). Affected devices do not properly neutralEPSS 0.3%CVE-2021-1557MEDIUMCisco DNA Spaces Connector Privilege Escalation VulnerabilitiesEPSS 0.3%CVE-2021-1558MEDIUMCisco DNA Spaces Connector Privilege Escalation VulnerabilitiesEPSS 0.3%CVE-2024-22366MEDIUMActive debug code exists in Yamaha wireless LAN access point devices. If a logged-in user who knows how to use the debug function accesses tEPSS 0.3%