Weaknesses of type CWE-78

4,668 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2026-97863MEDIUMmisp-modules: Shell Command Injection in MISP cisco_firesight_manager_ACL_rule_export Module via Unescaped Attribute ValuesEPSS 0.3%CVE-2021-21503HIGHPowerScale OneFS 8.1.2,8.2.2 and 9.1.0 contains an improper input sanitization issue in a command. The Compadmin user could potentially explEPSS 0.3%CVE-2026-73222HIGHClaude Code Templates: Unauthenticated OS command injection (RCE) in Claude Code Studio server (--studio)EPSS 0.3%CVE-2025-1038HIGHThe “Diagnostics Tools” page of the web-based configuration utility does not properly validate user-controlled input, allowing an authenticaEPSS 0.3%CVE-2025-20194MEDIUMA vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, low-privileged, remote attackerEPSS 0.3%CVE-2024-33793MEDIUMnetis-systems MEX605 v2.00.06 allows attackers to execute arbitrary OS commands via a crafted payload to the ping test page.EPSS 0.3%CVE-2024-37391HIGHProtonVPN before 3.2.10 on Windows mishandles the drive installer path, which should use this: '"' + ExpandConstant('{autopf}\Proton\Drive')EPSS 0.3%CVE-2025-27234HIGHZabbix Agent 2 smartctl plugin RCE vulnerability in Zabbix 5.0.EPSS 0.3%CVE-2026-34049LOWCoolify: Command Injection via unsanitized MongoDB collection names in database backupEPSS 0.3%CVE-2026-42201LOWCoolify: OS Command Injection via Database Credential Fields in Docker Compose Service CommandsEPSS 0.3%CVE-2024-40641HIGHUnsigned code template execution through workflows in projectdiscovery/nucleiEPSS 0.3%CVE-2024-1683HIGHDLL Injection in Tenable Identity Exposure Secure RelayEPSS 0.3%CVE-2020-11847HIGHVulnerability in sshrelay in privileged access manager provides full system access.EPSS 0.3%CVE-2021-1441MEDIUMCisco IOS XE Software Hardware Initialization Routines Arbitrary Code Execution VulnerabilityEPSS 0.3%CVE-2021-1529HIGHCisco IOS XE SD-WAN Software Command Injection VulnerabilityEPSS 0.3%CVE-2024-47918MEDIUMTiki Wiki CMS – CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)EPSS 0.3%CVE-2026-0654HIGHCommand injection on TP-Link Deco BE25EPSS 0.3%CVE-2026-100599HIGHOpenClaw 2026.5.1 before 2026.7.1 Remote Code Execution via googlemeet.chromeEPSS 0.3%CVE-2021-35028HIGHA command injection vulnerability in the CGI program of the Zyxel VPN2S firmware version 1.12 could allow an authenticated, local user to exEPSS 0.3%CVE-2026-33874HIGHAuthenticator vulnerable to Remote Code ExecutionEPSS 0.3%