Weaknesses of type CWE-78

4,668 results

Injeção de comandos do sistema operacional

A aplicação constrói comandos do SO usando entrada do usuário sem sanitizar adequadamente, permitindo que um atacante injete comandos arbitrários. Quando a entrada contém metacaracteres (como `|`, `;`, `&&`, backticks), o shell interpreta-os como operadores, executando código não intencional com os privilégios da aplicação.

Example

Um script PHP que executa `system('ping ' . $_GET['host'])` permite um atacante passar `127.0.0.1; rm -rf /` como parâmetro, executando deleção de arquivos. Ou em Java, `Runtime.exec()` com strings concatenadas do usuário sem validação.

How to mitigate

Use APIs que não invocam shell (ex: `execvp()` em C, arrays de parâmetros em Java/Python, ou prepared commands). Se inevitável usar shell, escape rigorosamente com funções específicas (`escapeshellarg()` em PHP) ou valide contra whitelist de caracteres permitidos. Nunca confie em blacklist de caracteres perigosos.

CVE-2025-24938HIGHInsufficient Validation of Input while user creationEPSS 0.3%CVE-2026-15069MEDIUMMultiple Vulnerabilities in IBM Engineering AI hub.EPSS 0.3%CVE-2021-34728HIGHCisco IOS XR Software Authenticated User Privilege Escalation VulnerabilitiesEPSS 0.3%CVE-2026-45562HIGHFreePBX: Authenticated Remote Code Execution in FreePBX Music on Hold (MoH) ModuleEPSS 0.3%CVE-2025-43875HIGHiSTAR Ultra, Ultra SE, Ultra G2, Ultra G2 SE, iSTAR Edge G2 - Authenticated web application command injection - getOptionsInfoEPSS 0.3%CVE-2026-61438HIGHPraisonAI before 4.6.78 Remote Code Execution via Broken AST SandboxEPSS 0.3%CVE-2026-23920HIGHHost and event action script regex validation can be bypassed in certain situations, leading to potential command injectionEPSS 0.3%CVE-2021-3459MEDIUMA privilege escalation vulnerability was reported in the MM1000 device configuration web server, which could allow privileged shell access aEPSS 0.3%CVE-2026-76226MEDIUMRenovate 43.65.0 before 43.102.11 Remote Code Execution via lockFileMaintenanceEPSS 0.3%CVE-2025-0636HIGHArbitrary Code Execution vulnerability in Ericsson RAN Compute and Site ControllerEPSS 0.3%CVE-2026-34714CRITICALVim before 9.2.0272 allows code execution that happens immediately upon opening a crafted file in the default configuration, because %{expr}EPSS 0.3%CVE-2025-43873HIGHiSTAR Ultra, Ultra SE, Ultra G2, Ultra G2 SE, iSTAR Edge G2 - Authenticated web application command injection - setFaultDebounceEPSS 0.3%CVE-2022-43867HIGHIBM Spectrum Scale command executionEPSS 0.3%CVE-2025-43876HIGHiSTAR Ultra, Ultra SE, Ultra G2, Ultra G2 SE, iSTAR Edge G2 - Authenticated web application command injection - get8021xSettingsEPSS 0.3%CVE-2026-100292HIGHImproper neutralization of special elements used in an OS command ('OS command injection') in Anjvision YSSD-RTMP-H5EPSS 0.3%CVE-2021-21526MEDIUMDell PowerScale OneFS 8.1.0 - 9.1.0 contains a privilege escalation in SmartLock compliance mode that may allow compadmin to execute arbitraEPSS 0.3%CVE-2025-22606HIGHCoolify Command Injection Vulnerability in Project NameEPSS 0.3%CVE-2025-25269HIGHLocal Privilege Escalation via Unauthenticated Command InjectionEPSS 0.3%CVE-2025-59172HIGHImproper Neutralization of Special Elements used in an OS Command VulnerabilityEPSS 0.3%CVE-2021-34719HIGHCisco IOS XR Software Authenticated User Privilege Escalation VulnerabilitiesEPSS 0.3%