Fallos del tipo CWE-78

4660 resultados

Injeção de Comando do Sistema Operacional

A aplicação constrói comandos do SO (shell, cmd.exe, etc.) usando dados de entrada do usuário ou de fontes externas sem validar ou sanitizar adequadamente. Um atacante consegue injetar metacaracteres especiais (como ;, |, &, `, $()) para executar comandos arbitrários além daqueles originalmente planejados.

Ejemplo

Uma API que executa `ping hostname` recebendo o hostname como parâmetro GET faz isso: `exec('ping ' + request.query.host)`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Cómo mitigar

Evite construir comandos concatenando strings com entrada externa — use bibliotecas que parametrizem comandos ou listas de argumentos (como execFile no Node.js, subprocess com lista em Python, ProcessBuilder em Java). Se for inevitável, valide contra uma whitelist rígida e, se disponível, use modo restrito do shell (sh -c com argumentos seguros) ou contenha a execução em sandbox/container.

CVE-2026-73224HIGHElecterm check folder size function may get attacked by unsafe folder nameEPSS 0.7%CVE-2025-45379HIGHDell CloudLink, versions prior to 8.2, contain a vulnerability where a privileged user with known password can run command injection from coEPSS 0.7%CVE-2026-84440HIGHIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 0.7%CVE-2025-8650MEDIUMKenwood DMX958XR libSystemLib Command Injection Remote Code Execution VulnerabilityEPSS 0.7%CVE-2025-8651MEDIUMKenwood DMX958XR JKWifiService Command Injection Remote Code Execution VulnerabilityEPSS 0.7%CVE-2025-8652MEDIUMKenwood DMX958XR JKWifiService Command Injection Remote Code Execution VulnerabilityEPSS 0.7%CVE-2025-8649MEDIUMKenwood DMX958XR JKWifiService Command Injection Remote Code Execution VulnerabilityEPSS 0.7%CVE-2025-8655MEDIUMKenwood DMX958XR libSystemLib Command injection Remote Code Execution VulnerabilityEPSS 0.7%CVE-2024-20459MEDIUMCisco ATA 190 Series Analog Telephone Adapter Muliplatform Firmware Command Injection VulnerabilityEPSS 0.7%CVE-2026-55578HIGHPheditor: Incomplete command sanitization in terminal feature allows RCE via pipe operator, backtick substitution, and newline injectionEPSS 0.7%CVE-2021-1421HIGHCisco Enterprise NFV Infrastructure Software Command Injection VulnerabilityEPSS 0.7%CVE-2026-77120HIGHCWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause priEPSS 0.7%CVE-2026-54051CRITICALNetwork-AI has an an OS Command Injection issueEPSS 0.7%CVE-2026-79755HIGHNuclio: Unauthenticated OS command injection via function namespace in docker ps --filter label (local Docker platform)EPSS 0.7%CVE-2026-44444CRITICALLumiverse: Spindle extension install runs untrusted lifecycle scripts before security scanEPSS 0.7%CVE-2026-73753HIGHAuthenticated Remote Command Injection Vulnerabilities in AOS-CX Command Line InterfaceEPSS 0.7%CVE-2026-20099MEDIUMCisco UCS Manager and FXOS Software Command Injection VulnerabilityEPSS 0.7%CVE-2026-14499HIGHLangflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpointsEPSS 0.7%CVE-2026-18683HIGHIBM i is Affected By privilege escalation in Navigator for iEPSS 0.7%CVE-2023-4856HIGH A format string vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user to execute arbitrary commands on a EPSS 0.7%