Falhas do tipo CWE-78

4.630 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2022-39224HIGHArbitrary shell execution when extracting or listing files contained in a malicious rpm.EPSS 1.5%CVE-2022-37898HIGHAuthenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilitieEPSS 1.5%CVE-2023-28528HIGHIBM AIX command executionEPSS 1.5%CVE-2025-14287HIGHCommand Injection in mlflow/mlflowEPSS 1.5%CVE-2026-32649HIGHMilesight Cameras OS Command InjectionEPSS 1.5%CVE-2023-51450MEDIUMbaserCMS OS command injection vulnerability in InstallerEPSS 1.5%CVE-2023-27991HIGHThe post-authentication command injection vulnerability in the CLI command of Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEXEPSS 1.5%CVE-2023-40069CRITICALOS command injection vulnerability in ELECOM wireless LAN routers allows an attacker who can access the product to execute an arbitrary OS cEPSS 1.5%CVE-2026-81937HIGHIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 1.5%CVE-2025-49141HIGHHaxCMS-PHP Command Injection VulnerabilityEPSS 1.5%CVE-2020-36910HIGHCayin Signage Media Player 3.0 Authenticated Remote Command Injection via NTP ParameterEPSS 1.5%CVE-2026-84071HIGHIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 1.5%CVE-2026-40527HIGHradare2 Command Injection via DWARF Parameter NamesEPSS 1.5%CVE-2021-28811HIGHVulnerability in Roon ServerEPSS 1.5%CVE-2021-34349HIGHCommand Injection Vulnerability in QVREPSS 1.5%CVE-2026-31181CRITICALAn issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunSerEPSS 1.4%CVE-2026-6721CRITICALMultiple Vulnerabilities in IBM Concert SoftwareEPSS 1.4%CVE-2026-31177CRITICALAn issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunMinEPSS 1.4%CVE-2026-31178CRITICALAn issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stunMaxEPSS 1.4%CVE-2020-7879HIGHipTIME C200 IP Camera command injection vulnerabilityEPSS 1.4%