Falhas do tipo CWE-78

4.638 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2026-6849HIGHOS Command Injection in TUBITAK BILGEM's Pardus OS My ComputerEPSS 1.4%CVE-2023-35893CRITICALIBM Security Guardium command executionEPSS 1.4%CVE-2023-51585HIGHVoltronic Power ViewPower USBCommEx shutdown Command Injection Remote Code Execution VulnerabilityEPSS 1.4%CVE-2024-45763CRITICALDell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS CommEPSS 1.4%CVE-2024-45765CRITICALDell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS CommEPSS 1.4%CVE-2025-33228HIGHNVIDIA Nsight Systems contains a vulnerability in the gfx_hotspot recipe, where an attacker could cause an OS command injection by supplyingEPSS 1.4%CVE-2025-33230HIGHNVIDIA Nsight Systems for Linux contains a vulnerability in the .run installer, where an attacker could cause an OS command injection by supEPSS 1.4%CVE-2026-3964MEDIUMOpenAkita Chat API Endpoint shell.py run os command injectionEPSS 1.4%CVE-2021-34602HIGHBender Charge Controller: Long URL could lead to webserver crashEPSS 1.4%CVE-2025-1229MEDIUMolajowon Loggrove page os command injectionEPSS 1.4%CVE-2023-28394HIGHBeekeeper Studio versions prior to 3.9.9 allows a remote authenticated attacker to execute arbitrary JavaScript code with the privilege of tEPSS 1.4%CVE-2026-45087CRITICALDalfox: Unauthenticated Remote Code Execution via `found-action` in Dalfox Server ModeEPSS 1.4%CVE-2023-39236HIGHASUS RT-AC86U - Command injection vulnerability - 4EPSS 1.4%CVE-2023-38033HIGHASUS RT-AC86U - Command injection vulnerability - 3EPSS 1.4%CVE-2023-38032HIGHASUS RT-AC86U - Command injection vulnerability - 2EPSS 1.4%CVE-2023-38031HIGHASUS RT-AC86U - Command injection vulnerability - 1EPSS 1.4%CVE-2023-39237HIGHASUS RT-AC86U - Command injection vulnerability - 5EPSS 1.4%CVE-2025-29040CRITICALAn issue in dlink DIR 823x 240802 allows a remote attacker to execute arbitrary code via the target_addr key value and the function 0x41737cEPSS 1.4%CVE-2023-0118CRITICALForeman: arbitrary code execution through templatesEPSS 1.4%CVE-2022-50919CRITICALTdarr 2.00.15 - Command InjectionEPSS 1.4%