Falhas do tipo CWE-78

4.640 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2022-50919CRITICALTdarr 2.00.15 - Command InjectionEPSS 1.4%CVE-2023-0164HIGHOrangeScrum version 2.0.11 allows an authenticated external attacker to execute arbitrary commands on the server. This is possible because tEPSS 1.4%CVE-2025-47900HIGHRCE on backup configuration passwordEPSS 1.4%CVE-2025-41272CRITICALNozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the EPSS 1.4%CVE-2025-47901HIGHRCE on restore configuration passwordEPSS 1.4%CVE-2025-41274CRITICALNozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the EPSS 1.4%CVE-2025-41269CRITICALNozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the EPSS 1.4%CVE-2025-41275CRITICALNozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the EPSS 1.4%CVE-2025-41277CRITICALNozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the EPSS 1.4%CVE-2025-41276CRITICALNozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the EPSS 1.4%CVE-2025-41270CRITICALNozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the EPSS 1.4%CVE-2022-40954MEDIUMApache Airflow Spark Provider RCE that bypass restrictions to read arbitrary filesEPSS 1.4%CVE-2025-62354CRITICALImproper neutralization of special elements used in an OS command ('command injection') in Cursor allows an unauthorized attacker to executeEPSS 1.4%CVE-2026-48547HIGHKanaDojo < 0.1.18 Command Injection via patchNotesData.json in release.ymlEPSS 1.4%CVE-2026-27613CRITICALCGI Parameter Injection (Bypass of STRICT_CGI_PARAMS and EscapeShellParam)EPSS 1.4%CVE-2023-27367HIGHNETGEAR RAX30 libcms_cli Command Injection Remote Code Execution VulnerabilityEPSS 1.4%CVE-2022-50691CRITICALMiniDVBLinux 5.4 Remote Root Command Execution via commands.shEPSS 1.4%CVE-2020-24552MEDIUMAtop Technology 3G/4G LTE Cellular to Ethernet and Serial Secure Industrial Gateway - Command InjectionEPSS 1.4%CVE-2025-12489HIGHevernote-mcp-server openBrowser Command Injection Privilege Escalation VulnerabilityEPSS 1.4%CVE-2026-20306CRITICALCisco Identity Services Engine Command Injection VulnerabilityEPSS 1.4%