Falhas do tipo CWE-78

4.644 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2022-24390HIGHAuthenticated Command Injection Vulnerability in Fidelis Network and DeceptionEPSS 1.3%CVE-2026-24788HIGHRaspAP raspap-webgui versions prior to 3.3.6 contain an OS command injection vulnerability. If exploited, an arbitrary OS command may be exeEPSS 1.3%CVE-2024-12829HIGHArista NG Firewall ExecManagerImpl Command Injection Remote Code Execution VulnerabilityEPSS 1.3%CVE-2026-8659MEDIUMOS Command Injection in Rapid7 InsightConnect SQLmap PluginEPSS 1.3%CVE-2026-8664MEDIUMOS Command Injection in Rapid7 InsightConnect Finger PluginEPSS 1.3%CVE-2026-8663MEDIUMOS Command Injection in Rapid7 InsightConnect RPM PluginEPSS 1.3%CVE-2026-8658MEDIUMOS Command Injection in Rapid7 InsightConnect Tcpdump PluginEPSS 1.3%CVE-2026-0630HIGHCommand Injection Vulnerability on TP-Link Archer BE230 v1.2 and AXE75 v1.0EPSS 1.3%CVE-2023-37213HIGH Synel SYnergy Fingerprint Terminals - CWE-78: 'OS Command Injection'EPSS 1.3%CVE-2024-21532HIGHAll versions of the package ggit are vulnerable to Command Injection via the fetchTags(branch) API, which allows user input to specify the bEPSS 1.3%CVE-2023-25699CRITICALWordPress VideoWhisper Live Streaming Integration plugin <= 5.5.15 - Remote Code Execution (RCE)EPSS 1.3%CVE-2023-41347HIGHASUS RT-AX55 - command injection - 3EPSS 1.3%CVE-2023-41348HIGHASUS RT-AX55 - command injection - 4EPSS 1.3%CVE-2023-41345HIGHASUS RT-AX55 - command injection - 1EPSS 1.3%CVE-2026-67394CRITICALA critical local privilege escalation via OS command injection vulnerability has been discovered in Plesk for Linux, affecting all versions EPSS 1.3%CVE-2025-34148CRITICALShenzhen Aitemi M300 Wi-Fi Repeater OS Command Injection via WISP SSIDEPSS 1.3%CVE-2026-85979HIGHCommand Injection in Puppet EnterpriseEPSS 1.3%CVE-2025-0110HIGHPAN-OS OpenConfig Plugin: Command Injection Vulnerability in OpenConfig PluginEPSS 1.3%CVE-2022-33869HIGHAn improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface of FortiWAN 4.0.0 thEPSS 1.3%CVE-2026-40933CRITICALFlowise: Authenticated RCE Via MCP AdaptersEPSS 1.3%