Falhas do tipo CWE-78

4.645 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2026-0854HIGHMerit LILIN|NVR - OS Command InjectionEPSS 1.2%CVE-2022-21143HIGHAirspan Networks Mimosa OS Command InjectionEPSS 1.2%CVE-2021-38470CRITICALInHand Networks IR615 RouterEPSS 1.2%CVE-2021-38478CRITICALInHand Networks IR615 RouterEPSS 1.2%CVE-2025-61591HIGHCursor CLI's Cursor Agent MCP OAuth2 Communication is Vulnerable to Remote Code ExecutionEPSS 1.2%CVE-2026-84675HIGHOS command injection vulnerability in Jenkins TICS Plugin 2025.1.1 and earlier allows attackers able to control build environment variable vEPSS 1.2%CVE-2026-22761MEDIUMDell PowerProtect Data Domain, versions 8.5 through 8.6 contain a command injection vulnerability. A high privileged attacker with remote acEPSS 1.2%CVE-2026-13760HIGHOS Command Injection in aws-cdk-lib Docker BundlingEPSS 1.2%CVE-2026-1460HIGHA post-authentication command injection vulnerability in the “DomainName” parameter of the DHCP configuration file in Zyxel DX3301-T0 and EXEPSS 1.2%CVE-2025-36529HIGHAn OS command injection issue exists in multiple versions of TB-eye network recorders and AHD recorders. If this vulnerability is exploited,EPSS 1.2%CVE-2024-57595CRITICALDLINK DIR-825 REVB 2.03 devices have an OS command injection vulnerability in the CGl interface apc_client_pin.cgi, which allows remote attaEPSS 1.2%CVE-2025-59518HIGHIn LemonLDAP::NG before 2.16.7 and 2.17 through 2.21 before 2.21.3, OS command injection can occur in the Safe jail. It does not Localize _ EPSS 1.2%CVE-2026-97366MEDIUMjhen0409 react-native-debugger Open in Editor window.js openDevTools os command injectionEPSS 1.2%CVE-2022-3133HIGHOS Command Injection in jgraph/drawioEPSS 1.2%CVE-2026-44724HIGHsysteminformation: Linux command injection in networkInterfaces() via unsanitized NetworkManager connection profile nameEPSS 1.2%CVE-2024-34073HIGHCommand Injection in sagemaker-python-sdkEPSS 1.2%CVE-2024-14010HIGHTypora 1.7.4 OS Command Injection via Export PDF PreferencesEPSS 1.2%CVE-2023-44080—An issue in PGYER codefever v.2023.8.14-2ce4006 allows a remote attacker to execute arbitrary code via a crafted request to the branchList cEPSS 1.2%CVE-2024-54024HIGHAn improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiIsolatEPSS 1.2%CVE-2022-47555CRITICALImproper Neutralization of Special Elements in Ormazabal productsEPSS 1.1%