Falhas do tipo CWE-78

4.645 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2026-33396CRITICALOneUptime has sandbox escape in Synthetic Monitor Playwright runtime allows project members to execute arbitrary commands on ProbeEPSS 1.1%CVE-2025-28138CRITICALThe TOTOLINK A800R V4.1.2cu.5137_B20200730 were found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg functEPSS 1.1%CVE-2025-71336CRITICALFlowise - Unsandboxed Remote Code Execution via Custom MCPEPSS 1.1%CVE-2021-47748CRITICALHasura GraphQL 1.3.3 - Remote Code ExecutionEPSS 1.1%CVE-2024-53286HIGHImproper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in DDNS Record functionality in SynEPSS 1.1%CVE-2021-26726HIGHRemote code execution in Valmet DNA before Collection 2021EPSS 1.1%CVE-2025-57516HIGHOS Command injection vulnerability in PublicCMS PublicCMS-V5.202506.a, and PublicCMS-V5.202506.b allowing attackers to execute arbitrary comEPSS 1.1%CVE-2022-40741CRITICALSOFTNEXT TECHNOLOGIES CORP. Mail SQR Expert - Command InjectionEPSS 1.1%CVE-2026-5485HIGHOS command injection in Amazon Athena ODBC driver on LinuxEPSS 1.1%CVE-2025-15389HIGHQNO Technology|VPN Firewall - OS Command InjectionEPSS 1.1%CVE-2025-24383CRITICALDell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command InjectionEPSS 1.1%CVE-2023-6795MEDIUMPAN-OS: OS Command Injection Vulnerability in the Web InterfaceEPSS 1.1%CVE-2022-43654HIGHNETGEAR CAX30S SSO Command Injection Remote Code Execution VulnerabilityEPSS 1.1%CVE-2023-20163MEDIUMCisco Identity Services Engine Command Injection VulnerabilitiesEPSS 1.1%CVE-2023-20164MEDIUMCisco Identity Services Engine Command Injection VulnerabilitiesEPSS 1.1%CVE-2023-23373HIGHQUSBCam2EPSS 1.1%CVE-2025-20617HIGHImproper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in UD-LT2 firmware Ver.1.00.008_SE aEPSS 1.1%CVE-2026-41450HIGHUAC < 3.3.0 Command Injection via command_collector.shEPSS 1.1%CVE-2025-20016HIGHOS command injection vulnerability exists in network storage servers STEALTHONE D220/D340/D440 provided by Y'S corporation. A user with an aEPSS 1.1%CVE-2023-41288HIGHVideo StationEPSS 1.1%