Falhas do tipo CWE-78
4.652 resultadosInjeção de comando do sistema operacional
A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.
Exemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.
Como mitigar
Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.
CVE-2026-32950HIGHSQLBot: RCE via SQL Injection in Excel Upload EndpointEPSS 1.0%CVE-2026-81349HIGHAzure HDInsight Ambari Elevation of Privilege VulnerabilityEPSS 1.0%CVE-2025-0676HIGHCommend Injection Leading to Privilege EscalationEPSS 1.0%CVE-2024-45252CRITICALElsight – CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')EPSS 1.0%CVE-2026-87898CRITICALOS command injection in Plesk allows remote authenticated users to execute arbitrary code with root privileges.EPSS 1.0%CVE-2024-45251CRITICALElsight – CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')EPSS 1.0%CVE-2024-38511HIGHA privilege escalation vulnerability was discovered in an upload processing functionality of XCC that could allow an authenticated XCC user EPSS 1.0%CVE-2024-38512HIGHA privilege escalation vulnerability was discovered in XCC that could allow an authenticated XCC user with elevated privileges to perform coEPSS 1.0%CVE-2025-24817HIGHAn OS Command Injection vulnerability in Nokia MantaRay NMEPSS 1.0%CVE-2023-26129HIGHAll versions of the package bwm-ng are vulnerable to Command Injection due to improper input sanitization in the 'check' function in the bwmEPSS 1.0%CVE-2025-54795HIGHClaude Code echo command allowed bypass of user approval prompt for command executionEPSS 1.0%CVE-2025-27797CRITICALOS command injection vulnerability in the specific service exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If exploited, an arbitrary OS commaEPSS 1.0%CVE-2025-60738CRITICALAn issue in Ilevia EVE X1 Server Firmware Version v4.7.18.0.eden and before Logic Version v6.00 - 2025_07_21 and before allows a remote attaEPSS 1.0%CVE-2024-55590HIGHMultiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet ForEPSS 1.0%CVE-2026-16812CRITICALVeloCloud Orchestrator OS Command InjectionEPSS 1.0%KEVCVE-2024-52020HIGHNetgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the wan_gateway parameter at wiz_fix2.cgi. This vulnEPSS 1.0%CVE-2024-52021HIGHNetgear R8500 v1.0.2.160 was discovered to contain a command injection vulnerability in the wan_gateway parameter at bsw_fix.cgi. This vulneEPSS 1.0%CVE-2026-84838HIGHRpm: command injection in rpmuncompress via unescaped filenames passed to popen()EPSS 1.0%CVE-2026-35519HIGHPi-hole FTL affected by Remote Code Execution (RCE) via dns.hostRecord Newline InjectionEPSS 1.0%CVE-2024-43778HIGHOS command injection vulnerability in multiple digital video recorders provided by TAKENAKA ENGINEERING CO., LTD. allows a remote authenticaEPSS 1.0%