Falhas do tipo CWE-78

4.652 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2026-40176HIGHComposer is vulnerable to Command Injection via Malicious Perforce RepositoryEPSS 1.0%CVE-2023-44415MEDIUMD-Link Multiple Routers cli Command Injection Remote Code Execution VulnerabilityEPSS 1.0%CVE-2022-40847HIGHIn Tenda AC1200 Router model W15Ev2 V15.11.0.10(1576), there exists a command injection vulnerability in the function formSetFixTools. This EPSS 1.0%CVE-2024-20335MEDIUMA vulnerability in the web-based management interface of Cisco Small Business 100, 300, and 500 Series Wireless APs could allow an authenticEPSS 1.0%CVE-2023-28704HIGHFurbo dog camera - Command InjectionEPSS 1.0%CVE-2025-3499CRITICALUnauthenticated execution of arbitrary commands in Radiflow iSAP Smart CollectorEPSS 1.0%CVE-2023-34974HIGHQTS, QuTS hero, QuTScloud, QVR, QESEPSS 1.0%CVE-2026-11417HIGHOS Command Injection in NodejsFunction Bundling in aws-cdk-libEPSS 1.0%CVE-2026-102437HIGHImproper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in DeepSeek-ReasonixEPSS 1.0%CVE-2024-28125CRITICALFitNesse all releases allows a remote authenticated attacker to execute arbitrary OS commands. Note: A contributor of FitNesse has claimed tEPSS 1.0%CVE-2024-31976HIGHEnGenius EWS356-FIR 1.1.30 and earlier devices allow a remote attacker to execute arbitrary OS commands via the Controller connectivity paraEPSS 1.0%CVE-2026-34935CRITICALPraisonAI: OS Command Injection in MCPHandler.parse_mcp_command()EPSS 1.0%CVE-2023-20231HIGHA vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to perform an injection attack against EPSS 1.0%CVE-2025-37163HIGHAuthenticated Command Injection Vulnerability in HPE Aruba Networking Management Software (AirWave) CLIEPSS 1.0%CVE-2026-36827MEDIUMA command injection vulnerability exists in Panabit PAP-XM320 up to and including V7.7. The web management interface invokes the backend helEPSS 1.0%CVE-2025-60006MEDIUMJunos OS Evolved: OS command injection vulnerabilities fixedEPSS 1.0%CVE-2022-25962HIGHAll versions of the package vagrant.js are vulnerable to Command Injection via the boxAdd function due to improper input sanitization. EPSS 1.0%CVE-2026-5709HIGHAWS Research and Engineering Studio (RES) FileBrowser Command InjectionEPSS 1.0%CVE-2026-5707HIGHCommand Injection via Virtual Desktop Session Name in AWS Research and Engineering Studio (RES)EPSS 1.0%CVE-2026-81537HIGHDataStage on Cloud Pak for Data has several vulnerabilitiesEPSS 1.0%