Falhas do tipo CWE-78
4.653 resultadosInjeção de comando do sistema operacional
A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.
Exemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.
Como mitigar
Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.
CVE-2026-72867CRITICALDokploy: Incomplete fix of CVE-2026-45628: Command Injection via Unvalidated Branch Fields in Compose Deployment Pipeline (server-side regex missing in compose.ts)EPSS 1.0%CVE-2026-72901CRITICALDokploy: Remote Code Execution via volume-backupEPSS 1.0%CVE-2025-10589HIGHN-Partner|N-Reporter, N-Cloud, N-Probe - OS Command InjectionEPSS 1.0%CVE-2026-7863HIGHOS Command Injection in TUBITAK BILGEM's Pardus SoftwareEPSS 1.0%CVE-2024-0165HIGH
Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_acldb_dump utility. An authenticated attacker EPSS 1.0%CVE-2022-25855HIGHAll versions of the package create-choo-app3 are vulnerable to Command Injection via the devInstall function due to improper user-input saniEPSS 1.0%CVE-2026-11845HIGHIEI Integration Corp|iVEC-IEI Virtualization Edge Computer - OS Command InjectionEPSS 1.0%CVE-2024-10119CRITICALSECOM WRTM326 - OS Command InjectionEPSS 1.0%CVE-2022-43642HIGHThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-825 1.0.9/EE routers.EPSS 0.9%CVE-2022-43644HIGHThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-825 1.0.9/EE routers.EPSS 0.9%CVE-2022-43647HIGHThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-825 1.0.9/EE routers.EPSS 0.9%CVE-2022-43645HIGHThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-825 1.0.9/EE routers.EPSS 0.9%CVE-2022-43646HIGHThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-825 1.0.9/EE routers.EPSS 0.9%CVE-2026-22901MEDIUMQuNetSwitchEPSS 0.9%CVE-2026-0507HIGHOS Command Injection vulnerability in SAP Application Server for ABAP and SAP NetWeaver RFCSDKEPSS 0.9%CVE-2023-26127HIGHAll versions of the package n158 are vulnerable to Command Injection due to improper input sanitization in the 'module.exports' function.
*EPSS 0.9%CVE-2025-8637MEDIUMKenwood DMX958XR Firmware Update Command Injection VulnerabilityEPSS 0.9%CVE-2025-8632MEDIUMKenwood DMX958XR Firmware Update Command Injection VulnerabilityEPSS 0.9%CVE-2025-8636MEDIUMKenwood DMX958XR Firmware Update Command Injection VulnerabilityEPSS 0.9%CVE-2025-8633MEDIUMKenwood DMX958XR Firmware Update Command Injection VulnerabilityEPSS 0.9%