Falhas do tipo CWE-78
4.653 resultadosInjeção de comando do sistema operacional
A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.
Exemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.
Como mitigar
Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.
CVE-2025-22481HIGHQTS, QuTS heroEPSS 0.9%CVE-2026-17431MEDIUMPDF::WebKit versions through 1.2 for Perl allow OS command injection via a 2-arg open() of the output path in to_pdf and of stylesheet paths in _style_tag_forEPSS 0.9%CVE-2026-100382CRITICALUnauthenticated remote code execution through wikitext in ExternalDataEPSS 0.9%CVE-2025-26389CRITICALA vulnerability has been identified in OZW672 (All versions < V8.0), OZW772 (All versions < V8.0). The web service in affected devices does EPSS 0.9%CVE-2023-50204HIGHD-Link G416 flupl pythonapp Command Injection Remote Code Execution VulnerabilityEPSS 0.9%CVE-2023-50203HIGHD-Link G416 nodered chmod Command Injection Remote Code Execution VulnerabilityEPSS 0.9%CVE-2024-21531MEDIUMAll versions of the package git-shallow-clone are vulnerable to Command injection due to missing sanitization or mitigation flags in the proEPSS 0.9%CVE-2023-50215HIGHD-Link G416 nodered gz File Handling Command Injection Remote Code Execution VulnerabilityEPSS 0.9%CVE-2023-50214HIGHD-Link G416 nodered tar File Handling Command Injection Remote Code Execution VulnerabilityEPSS 0.9%CVE-2023-7093MEDIUMKylinSoft kylin-system-updater com.kylin.systemupgrade Service UpgradeStrategiesDbus.py os command injectionEPSS 0.9%CVE-2025-0457HIGHNetVision Information airPASS - OS Command InjectionEPSS 0.9%CVE-2026-12940CRITICALLangflow is affected by remote code execution due to multiple unauthenticated and insufficiently authorized API endpointsEPSS 0.9%CVE-2023-23356MEDIUMQuFirewallEPSS 0.9%CVE-2026-80379HIGHDataStage on Cloud Pak for Data has several vulnerabilitiesEPSS 0.9%CVE-2025-14737HIGHCommand Injection Vulnerability in TP-Link WA850REEPSS 0.9%CVE-2024-45880HIGHA command injection vulnerability exists in Motorola CX2L router v1.0.2 and below. The vulnerability is present in the SetStationSettings fuEPSS 0.9%CVE-2023-3314HIGH
A vulnerability arises out of a failure to comprehensively sanitize the processing of a zip file(s). Incomplete neutralization of external EPSS 0.9%CVE-2026-80425HIGHDataStage on Cloud Pak for Data has several vulnerabilitiesEPSS 0.9%CVE-2025-8630MEDIUMKenwood DMX958XR Firmware Update Command Injection VulnerabilityEPSS 0.9%CVE-2025-8629MEDIUMKenwood DMX958XR Firmware Update Command Injection VulnerabilityEPSS 0.9%