Falhas do tipo CWE-78
4.653 resultadosInjeção de comando do sistema operacional
A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.
Exemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.
Como mitigar
Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.
CVE-2023-35850HIGHSUNNET WMPro - Command InjectionEPSS 0.9%CVE-2023-24841HIGHHGiga MailSherlock - Command InjectionEPSS 0.9%CVE-2025-33206HIGHNVIDIA NSIGHT Graphics for Linux contains a vulnerability where an attacker could cause command injection. A successful exploit of this vulnEPSS 0.9%CVE-2023-37863HIGHPHOENIX CONTACT: OS Command Injection in WP 6xxx Web panelsEPSS 0.9%CVE-2024-25468HIGHAn issue in TOTOLINK X5000R V.9.1.0u.6369_B20230113 allows a remote attacker to cause a denial of service via the host_time parameter of theEPSS 0.9%CVE-2024-35306HIGHOS Command injection in Ajax PHP files through HTTP RequestEPSS 0.9%CVE-2026-63586CRITICALUnauthenticated Remote Code Execution via Shell Injection in Web Management InterfaceEPSS 0.9%CVE-2025-67264HIGHAn OS command injection vulnerability in the com.sprd.engineermode component in Doogee Note59, Note59 Pro, and Note59 Pro+ allows a local atEPSS 0.9%CVE-2023-53981HIGHPhotoShow 3.0 Remote Code Execution via Exiftran Path InjectionEPSS 0.9%CVE-2026-40288CRITICALPraisonAI: Critical RCE via `type: job` workflow YAMLEPSS 0.9%CVE-2026-73625HIGHGitPython before 3.1.54 Remote Code Execution via kwarg value smugglingEPSS 0.9%CVE-2026-28507HIGHIdno: Remote Code Execution via Chained Import File Write and Template Path TraversalEPSS 0.9%CVE-2026-23500CRITICALDolibarr: OS Command Injection (RCE) via MAIN_ODT_AS_PDF configurationEPSS 0.9%CVE-2026-85426CRITICALMOOS-IvP through 24.8.1 uMemWatch Command Injection via MOOS Client NamesEPSS 0.9%CVE-2025-60963HIGHOS Command Injection vulnerability in EndRun Technologies Sonoma D12 Network Time Server (GPS) F/W 6010-0071-000 Ver 4.00 allows attackers tEPSS 0.9%CVE-2019-12091HIGHNetskope client command injections vulnerabilityEPSS 0.9%CVE-2026-22313CRITICALOS Commands Executed with Administrative Permissions in Radiflow iSAP Smart CollectorEPSS 0.9%CVE-2026-16843HIGHSome Hikvision Networking Products are vulnerable to authenticated command execution due to insufficient input validation. Attackers with vaEPSS 0.9%CVE-2026-21837HIGHHCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management APIEPSS 0.9%CVE-2026-7246HIGH[DISPUTED] Pallets Click contains a command injection via Unsanitized Filename "click.edit()"EPSS 0.9%