Falhas do tipo CWE-78
4.660 resultadosInjeção de comando do sistema operacional
A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.
Exemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.
Como mitigar
Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.
CVE-2025-24351HIGHA vulnerability in the “Remote Logging” functionality of the web application of ctrlX OS allows a remote authenticated (low-privileged) attaEPSS 0.9%CVE-2026-61434HIGHPraisonAI before 4.6.78 Allowlist Bypass via find -execEPSS 0.9%CVE-2026-42846CRITICALClipBucket: Remote Play URL Command InjectionEPSS 0.9%CVE-2026-38615CRITICALDedeCMS V5.7.118 is vulnerable to Command Execution in file_manage_control.php.EPSS 0.9%CVE-2026-23592HIGHInsecure File Handling allows Remote Code Execution in Backup FunctionalityEPSS 0.9%CVE-2025-34186CRITICALIlevia EVE X1/X5 Server 4.7.18.0.eden Authentication BypassEPSS 0.9%CVE-2023-38056HIGHCode execution via System Configuration EPSS 0.9%CVE-2025-26320MEDIUMt0mer BroadlinkManager v5.9.1 was discovered to contain an OS command injection vulnerability via the IP Address parameter at /device/ping.EPSS 0.9%CVE-2026-19136HIGHA potential command injection vulnerability was reported in the Tianxi AI Agent PC Application, distributed exclusively in the Chinese markeEPSS 0.9%CVE-2026-45152HIGHuniget: Command Injection in tool.Check Leading to Arbitrary Code ExecutionEPSS 0.9%CVE-2025-20186HIGHA vulnerability in the web-based management interface of the Wireless LAN Controller feature of Cisco IOS XE Software could allow an authentEPSS 0.9%CVE-2026-58195HIGHAgentic-Flow: OS Command Injection in agentic-flow MCP server tools via unsanitized tool-parameter interpolation into execSyncEPSS 0.9%CVE-2023-22816MEDIUMLimited Post-Authentication Remote Command Injection in My Cloud ProductsEPSS 0.9%CVE-2024-30314HIGHDreamweaver Desktop | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)EPSS 0.9%CVE-2025-2257HIGHTotal Upkeep – WordPress Backup Plugin plus Restore & Migrate by BoldGrid <= 1.16.10 - Authenticated (Admin+) Command InjectionEPSS 0.9%CVE-2026-69320HIGHVisual Studio Code Remote Code Execution VulnerabilityEPSS 0.9%CVE-2026-28384CRITICALAuthenticated RCE via unsanitized compression_algorithmEPSS 0.9%CVE-2023-35895MEDIUMIBM Informix JDBC code executionEPSS 0.9%CVE-2023-49695MEDIUMOS command injection vulnerability in WRC-X3000GSN v1.0.2, WRC-X3000GS v1.0.24 and earlier, and WRC-X3000GSA v1.0.24 and earlier allows a neEPSS 0.9%CVE-2023-25507HIGHNVIDIA DGX-1 BMC contains a vulnerability in the SPX REST API, where an attacker with the appropriate level of authorization can inject arbiEPSS 0.9%