Falhas do tipo CWE-78
4.662 resultadosInjeção de comando do sistema operacional
A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.
Exemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.
Como mitigar
Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.
CVE-2026-16882CRITICALVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.9%CVE-2026-67965CRITICALAn issue in Tneda W20E v.16.01.0.6(2782) allows a remote attacker to execute arbitrary code via the url_need_login functionEPSS 0.9%CVE-2025-59783HIGHOS Command Injection over APIEPSS 0.9%CVE-2026-16956CRITICALIBM Db2 Mirror for i is vulnerable to OS command injection []EPSS 0.9%CVE-2022-43628MEDIUMThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-1935 1.03 routers. AlEPSS 0.9%CVE-2021-3061MEDIUMPAN-OS: OS Command Injection Vulnerability in the Command Line Interface (CLI)EPSS 0.9%CVE-2020-37012CRITICALTea LaTex 1.0 - Remote Code ExecutionEPSS 0.9%CVE-2026-71963HIGHHermes Agent 0.18.2 - 0.21.0 RCE via git core.fsmonitor Config InjectionEPSS 0.9%CVE-2026-40187HIGHAuthenticated RCE via Malicious eTemplate Upload in EGroupwareEPSS 0.9%CVE-2026-28673HIGHxiaoheiFS Vulnerable to RCE via Unrestricted Plugin Installation (Manifest Manipulation)EPSS 0.9%CVE-2026-73667HIGHOpenChoreo: Authenticated OS command injection via OpenChoreo Workflow Plane templates enables code execution in privileged podsEPSS 0.9%CVE-2026-81545HIGHDataStage on Cloud Pak for Data has several vulnerabilitiesEPSS 0.9%CVE-2022-25597HIGHASUS RT-AC86U - Command InjectionEPSS 0.9%CVE-2024-39607MEDIUMOS command injection vulnerability exists in ELECOM wireless LAN routers. A specially crafted request may be sent to the affected product byEPSS 0.9%CVE-2025-8890CRITICALAuthenticated RCE in SDMC NE6037 routerEPSS 0.9%CVE-2026-42454CRITICALTermix: OS Command Injection in Docker Container Management EndpointsEPSS 0.9%CVE-2026-79423HIGHAn authenticated remote code execution (RCE) vulnerability in the admin_config.php component of seacms v13.6 allows attackers to execute arbEPSS 0.9%CVE-2026-55378CRITICALJS Recon: Command injection in PR Branch Checker workflow via untrusted pull request context valuesEPSS 0.8%CVE-2026-0711MEDIUMA post-authentication command injection vulnerability in the EasyMesh-related APIs of Zyxel DX3300-T0 firmware versions through 5.50(ABVY.7.EPSS 0.8%CVE-2021-0218HIGHJunos OS: Command injection vulnerability in license-check daemonEPSS 0.8%