Falhas do tipo CWE-78

4.662 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2026-15427HIGHOS Command Injection in TR-069 (CWMP) Management Interface in TP-Link Archer VX1800vEPSS 0.8%CVE-2024-1628HIGHOS command injection vulnerabilities in GE HealthCare ultrasound devicesEPSS 0.8%CVE-2026-85168HIGHn8n before 1.123.73 Remote Code Execution via Git NodeEPSS 0.8%CVE-2026-73623HIGHGitPython before 3.1.54 Remote Code Execution via --templateEPSS 0.8%CVE-2025-46117CRITICALAn issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.14 and 200.17.7.0.139, and in Ruckus ZoneDirector prior to 10.5.EPSS 0.8%CVE-2026-21267HIGHDreamweaver Desktop | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)EPSS 0.8%CVE-2026-18268HIGHKenwood DNR1007XR JKGenService Command Injection Local Privilege Escalation VulnerabilityEPSS 0.8%CVE-2026-41208HIGHPaperclip: Privilege Escalation via Agent-Controlled workspaceStrategy.provisionCommand Leading to OS Command ExecutionEPSS 0.8%CVE-2024-25579MEDIUMOS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent attacker with an administrative privilege to exeEPSS 0.8%CVE-2024-53692MEDIUMQTS, QuTS heroEPSS 0.8%CVE-2024-22372MEDIUMOS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent attacker with an administrative privilege to exeEPSS 0.8%CVE-2022-20655HIGHA vulnerability in the implementation of the CLI on a device that is running ConfD could allow an authenticated, local attacker to perform aEPSS 0.8%CVE-2024-20277MEDIUMA vulnerability in the web-based management interface of Cisco ThousandEyes Enterprise Agent, Virtual Appliance installation type, could allEPSS 0.8%CVE-2023-21410HIGHNon-sanitized user input could lead to arbitrary code execution in AXIS License Plate VerifierEPSS 0.8%CVE-2025-54958MEDIUMPowered BLUE 870 versions 0.20130927 and prior contain an OS command injection vulnerability. If this vulnerability is exploited, arbitrary EPSS 0.8%CVE-2023-21411HIGHNon-sanitized user input could lead to arbitrary code execution during Access Control configuration in AXIS License Plate VerifierEPSS 0.8%CVE-2023-49235CRITICALAn issue was discovered in libremote_dbg.so on TRENDnet TV-IP1314PI 5.5.3 200714 devices. Filtering of debug information is mishandled durinEPSS 0.8%CVE-2026-0302LOWCheckov by Prisma Cloud: OS Command Injection VulnerabilityEPSS 0.8%CVE-2026-9277CRITICALshell-quote `quote()` does not validate object-token shapes, allowing command injection via line terminators in `.op`EPSS 0.8%CVE-2024-10019MEDIUMPath Traversal and OS Command Injection in parisneo/lollms-webuiEPSS 0.8%