Falhas do tipo CWE-78

4.664 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2025-34160CRITICALAnyShare ServiceAgent API Unauthenticated RCEEPSS 0.8%CVE-2025-42892MEDIUMOS Command Injection vulnerability in SAP Business ConnectorEPSS 0.8%CVE-2026-45172HIGHIdira Privileged Session Manager for SSH (PSMP): Arbitrary Command Execution via Improper Neutralization of Special Elements used in an OS CommandEPSS 0.8%CVE-2023-28726HIGHPanasonic AiSEG2 versions 2.80F through 2.93A allows remote attackers to execute arbitrary OS commands.EPSS 0.8%CVE-2026-59734HIGHCoolify: OS Command Injection in Health Check Configuration Allows Remote Code ExecutionEPSS 0.8%CVE-2022-43443HIGHOS command injection vulnerability in Buffalo network devices allows an network-adjacent attacker to execute an arbitrary OS command if a spEPSS 0.8%CVE-2026-72875HIGHDokploy: Remote Code Execution (RCE) via Command Injection in settings.readTraefikFileEPSS 0.8%CVE-2026-72902CRITICALDokploy: Authenticated RCE via Command Injection in registry.testRegistry / registry.testRegistryByIdEPSS 0.8%CVE-2026-64837HIGHICEcoder through 8.1 OS Command Injection via lib/properties.phpEPSS 0.8%CVE-2024-51245HIGHIn DrayTek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the reEPSS 0.8%CVE-2025-57283HIGHThe Node.js package browserstack-local 1.5.8 contains a command injection vulnerability. This occurs because the logfile variable is not proEPSS 0.8%CVE-2021-3726HIGHOS Command Injection in ohmyzsh/ohmyzshEPSS 0.8%CVE-2026-44656MEDIUMVim: OS Command Injection via 'path' completionEPSS 0.8%CVE-2026-49190CRITICALMissing Per-Instruction Authorization ChecksEPSS 0.8%CVE-2024-51244HIGHIn Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doEPSS 0.8%CVE-2026-82099HIGHDataStage on Cloud Pak for Data has several vulnerabilities due to open source softwareEPSS 0.8%CVE-2026-41036HIGHCommand Injection Vulnerability in Quantum Networks Router QN-I-470EPSS 0.8%CVE-2024-51248HIGHIn Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the moEPSS 0.8%CVE-2026-81550HIGHDataStage on Cloud Pak for Data has several vulnerabilities due to open source softwareEPSS 0.8%CVE-2026-82095HIGHDataStage on Cloud Pak for Data has several vulnerabilities due to open source softwareEPSS 0.8%