Falhas do tipo CWE-78

4.664 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2026-72738CRITICALDokploy: Authenticated RCE via Command Injection in backup.listBackupFiles search ParameterEPSS 0.8%CVE-2024-41585MEDIUMDrayTek Vigor3910 devices through 4.3.2.6 are affected by an OS command injection vulnerability that allows an attacker to leverage the recvEPSS 0.8%CVE-2026-3014MEDIUMRemote Code Execution by administrative user on the Management ServerEPSS 0.8%CVE-2026-27566HIGHOpenClaw < 2026.2.22 - Allowlist Bypass via Wrapper Binary Unwrapping in system.runEPSS 0.8%CVE-2026-66138HIGHIn OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code execution on a runniEPSS 0.8%CVE-2026-54182HIGHbackpack/crud: OS command injection in Stats::makeCurlRequest via attacker-controlled Host header (pre-auth)EPSS 0.8%CVE-2026-41411MEDIUMVim: Command injection via backtick expansion in tag filenamesEPSS 0.8%CVE-2026-49980CRITICALRclone: Unauthenticated command execution in `rclone rcd --rc-serve` via inline remote instantiation, bypassing CVE-2026-41179 fixEPSS 0.8%CVE-2024-58338HIGHAnevia Flamingo XL 3.2.9 Remote Root Jailbreak via Traceroute CommandEPSS 0.8%CVE-2026-33641HIGHGlances Vulnerable to Command Injection via Dynamic Configuration ValuesEPSS 0.8%CVE-2025-66203CRITICALStreamVault is Vulnerable to Authenticated Remote Code Execution (RCE) via ytdlpargs Configuration InjectionEPSS 0.8%CVE-2024-42029MEDIUMxdg-desktop-portal-hyprland (aka an XDG Desktop Portal backend for Hyprland) before 1.3.3 allows OS command execution, e.g., because single EPSS 0.8%CVE-2021-33633HIGHCommand Injection in aops-ceresEPSS 0.8%CVE-2026-82887HIGHIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 0.8%CVE-2023-37032HIGHA Stack-based buffer overflow in the Mobile Management Entity (MME) of Magma versions <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5EPSS 0.8%CVE-2026-73660HIGHFreePBX: Authenticated TTS AGI Command Injection Through TTS NameEPSS 0.8%CVE-2024-49803CRITICALIBM Security Verify Access Appliance command executionEPSS 0.8%CVE-2023-46510—An issue in ZIONCOM (Hong Kong) Technology Limited A7000R v.4.1cu.4154 allows an attacker to execute arbitrary code via the cig-bin/cstecgi.EPSS 0.8%CVE-2026-41497CRITICALIncomplete fix for CVE-2026-34935: Command Injection in MervinPraison/PraisonAIEPSS 0.8%CVE-2026-100844HIGHMONAI before 1.6.0 OS Command Injection via dataset_name_or_idEPSS 0.8%