Falhas do tipo CWE-78

4.664 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2025-27393HIGHA vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0). Affected devices do not properly sanitizEPSS 0.7%CVE-2025-27392HIGHA vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0). Affected devices do not properly sanitizEPSS 0.7%CVE-2025-24480CRITICALFactoryTalk® View Machine Editon - Remote Code ExecutionEPSS 0.7%CVE-2025-9762CRITICALPost By Email <= 1.0.4b - Unauthenticated Arbitrary File Upload via Email AttachmentsEPSS 0.7%CVE-2025-8473MEDIUMAlpine iLX-507 UPDM_wstpCBCUpdStart Command Injection VulnerabilityEPSS 0.7%CVE-2023-37249—Infoblox NIOS through 8.5.1 has a faulty component that accepts malicious input without sanitization, resulting in shell access.EPSS 0.7%CVE-2026-53545CRITICALTermix: Remote Code Execution via Tunnel Disconnect pkill Command InjectionEPSS 0.7%CVE-2026-30631CRITICALAn issue was discovered in bytebot-ai in commit 3d37894ce07ef8d8b40adc7fd309ad96c2a71313 (2025-09-11) allowing attackers to execute arbitrarEPSS 0.7%CVE-2026-50112HIGHApache CloudStack: RCE and SSRF in direct download, metalink and NFS templatesEPSS 0.7%CVE-2026-91100MEDIUMHP Linux Imaging and Printing (HPLIP) Software– Multiple VulnerabilitiesEPSS 0.7%CVE-2025-3128CRITICALMitsubishi Electric Europe smartRTU OS Command InjectionEPSS 0.7%CVE-2026-48347HIGHAnimate | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)EPSS 0.7%CVE-2024-7728HIGHCAYIN Technology CMS - OS Command InjectionEPSS 0.7%CVE-2026-55410MEDIUMNocoBase backup restore schema name allows command injectionEPSS 0.7%CVE-2024-50809HIGHThe theme.php file in SDCMS 2.8 has a command execution vulnerability that allows for the execution of system commandsEPSS 0.7%CVE-2022-48593HIGHA SQL injection vulnerability exists in the “topology data service” feature of the ScienceLogic SL1 that takes unsanitized user‐controlled iEPSS 0.7%CVE-2022-48588HIGHA SQL injection vulnerability exists in the “schedule editor decoupled” feature of the ScienceLogic SL1 that takes unsanitized user‐controllEPSS 0.7%CVE-2020-36877CRITICALReQuest Serious Play F3 Media Server <= 7.0.3 code executionEPSS 0.7%CVE-2025-68700HIGHRAGFlow Remote Code Execution VulnerabilityEPSS 0.7%CVE-2026-56685HIGHDell ObjectScale, versions prior to 4.3.0.1, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command InEPSS 0.7%