Falhas do tipo CWE-78
4.665 resultadosInjeção de comando do sistema operacional
A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.
Exemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.
Como mitigar
Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.
CVE-2026-11325HIGHcloudflare/pages-action is deprecated — migration required by September 18th, 2026EPSS 0.7%CVE-2025-66626HIGHargoproj/argo-workflows is vulnerable to RCE via ZipSlip and symbolic linksEPSS 0.7%CVE-2026-33414MEDIUMPowerShell Command Injection in Podman HyperV MachineEPSS 0.7%CVE-2024-6048CRITICALOpenfind MailGates and MailAudit - OS Command InjectionEPSS 0.7%CVE-2025-3881HIGHeCharge Hardy Barth cPH2 check_req.php ntp Command Injection Remote Code Execution VulnerabilityEPSS 0.7%CVE-2025-3882HIGHeCharge Hardy Barth cPH2 nwcheckexec.php dest Command Injection Remote Code Execution VulnerabilityEPSS 0.7%CVE-2025-3883HIGHeCharge Hardy Barth cPH2 index.php Command Injection Remote Code Execution VulnerabilityEPSS 0.7%CVE-2026-49366HIGHIn JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completionEPSS 0.7%CVE-2019-1709MEDIUMCisco Firepower Threat Defense Software Command Injection VulnerabilityEPSS 0.7%CVE-2026-84422HIGHIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 0.7%CVE-2025-46418HIGHWestermo WeOS 5.x starting from 5.24 allows OS command injection via a media definition.EPSS 0.7%CVE-2025-51958CRITICALaelsantex runcommand 2014-04-01, a plugin for DokuWiki, allows unauthenticated attackers to execute arbitrary system commands via lib/pluginEPSS 0.7%CVE-2026-84436CRITICALIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 0.7%CVE-2023-48380HIGHSoftnext Mail SQR Expert - Command InjectionEPSS 0.7%CVE-2025-9494HIGHViessmann Vitogate 300 OS Command InjectionEPSS 0.7%CVE-2026-91931CRITICALFlowise before 3.1.4 Remote Code Execution via Custom MCP npxEPSS 0.7%CVE-2026-33791HIGHJunos OS and Junos OS Evolved: Execution of crafted CLI commands allows for arbitrary shell injection as rootEPSS 0.7%CVE-2025-40949HIGHA vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versions < V2.17.1), RUGGEEPSS 0.7%CVE-2024-28015CRITICALImproper Neutralization of Special Elements used in an OS Command vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WGEPSS 0.7%CVE-2026-79724CRITICALLangflow is vulnerable to arbitrary code execution due to multiple incomplete code security controls and missing execution guardsEPSS 0.7%