Falhas do tipo CWE-78

4.665 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2026-18683HIGHIBM i is Affected By privilege escalation in Navigator for iEPSS 0.7%CVE-2026-44444CRITICALLumiverse: Spindle extension install runs untrusted lifecycle scripts before security scanEPSS 0.7%CVE-2026-73753HIGHAuthenticated Remote Command Injection Vulnerabilities in AOS-CX Command Line InterfaceEPSS 0.7%CVE-2026-11834HIGHUnauthenticated Command Injection via DHCP Option Handling in Multiple TP-Link RoutersEPSS 0.7%CVE-2024-13892HIGHCommand Injection in Smartwares camerasEPSS 0.7%CVE-2026-14499HIGHLangflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpointsEPSS 0.7%CVE-2026-40852HIGHCommand injection via malicious configurationEPSS 0.7%CVE-2023-4856HIGH A format string vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user to execute arbitrary commands on a EPSS 0.7%CVE-2025-26074CRITICALOrkes Conductor v3.21.11 allows remote attackers to execute arbitrary OS commands through unrestricted access to Java classes.EPSS 0.7%CVE-2023-28906HIGHCommand injection in networking serviceEPSS 0.7%CVE-2019-1699MEDIUMCisco Firepower Threat Defense Software Command Injection VulnerabilityEPSS 0.7%CVE-2024-39228CRITICALGL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16,EPSS 0.7%CVE-2026-5967HIGHTeamT5|ThreatSonar Anti-Ransomware - Privilege EscalationEPSS 0.7%CVE-2026-32298HIGHAngeet ES3 KVM OS command injectionEPSS 0.7%CVE-2026-22277HIGHDell UnityVSA, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command InjectEPSS 0.7%CVE-2026-53542HIGHTermix: Tar option injection in file-manager archive creation allows command execution on managed SSH hostsEPSS 0.7%CVE-2026-21418HIGHDell Unity, version(s) 5.5.2 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command InjectiEPSS 0.7%CVE-2026-56004CRITICALobs-service-tar_scm: command injection via mercurial handlerEPSS 0.7%CVE-2022-45939HIGHGNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etagEPSS 0.7%CVE-2024-47608MEDIUMLogicytics vulnerable to shell injectionsEPSS 0.7%