Falhas do tipo CWE-78

4.668 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2024-14026LOWQTS, QuTS heroEPSS 0.6%CVE-2024-7517HIGHPrivileged escalation via crafted use of portcfg commandEPSS 0.6%CVE-2026-35073MEDIUMDell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release versions 8.3.1.0 throughEPSS 0.6%CVE-2026-35074MEDIUMDell PowerProtect Data Domain Feature Release versions 7.7.1.0 through 8.6.0.0 and version 8.7.0.0, LTS2025 release versions 8.3.1.0 throughEPSS 0.6%CVE-2026-54483MEDIUMDell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1EPSS 0.6%CVE-2026-35071HIGHDell PowerScale InsightIQ, versions 6.0.0 through 6.2.0, contains an improper neutralization of special elements used in an OS command ('OS EPSS 0.6%CVE-2026-49813MEDIUMDell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1EPSS 0.6%CVE-2026-39420MEDIUMMaxKB: Sandbox escape via LD_PRELOAD bypassEPSS 0.6%CVE-2024-13087LOWQHoraEPSS 0.6%CVE-2023-49692HIGHA vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V7.2.2), RUGGEDCOM RM1224 LTE(4G) NAEPSS 0.6%CVE-2025-4230HIGHPAN-OS: Authenticated Admin Command Injection Vulnerability Through CLIEPSS 0.6%CVE-2026-85660CRITICALcli-mcp-server 0.2.5 Command Allowlist Bypass via Shell SubstitutionEPSS 0.6%CVE-2025-0356HIGHNEC Corporation Aterm WX1500HP Ver.1.4.2 and earlier and WX3600HP Ver.1.5.3 and earlier allows a attacker to execute arbitrary OS commands vEPSS 0.6%CVE-2025-0680CRITICALNew Rock Technologies Cloud Connected Devices has a Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability.EPSS 0.6%CVE-2026-45431HIGHCommand Injection Vulnerability in GX Earth ONT ModelsEPSS 0.6%CVE-2026-48778HIGHNotepad++: Arbitrary Code Execution via config.xml commandLineInterpreterEPSS 0.6%CVE-2023-24046HIGHAn issue was discovered on Connectize AC21000 G6 641.139.1.1256 allows attackers to run arbitrary commands via use of a crafted string in thEPSS 0.6%CVE-2025-15519HIGHCommand Injection in Modem Management CLI on TP-Link Archer NX200, NX210, NX500 and NX600EPSS 0.6%CVE-2025-15518HIGHCommand Injection in Wireless Control CLI on TP-Link Archer NX200, NX210, NX500 and NX600EPSS 0.6%CVE-2026-82892HIGHIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 0.6%