Falhas do tipo CWE-78

4.668 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2025-30370HIGHjupyterlab-git has a command injection vulnerability in "Open Git Repository in Terminal"EPSS 0.6%CVE-2023-24422HIGHA sandbox bypass vulnerability involving map constructors in Jenkins Script Security Plugin 1228.vd93135a_2fb_25 and earlier allows attackerEPSS 0.6%CVE-2026-44723MEDIUMVowpal Wabbit: Shell injection via crafted PR title in python_checks.yml allows arbitrary command execution on CI runnerEPSS 0.6%CVE-2026-65590MEDIUMn8n before 2.30.1 Shell Sandbox Bypass on Linux WindowsEPSS 0.6%CVE-2026-68560HIGHWekan:hell Injection in External Antivirus Scanner Path via asyncExecEPSS 0.6%CVE-2026-22621HIGHImproper input validation in one of the session management interface of Eaton's Tripp Lite Series PADM firmware could allow an authenticatedEPSS 0.6%CVE-2024-49563HIGHDell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command InjectionEPSS 0.6%CVE-2026-95521HIGHRpm: rpm: shell command injection via macro expansion of source/spec file basenames when installing a source rpmEPSS 0.6%CVE-2025-10622HIGHForeman: os command injection via ct_location and fcct_location parametersEPSS 0.6%CVE-2026-89139HIGHTemporal Server worker deployment compute provider executes a caller-supplied command on the Worker Service hostEPSS 0.6%CVE-2026-100368HIGHCliInvoke.Specializations: Command injection in PowerShell and Cmd shell wrappersEPSS 0.6%CVE-2026-77601HIGHOpenC3 COSMOS: Authenticated OS command injection via the `pypi_url` settingEPSS 0.6%CVE-2024-10653HIGHCHANGING Information Technology IDExpert - OS Command InjectionEPSS 0.6%CVE-2026-86733HIGHSnipe-IT before 8.7.0 Remote Code Execution via Backup RestoreEPSS 0.6%CVE-2026-31067MEDIUMA remote command execution (RCE) vulnerability in the /goform/formReleaseConnect component of UTT Aggressive 520W v3v1.7.7-180627 allows attEPSS 0.6%CVE-2024-5400HIGHOpenfind Mail2000 - OS Command InjectionEPSS 0.6%CVE-2026-25623HIGHArista Edge Threat Management NGFW UI Arbitrary Command ExecutionEPSS 0.6%CVE-2022-38132HIGHCommand injection vulnerability in Linksys MR8300 router while Registration to DDNS Service. By specifying username and password, an attacker connected to the router's web interface can execute arbitrary OS commands.EPSS 0.6%CVE-2026-17102HIGHDataStage on Cloud Pak for Data has several vulnerabilitiesEPSS 0.6%CVE-2025-43939HIGHDell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command InjectionEPSS 0.6%