Falhas do tipo CWE-78

4.668 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2026-23820HIGHInconsistent input filtering allows Authenticated Command Injection in AOS-8 Instant and AOS-10 CLIEPSS 0.6%CVE-2025-0119MEDIUMCortex XDR Broker VM: Authenticated Command Injection Vulnerability in Broker VMEPSS 0.6%CVE-2025-64755HIGH@anthropic-ai/claude-code has Sed Command Validation Bypass that Allows Arbitrary File WritesEPSS 0.6%CVE-2026-16672HIGHDataStage on Cloud Pak for Data has several vulnerabilitiesEPSS 0.6%CVE-2022-27482HIGHA improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiADC version 7.0.0 through 7.0.EPSS 0.6%CVE-2026-55249MEDIUM@rtk-ai/rtk-rewrite: OpenClaw Rewrite Plugin Command Injection via execSync Template StringEPSS 0.6%CVE-2024-31478MEDIUMMultiple unauthenticated Denial-of-Service (DoS) vulnerabilities exists in the Soft AP daemon accessed via the PAPI protocol. Successful expEPSS 0.6%CVE-2026-12542MEDIUMForeman: command injection in foreman-tailEPSS 0.6%CVE-2024-49281MEDIUMWordPress Click to Chat – WP Support All-in-One Floating Widget plugin <= 2.3.3 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.5%CVE-2024-26023MEDIUMOS command injection vulnerability in BUFFALO wireless LAN routers allows a logged-in user to execute arbitrary OS commands.EPSS 0.5%CVE-2024-31482MEDIUMAn unauthenticated Denial-of-Service (DoS) vulnerability exists in the ANSI escape code service accessed via the PAPI protocol. Successful eEPSS 0.5%CVE-2026-54149HIGHMaxKB MCP tool import validation bypass allows post-authentication remote code executionEPSS 0.5%CVE-2026-22622HIGHImproper input validation in one of the session management interface of Eaton's Tripp Lite series PADM firmware could allow an authenticatedEPSS 0.5%CVE-2024-20275MEDIUMCisco Secure Firewall Management Center Software Backup Cluster Command Injection VulnerabilityEPSS 0.5%CVE-2020-21583—An issue was discovered in hwclock.13-v2.27 allows attackers to gain escalated privlidges or execute arbitrary commands via the path parametEPSS 0.5%CVE-2026-57136HIGHPraisonAI SandboxExecutor allowedCommands bypass via shell chainingEPSS 0.5%CVE-2026-84361HIGHComposer: Perforce source URL permits P4PORT `rsh:` command executionEPSS 0.5%CVE-2025-56590CRITICALAn issue was discovered in the InsertFromURL() function of the Apryse HTML2PDF SDK thru 11.10. This vulnerability could allow an attacker toEPSS 0.5%CVE-2026-5935HIGHTSSC/IMC is vulnerable to OS Command InjectionEPSS 0.5%CVE-2026-80412HIGHDataStage on Cloud Pak for Data has several vulnerabilitiesEPSS 0.5%