Falhas do tipo CWE-78

4.668 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2026-80412HIGHDataStage on Cloud Pak for Data has several vulnerabilitiesEPSS 0.5%CVE-2024-38641HIGHQTS, QuTS heroEPSS 0.5%CVE-2025-24377HIGHDell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command InjectionEPSS 0.5%CVE-2026-12005HIGHSecurity vulnerabilities have been found in IBM Verify Identity Access and IBM Security Verify AccessEPSS 0.5%CVE-2026-42994HIGHBitwarden CLI 2026.4.0 from 2026-04-22T21:57Z to 2026-04-22T23:30Z, when obtained from npm, had embedded malicious code. This is related to EPSS 0.5%CVE-2026-88282HIGHGV-LPCLPC2011/2211 - Stored FTP-Username Command InjectionEPSS 0.5%CVE-2026-88272HIGHGV-LPC2011/LPC2211 - Stored Administrator-Username Command InjectionEPSS 0.5%CVE-2025-40947HIGHA vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versions < V2.17.1), RUGGEEPSS 0.5%CVE-2021-4466HIGHIPCop <= 2.1.9 Authenticated RCEEPSS 0.5%CVE-2026-80214HIGHLibreNMS Virtualisation Discovery Module RCEEPSS 0.5%CVE-2024-52961HIGHAn improper neutralization of special elements used in an OS Command vulnerability [CWE-78] vulnerability in Fortinet FortiSandbox 5.0.0, FoEPSS 0.5%CVE-2024-31843MEDIUMAn issue was discovered in Italtel Embrace 1.6.4. The Web application does not properly check the parameters sent as input before they are pEPSS 0.5%CVE-2025-67164CRITICALAn authenticated arbitrary file upload vulnerability in the /storage/poc.php component of Pagekit CMS v1.0.18 allows attackers to execute arEPSS 0.5%CVE-2026-70425MEDIUMDell PowerScale OneFS, Versions 9.5.0.0 through 9.7.1.0, Versions 9.8.0.0 through 9.10.1.0, and Versions 9.11.0.0 through 9.14.0.1, contain EPSS 0.5%CVE-2024-6032HIGHTesla Model S Iris Modem ql_atfwd Command Injection Code Execution VulnerabilityEPSS 0.5%CVE-2026-52831HIGHNuclio: Unsanitized cron trigger event headers/body injected into CronJob shell command leads to persistent RCEEPSS 0.5%CVE-2026-73081HIGHActivepieces: Remote Code Execution via Command Injection in Code Step NameEPSS 0.5%CVE-2026-58502HIGHgithubtoplanguages: Command Injection via Issue Title in Discord Notification WorkflowEPSS 0.5%CVE-2024-21773HIGHMultiple TP-LINK products allow a network-adjacent unauthenticated attacker with access to the product from the LAN port or Wi-Fi to executeEPSS 0.5%CVE-2025-0415CRITICALCommand Injection in NTP SettingEPSS 0.5%