Falhas do tipo CWE-78
4.668 resultadosInjeção de comando do sistema operacional
A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.
Exemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.
Como mitigar
Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.
CVE-2021-1476MEDIUMCisco Adaptive Security Appliance Software and Firepower Threat Defense Software Command Injection VulnerabilityEPSS 0.5%CVE-2026-19843HIGH389-ds-base: 389-ds-base: command injection via unescaped ldap dn in cockpit 389 console ldap editorEPSS 0.5%CVE-2026-25041HIGHBudibase has a Command Injection in PostgreSQL Dump CommandEPSS 0.5%CVE-2025-13481HIGHIBM Aspera Orchestrator Command InjectionEPSS 0.5%CVE-2026-72878CRITICALDokploy: OS Command Injection in backup/restore pipeline via unescaped user-controlled shell argumentsEPSS 0.5%CVE-2023-2625CRITICALA vulnerability exists that can be exploited by an authenticated client that is connected to the same network segment as the CoreTec 4, haviEPSS 0.5%CVE-2025-55284HIGHClaude Code's Permissive Default Allowlist Enables Unauthorized File Read and Network Exfiltration in Claude CodeEPSS 0.5%CVE-2019-1776MEDIUMCisco NX-OS Software Command Injection VulnerabilityEPSS 0.5%CVE-2019-1769MEDIUMCisco NX-OS Software Line Card Command Injection VulnerabilityEPSS 0.5%CVE-2024-3798HIGHInsecure handling of GET argument in PhonieboxEPSS 0.5%CVE-2019-1778MEDIUMCisco NX-OS Software Command Injection VulnerabilityEPSS 0.5%CVE-2026-44345HIGHBentoML: Dockerfile command injection via docker.base_imageEPSS 0.5%CVE-2026-45035CRITICALTabby: RCE via `tabby://run` URL SchemeEPSS 0.5%CVE-2026-62182HIGHKubeEdge: ConfigUpdateJob updateFields enables remote shell injection and code execution on edge nodesEPSS 0.5%CVE-2026-44346HIGHBentoML: Dockerfile command injection via envs[*].name in bentofile.yamlEPSS 0.5%CVE-2025-36607HIGHDell Unity, version(s) 5.5 and prior, contain(s) an OS Command Injection Vulnerability in its svc_nas utility. An authenticated attacker couEPSS 0.5%CVE-2023-3313HIGH
An OS common injection vulnerability exists in the ESM certificate API, whereby incorrectly neutralized special elements may have allowed aEPSS 0.5%CVE-2025-36569MEDIUMDell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.0.10, LTS2024 releasEPSS 0.5%CVE-2026-17248HIGHIBM i is Affected By Multiple Vulnerabilities in the Debug ServerEPSS 0.5%CVE-2025-54469CRITICALNeuVector Enforcer is vulnerable to Command Injection and Buffer overflowEPSS 0.5%