Falhas do tipo CWE-78

4.668 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2026-44258CRITICALefw4.X: Path Traversal via Unchecked dst Parameter leads to Remote Code ExecutionEPSS 0.5%CVE-2024-53992HIGHunzip-bot Allows Remote Code Execution (RCE) via archive extraction, password prompt, or video uploadEPSS 0.5%CVE-2023-31188HIGHMultiple TP-LINK products allow a network-adjacent authenticated attacker to execute arbitrary OS commands. Affected products/versions are aEPSS 0.5%CVE-2024-48963HIGHThe package Snyk CLI before 1.1294.0 is vulnerable to Code Injection when scanning an untrusted PHP project. The vulnerability can be triggeEPSS 0.5%CVE-2024-48964HIGHThe package Snyk CLI before 1.1294.0 is vulnerable to Code Injection when scanning an untrusted Gradle project. The vulnerability can be triEPSS 0.5%CVE-2023-28617HIGHorg-babel-execute:latex in ob-latex.el in Org Mode through 9.6.1 for GNU Emacs allows attackers to execute arbitrary commands via a file namEPSS 0.5%CVE-2025-23344HIGHThe NVIDIA NVDebug tool contains a vulnerability that may allow an actor to run code on the platform host as a non-privileged user. A succesEPSS 0.5%CVE-2024-11681MEDIUMRemote Code Execution in MacPortsEPSS 0.5%CVE-2023-43069HIGH Dell SmartFabric Storage Software v1.4 (and earlier) contain(s) an OS Command Injection Vulnerability in the CLI. An authenticated local atEPSS 0.5%CVE-2024-20469MEDIUMCisco Identity Services Engine Command Injection VulnerabilityEPSS 0.5%CVE-2026-41064CRITICALAVideo has an incomplete fix for CVE-2026-33502 (Command Injection)EPSS 0.5%CVE-2024-45325MEDIUMAn improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiDDoSEPSS 0.5%CVE-2022-41751HIGHJhead 3.06.0.1 allows attackers to execute arbitrary OS commands by placing them in a JPEG filename and then using the regeneration -rgt50 oEPSS 0.5%CVE-2026-55427HIGHCoder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh`EPSS 0.5%CVE-2026-25044HIGHBudibase: Command Injection in Bash Automation StepEPSS 0.5%CVE-2026-49492HIGHMarkdown Preview Enhanced OS Command Injection in External File and Link OpeningEPSS 0.5%CVE-2022-35849HIGHAn improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface of FortiADC 7.1.0 thEPSS 0.5%CVE-2024-40895MEDIUMFFRI AMC versions 3.4.0 to 3.5.3 and some OEM products that implement/bundle FFRI AMC versions 3.4.0 to 3.5.3 allow a remote unauthenticatedEPSS 0.5%CVE-2025-43943MEDIUMDell Cloud Disaster Recovery, version(s) prior to 19.20, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OEPSS 0.5%CVE-2025-36606HIGHDell Unity, version(s) 5.5 and prior, contain(s) an OS Command Injection Vulnerability in its svc_nfssupport utility. An authenticated attacEPSS 0.5%