Falhas do tipo CWE-78

4.669 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2025-43943MEDIUMDell Cloud Disaster Recovery, version(s) prior to 19.20, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OEPSS 0.5%CVE-2025-69755HIGHAn issue in Neterbit NW-431F Router vNW-431F-20241014-IR03 allows a remote attacker to obtain sensitive information and execute arbitrary coEPSS 0.5%CVE-2026-75363MEDIUMAn issue in Comfast CF-WR630AX v.2.7.0.2 allows a remote attacker to execute arbitrary code via the /usr/bin/webmgnt, /cgi-bin/mbox-config, EPSS 0.5%CVE-2019-1774MEDIUMCisco NX-OS Software Command Injection VulnerabilityEPSS 0.5%CVE-2019-1775MEDIUMCisco NX-OS Software Command Injection VulnerabilityEPSS 0.5%CVE-2023-48668HIGH Dell PowerProtect DD, versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 on DDMC contain an OS command injection vulnerabiEPSS 0.5%CVE-2021-35031MEDIUMA vulnerability in the TFTP client of Zyxel GS1900 series firmware, XGS1210 series firmware, and XGS1250 series firmware, which could allow EPSS 0.5%CVE-2026-91936HIGHFlowise before 3.1.4 Script Injection via Docker WorkflowsEPSS 0.5%CVE-2019-12709MEDIUMCisco IOS XR Software for Cisco ASR 9000 VMAN CLI Privilege Escalation VulnerabilityEPSS 0.5%CVE-2026-70335HIGHGitHub Copilot and Visual Studio Code Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2025-43884HIGHDell PowerProtect Data Manager, version(s) 19.19 and 19.20, Hyper-V contain(s) an Improper Neutralization of Special Elements used in an OS EPSS 0.5%CVE-2026-44666CRITICALHRConvert2: Missing Sanitization enables Unauthenticated Remote Command ExecutionEPSS 0.5%CVE-2026-72904CRITICALFirecrawl: Arbitrary file read via JSON Schema $ref expansionEPSS 0.5%CVE-2026-100254HIGHIn JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 authenticated users could execute commands on Windows servers via CRLF injection EPSS 0.5%CVE-2026-55576HIGHMaaAssistantArknights: PR-title expression injection in release-preparation.ymlEPSS 0.5%CVE-2026-39382CRITICALdbt has a Command Injection in Reusable Workflow via Unsanitized comment-body OutputEPSS 0.5%CVE-2026-102826HIGHsimple-git allows command execution through unblocked Git configuration includesEPSS 0.5%CVE-2026-55748MEDIUMOpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharaEPSS 0.5%CVE-2023-34873HIGHOn MOBOTIX P3 cameras before MX-V4.7.2.18 and Mx6 cameras before MX-V5.2.0.61, the tcpdump feature does not properly validate input, which aEPSS 0.5%CVE-2025-70082MEDIUMLantronix EDS3000PS Unverified Password ChangeEPSS 0.5%