Falhas do tipo CWE-78

4.669 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2025-52988HIGHJunos OS and Junos OS Evolved: Privilege escalation to root via CLI command 'request system logout'EPSS 0.4%CVE-2026-79916CRITICALMaxKB AWS Bedrock model credential injection leads to remote code executionEPSS 0.4%CVE-2021-1584MEDIUMCisco Nexus 9000 Series Fabric Switches ACI Mode Privilege Escalation VulnerabilityEPSS 0.4%CVE-2025-20193MEDIUMA vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, low-privileged, remote attackerEPSS 0.4%CVE-2024-21821HIGHMultiple TP-LINK products allow a network-adjacent authenticated attacker with access to the product from the LAN port or Wi-Fi to execute aEPSS 0.4%CVE-2024-54025MEDIUMAn improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiIsolatEPSS 0.4%CVE-2026-49402HIGHDeno: Command Injection via spawnSync & spawn on WindowsEPSS 0.4%CVE-2025-27078MEDIUMAuthenticated Remote Command Execution caused by Insecure Function Usage in System BinaryEPSS 0.4%CVE-2018-0115—A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series routers could allow an authenticated, local attackEPSS 0.4%CVE-2020-3169MEDIUMCisco FXOS Software CLI Command Injection VulnerabilityEPSS 0.4%CVE-2017-6796—A vulnerability in the USB-modem code of Cisco IOS XE Software running on Cisco ASR 920 Series Aggregation Services Routers could allow an aEPSS 0.4%CVE-2026-65612MEDIUMShell Command Injection in nnnEPSS 0.4%CVE-2025-53868HIGHBIG-IP SCP and SFTP vulnerabilityEPSS 0.4%CVE-2026-63725HIGHsysPass FileBackupService Authenticated OS Command Injection via Backup PathEPSS 0.4%CVE-2026-65611MEDIUMShell Command Injection in nnnEPSS 0.4%CVE-2024-50376HIGHA CWE-79 "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')" was discovered affecting the following devicEPSS 0.4%CVE-2023-34214HIGHSecond Order Command-injection Vulnerability in the Certificate-generation FunctionEPSS 0.4%CVE-2025-11571LOWCommand Execution vulnerability in Simplicity InstallerEPSS 0.4%CVE-2019-25255HIGHVideoFlow Digital Video Protection DVP 2.10 Authenticated Remote Code ExecutionEPSS 0.4%CVE-2025-11546CRITICALCLUSTERPRO X for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2 and EXPRESSCLUSTER X for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2, CLUSTERPRO X SingleSeEPSS 0.4%