Falhas do tipo CWE-78

4.669 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2025-67035HIGHLantronix EDS5000 OS Command InjectionEPSS 0.4%CVE-2026-48694HIGHFastNetMon Community Edition through 1.2.9 contains a configuration injection vulnerability in the Juniper router integration plugin. In srcEPSS 0.4%CVE-2020-12774HIGHD-Link DSL-7740C - Command InjectionEPSS 0.4%CVE-2024-27920HIGHUnsigned code template execution through workflows in projectdiscovery/nucleiEPSS 0.4%CVE-2019-1883HIGHCisco Integrated Management Controller CLI Command Injection VulnerabilityEPSS 0.4%CVE-2025-30241HIGHOS Command Injection in Web Interface in Multiple TP-Link Aginet DevicesEPSS 0.4%CVE-2026-18824HIGHVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.4%CVE-2026-75364MEDIUMComfast CF-N1-S firmware 2.6.0.1 and CF-WR630AX (2024-01-30 build), the update_interface_png SET handler in /usr/bin/webmgnt fails to sanitiEPSS 0.4%CVE-2026-42924HIGHBIG-IP iControl SOAP vulnerabilityEPSS 0.4%CVE-2022-47210HIGHThe default console presented to users over telnet (when enabled) is restricted to a subset of commands. Commands issued at this console, hoEPSS 0.4%CVE-2025-30076HIGHKoha before 24.11.02 allows admins to execute arbitrary commands via shell metacharacters in the tools/scheduler.pl report parameter.EPSS 0.4%CVE-2020-3457MEDIUMCisco FXOS Software Command Injection VulnerabilityEPSS 0.4%CVE-2025-58059CRITICALValtimo scripting engine can be used to gain access to sensitive data or resourcesEPSS 0.4%CVE-2026-32010MEDIUMOpenClaw < 2026.2.22 - Allowlist Bypass via sort --compress-program ParameterEPSS 0.4%CVE-2026-54686MEDIUMWarp: DCS lifecycle hook spoofing can alter terminal session metadataEPSS 0.4%CVE-2019-15986MEDIUMCisco Unity Express Command Injection VulnerabilityEPSS 0.4%CVE-2023-28767HIGHThe configuration parser fails to sanitize user-controlled input in the Zyxel ATP series firmware versions 5.10 through 5.36, USG FLEX serieEPSS 0.4%CVE-2026-87741HIGHConvertPlus <= 3.6.3 - Authenticated (Subscriber+) PHP Object Injection via 'style' ParameterEPSS 0.4%CVE-2025-63408MEDIUMLocal Agent DVR versions thru 6.6.1.0 are vulnerable to directory traversal that allows an unauthenticated local attacker to gain access to EPSS 0.4%CVE-2022-26868MEDIUMDell EMC PowerStore versions 2.0.0.x, 2.0.1.x, and 2.1.0.x are vulnerable to a command injection flaw. An authenticated attacker could potenEPSS 0.4%