Falhas do tipo CWE-78
4.669 resultadosInjeção de comando do sistema operacional
A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.
Exemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.
Como mitigar
Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.
CVE-2026-20350MEDIUMCisco ThousandEyes Virtual Appliance Authenticated Web Interface Command Injection VulnerabilityEPSS 0.3%CVE-2026-45255HIGHRemote code execution via installer Wi-Fi access point scansEPSS 0.3%CVE-2025-46334HIGHGit GUI malicious command injection on WindowsEPSS 0.3%CVE-2025-54430CRITICALdedupe is vulnerable to secret exfiltration via `issue_comment`EPSS 0.3%CVE-2022-20865MEDIUMCisco FXOS Software Command Injection VulnerabilityEPSS 0.3%CVE-2024-20326HIGHA vulnerability in the ConfD CLI and the Cisco Crosswork Network Services Orchestrator CLI could allow an authenticated, low-privileged, loEPSS 0.3%CVE-2024-32477HIGHRace condition when flushing input stream leads to permission prompt bypassEPSS 0.3%CVE-2026-40111CRITICALPraisonAIAgents has an OS Command Injection via shell=True in Memory Hooks Executor (memory/hooks.py)EPSS 0.3%CVE-2023-29120CRITICALUnauthorized Remote Command Execution in Enel X JuiceboxEPSS 0.3%CVE-2025-36143MEDIUMIBM watsonx.data command executionEPSS 0.3%CVE-2024-29189HIGHansys-geometry-core OS Command Injection vulnerabilityEPSS 0.3%CVE-2026-71567HIGHUser-controlled variables inserted unescaped into shell scripts and Kubernetes manifestsEPSS 0.3%CVE-2023-34642HIGHKioWare for Windows through v8.33 was discovered to contain an incomplete blacklist filter for blocked dialog boxes on Windows 10. This issuEPSS 0.3%CVE-2022-24753HIGHCode injection in Stripe CLI on windowsEPSS 0.3%CVE-2021-32556LOWapport get_modified_conffiles() function command injectionEPSS 0.3%CVE-2025-36354HIGHIBM Security Verify Access command executionEPSS 0.3%CVE-2025-10568MEDIUMHyperX NGENUITY - Arbitrary Code ExecutionEPSS 0.3%CVE-2025-27398LOWA vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V4.0). Affected devices do not properly neutralEPSS 0.3%CVE-2025-20194MEDIUMA vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, low-privileged, remote attackerEPSS 0.3%CVE-2021-1558MEDIUMCisco DNA Spaces Connector Privilege Escalation VulnerabilitiesEPSS 0.3%