Falhas do tipo CWE-78
4.669 resultadosInjeção de comando do sistema operacional
A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.
Exemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.
Como mitigar
Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.
CVE-2021-1557MEDIUMCisco DNA Spaces Connector Privilege Escalation VulnerabilitiesEPSS 0.3%CVE-2024-22366MEDIUMActive debug code exists in Yamaha wireless LAN access point devices. If a logged-in user who knows how to use the debug function accesses tEPSS 0.3%CVE-2026-97863MEDIUMmisp-modules: Shell Command Injection in MISP cisco_firesight_manager_ACL_rule_export Module via Unescaped Attribute ValuesEPSS 0.3%CVE-2021-21503HIGHPowerScale OneFS 8.1.2,8.2.2 and 9.1.0 contains an improper input sanitization issue in a command. The Compadmin user could potentially explEPSS 0.3%CVE-2025-1038HIGHThe “Diagnostics Tools” page of the web-based configuration utility does not properly validate user-controlled input, allowing an authenticaEPSS 0.3%CVE-2026-73222HIGHClaude Code Templates: Unauthenticated OS command injection (RCE) in Claude Code Studio server (--studio)EPSS 0.3%CVE-2024-33793MEDIUMnetis-systems MEX605 v2.00.06 allows attackers to execute arbitrary OS commands via a crafted payload to the ping test page.EPSS 0.3%CVE-2024-37391HIGHProtonVPN before 3.2.10 on Windows mishandles the drive installer path, which should use this: '"' + ExpandConstant('{autopf}\Proton\Drive')EPSS 0.3%CVE-2025-27234HIGHZabbix Agent 2 smartctl plugin RCE vulnerability in Zabbix 5.0.EPSS 0.3%CVE-2026-42201LOWCoolify: OS Command Injection via Database Credential Fields in Docker Compose Service CommandsEPSS 0.3%CVE-2026-34049LOWCoolify: Command Injection via unsanitized MongoDB collection names in database backupEPSS 0.3%CVE-2024-40641HIGHUnsigned code template execution through workflows in projectdiscovery/nucleiEPSS 0.3%CVE-2024-1683HIGHDLL Injection in Tenable Identity Exposure Secure RelayEPSS 0.3%CVE-2020-11847HIGHVulnerability in sshrelay in privileged access manager provides full system access.EPSS 0.3%CVE-2021-1441MEDIUMCisco IOS XE Software Hardware Initialization Routines Arbitrary Code Execution VulnerabilityEPSS 0.3%CVE-2021-1529HIGHCisco IOS XE SD-WAN Software Command Injection VulnerabilityEPSS 0.3%CVE-2024-47918MEDIUMTiki Wiki CMS – CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)EPSS 0.3%CVE-2026-0654HIGHCommand injection on TP-Link Deco BE25EPSS 0.3%CVE-2021-35028HIGHA command injection vulnerability in the CGI program of the Zyxel VPN2S firmware version 1.12 could allow an authenticated, local user to exEPSS 0.3%CVE-2026-100599HIGHOpenClaw 2026.5.1 before 2026.7.1 Remote Code Execution via googlemeet.chromeEPSS 0.3%