Falhas do tipo CWE-78

4.669 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2025-59172HIGHImproper Neutralization of Special Elements used in an OS Command VulnerabilityEPSS 0.3%CVE-2021-34722MEDIUMCisco IOS XR Software Command Injection VulnerabilitiesEPSS 0.3%CVE-2021-34719HIGHCisco IOS XR Software Authenticated User Privilege Escalation VulnerabilitiesEPSS 0.3%CVE-2021-34721MEDIUMCisco IOS XR Software Command Injection VulnerabilitiesEPSS 0.3%CVE-2026-102828CRITICALsimple-git unsafe-operation guard does not block trailer command configurationEPSS 0.3%CVE-2026-102829CRITICALsimple-git: `VISUAL` editor environment variable is omitted from unsafe editor detectionEPSS 0.3%CVE-2026-14275MEDIUMIBM i Access Client Solutions (ACS) is Affected By Multiple VulnerabilitiesEPSS 0.3%CVE-2021-21550MEDIUMDell EMC PowerScale OneFS 8.1.0-9.1.0 contain an improper neutralization of special elements used in an OS command vulnerability. This vulneEPSS 0.3%CVE-2021-21527MEDIUMDell PowerScale OneFS 8.1.0-9.1.0 contain an improper neutralization of special elements used in an OS command vulnerability. This vulnerabiEPSS 0.3%CVE-2026-14276MEDIUMIBM i Access Client Solutions (ACS) is Affected By Multiple VulnerabilitiesEPSS 0.3%CVE-2026-34982HIGHVim modeline bypass via various options affects Vim < 9.2.0276EPSS 0.3%CVE-2022-1356HIGHCambium Networks cnMaestro use of Potentially Dangerous FunctionEPSS 0.3%CVE-2020-25859—The QCMAP_CLI utility in the Qualcomm QCMAP software suite prior to versions released in October 2020 uses a system() call without validatinEPSS 0.3%CVE-2024-37678MEDIUMCross Site Scripting vulnerability in Hangzhou Meisoft Information Technology Co., Ltd. Finesoft v.8.0 and before allows a remote attacker tEPSS 0.3%CVE-2025-33234HIGHNVIDIA runx contains a vulnerability where an attacker could cause a code injection. A successful exploit of this vulnerability might lead tEPSS 0.3%CVE-2026-32948MEDIUMsbt: Source dependency feature (via crafted VCS URL) leads to arbitrary code execution on WindowsEPSS 0.3%CVE-2026-55582HIGHmcp-shell: Secure Mode Allowlist Bypass via Git Shell AliasEPSS 0.3%CVE-2026-84967MEDIUMArbitrary command execution via shell-expanded connection string in Launch MongoDB Shell terminalEPSS 0.3%CVE-2025-47780MEDIUMcli_permissions.conf: deny option does not work for disallowing shell commandsEPSS 0.3%CVE-2025-43858CRITICALYoutubeDLSharp allows command injection on windows system due to non sanitized argumentsEPSS 0.3%