Falhas do tipo CWE-78

4.669 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2025-27079MEDIUMArbitrary File Creation vulnerability allows for Authenticated Remote Code Execution in CLI InterfaceEPSS 0.2%CVE-2023-40716MEDIUMAn improper neutralization of special elements used in an OS command vulnerability [CWE-78]  in the command line interpreter of FortiTester EPSS 0.2%CVE-2022-40679HIGHAn improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiADC 5.x all versions, 6.0 all versions, EPSS 0.2%CVE-2026-43943HIGHelecterm: RCE via malicious SSH server filename in openFileWithEditorEPSS 0.2%CVE-2025-12742HIGHRemote Code Execution in Looker via Teradata JDBC DriverEPSS 0.2%CVE-2026-55849HIGH@cyclonedx/cyclonedx-npm: Shell Injection via Unsanitized `--workspace` ArgumentEPSS 0.2%CVE-2026-81097HIGHrails-mcp-server 1.4.0 through 1.6.0 OS Command Execution via execute_ruby PTY EscapeEPSS 0.2%CVE-2026-89066HIGHOS command injection in the task synthesis component in projenEPSS 0.2%CVE-2024-47115HIGHIBM AIX command executionEPSS 0.2%CVE-2026-88886HIGHRenovate before 44.14.7 Command Injection via gradle-wrapperEPSS 0.2%CVE-2024-20289MEDIUMCisco NX-OS Software Command Injection VulnerabilityEPSS 0.2%CVE-2025-68922HIGHOpenOps before 0.6.11 allows remote code execution in the Terraform block.EPSS 0.2%CVE-2025-62801MEDIUMFastMCP vulnerable to windows command injection in FastMCP Cursor installer via server_nameEPSS 0.2%CVE-2026-48097HIGHNexTOR_IP_CHANGER has PATH Injection Leading to Arbitrary Command ExecutionEPSS 0.2%CVE-2025-20138HIGHCisco IOS XR Software CLI Privilege Escalation VulnerabilityEPSS 0.2%CVE-2026-55895MEDIUMVim: Vimscript Code Injection in netrw NetrwLocalRmFile() via crafted filenameEPSS 0.2%CVE-2026-49260HIGHPhpWeasyPrint: shell command injection via configurable WeasyPrint binary path due to inverted is_executable() guard (mirror of KnpLabs/snappy GHSA-vpr4-p6fq-85jc)EPSS 0.2%CVE-2026-44463HIGHZed: Allowlist Bypass via Environment Variable Injection in Terminal Tool PermissionsEPSS 0.2%CVE-2026-44466HIGHZed: Allowlist Bypass via Bash Arithmetic Expansion in Terminal Tool PermissionsEPSS 0.2%CVE-2026-56389MEDIUMArbitrary Command Execution in GNU BisonEPSS 0.2%