Falhas do tipo CWE-78

4.669 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2026-46606HIGHGlances: Command Injection via KVM/QEMU VM Domain Names in glances/plugins/vms/engines/virsh.pyEPSS 0.2%CVE-2024-20398HIGHCisco IOS XR Software Local Privilege Escalation VulnerabilityEPSS 0.2%CVE-2026-44713HIGHpam_usb: Command injection via $TMUX environment variable leads to RCE as rootEPSS 0.2%CVE-2026-44709HIGHpam_usb: PINENTRY_FALLBACK_APP environment variable allows arbitrary command executionEPSS 0.2%CVE-2026-55426HIGHlinuxfabrik-lib: Local privilege escalation using embedded commandEPSS 0.2%CVE-2026-57998HIGHbetter-npm-audit OS Command Injection via registry flagEPSS 0.2%CVE-2026-46643HIGHSnappy: Binary path is never shell-escaped due to an inverted is_executable checkEPSS 0.2%CVE-2026-44712HIGHpam_usb: Shell injection via device UUID and username in pamusb-conf and pamusb-agentEPSS 0.2%CVE-2026-48800HIGHNotepad++: Arbitrary Code Execution via shortcuts.xml UserCommand InjectionEPSS 0.2%CVE-2026-74801HIGHSiYuan before 3.7.4 Local Privilege Escalation via elevator.exeEPSS 0.2%CVE-2023-28000MEDIUMAn improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiADC CLI 7.1.0, 7.0.0 through 7.0.3, 6.2.EPSS 0.2%CVE-2026-16695HIGHIBM i Access Client Solutions (ACS) is Affected By Multiple VulnerabilitiesEPSS 0.2%CVE-2026-32608HIGHGlances has a Command Injection via Process Names in Action Command TemplatesEPSS 0.2%CVE-2022-25328MEDIUMPrivilege escalation through command injection in fscryptEPSS 0.2%CVE-2025-23294HIGHNVIDIA WebDataset for all platforms contains a vulnerability where an attacker could execute arbitrary code with elevated permissions. A sucEPSS 0.2%CVE-2026-25143HIGHmelange affected by potential host command execution via license-check YAML mode patch pipelineEPSS 0.2%CVE-2021-36293MEDIUMDell VNX2 for File version 8.1.21.266 and earlier, contain a privilege escalation vulnerability. A local malicious admin may potentially expEPSS 0.2%CVE-2026-24844HIGHmelange pipeline working-directory could allow command injectionEPSS 0.2%CVE-2026-52876HIGHStreambert: Arbitrary File Execution via VLC/mpv Launcher FallbackEPSS 0.2%CVE-2025-13605CRITICALShell command injection in 3onedata GW1101-1D(RS-485)-TB-P modbus gatewayEPSS 0.2%