Falhas do tipo CWE-78

4.669 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2026-79079HIGHAn issue in CrossWire Xiphos <= 4.3.2 allows a local attacker to execute arbitrary code via the src/main/url.cc and src/gtk/menu_popup.c comEPSS 0.2%CVE-2026-55697HIGHpnpm: Repository-controlled configDependencies can select a pacquet native install engineEPSS 0.2%CVE-2026-19635HIGHLocal Privilege EscalationEPSS 0.2%CVE-2026-44076MEDIUMShell injection via volume pathEPSS 0.2%CVE-2024-8934MEDIUMBeckhoff: Local command injection via TwinCAT Package ManagerEPSS 0.2%CVE-2024-58278HIGHIndigoSTAR Software - perl2exe <= V30.10C - Arbitrary Code ExecutionEPSS 0.2%CVE-2026-61898HIGHaccountsservice: shell injection via attacker-controlled ~/.pam_environment in Ubuntu language helper scriptsEPSS 0.2%CVE-2026-76055HIGHImproper Neutralization of Special Elements used in an OS Command in the package manager component of Black Duck blackduck-c-cpp before 3.0.EPSS 0.2%CVE-2024-50377MEDIUMA CWE-798 "Use of Hard-coded Credentials" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3)EPSS 0.2%CVE-2025-20295MEDIUMCisco UCS Manager Software Command Injection VulnerabilityEPSS 0.2%CVE-2026-55441HIGHmise: Arbitrary command execution via task-include files in an untrusted, config-less repositoryEPSS 0.2%CVE-2026-76802MEDIUMNuclei: Arbitrary Command Execution via DAST Code Signature BypassEPSS 0.2%CVE-2025-60013MEDIUMF5OS-A FIPS HSM password vulnerabilityEPSS 0.2%CVE-2026-48122MEDIUMWorkspace settings can override executable and Gemfile paths used by the Ruby LSP VS Code extensionEPSS 0.2%CVE-2025-40582HIGHA vulnerability has been identified in SCALANCE LPE9403 (6GK5998-3GS00-2AC2) (All versions < V2.1 HF0 with SINEMA Remote Connect Edge ClientEPSS 0.2%CVE-2024-20461MEDIUMCisco ATA 190 Series Analog Telephone Adapter Firmware Command Injection VulnerabilityEPSS 0.2%CVE-2026-14852MEDIUMmk_sap_hana: Privilege escalation via crafted sapstartsrv process nameEPSS 0.2%CVE-2026-45036HIGHTabby auto-confirms ZMODEM detection on terminal output, leading to shell command execution from displayed file content under fish, bash, and zshEPSS 0.2%CVE-2026-55798MEDIUMPillow: WindowsViewer.get_command() OS command injection via unescaped shell pathEPSS 0.2%CVE-2026-70611MEDIUMElectron: DevTools embedder handler executes arbitrary files via shell openEPSS 0.2%