Falhas do tipo CWE-78

4.669 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2026-68519HIGHGlances: `--disable-config-exec` does not cover on-alert action commands (incomplete fix of CVE-2026-53925)EPSS 0.2%CVE-2024-21782MEDIUMBIG-IP and BIG-IQ secure copy vulnerabilityEPSS 0.2%CVE-2023-53158MEDIUMThe gix-transport crate before 0.36.1 for Rust allows command execution via the "gix clone 'ssh://-oProxyCommand=open$IFS" substring. NOTE: EPSS 0.2%CVE-2023-43066MEDIUM Dell Unity prior to 5.3 contains a Restricted Shell Bypass vulnerability. This could allow an authenticated, local attacker to exploit thisEPSS 0.2%CVE-2026-34779MEDIUMElectron: AppleScript injection in app.moveToApplicationsFolder on macOSEPSS 0.2%CVE-2025-54595HIGHPearcleaner's unauthenticated access to privileged XPC helper allows root command executionEPSS 0.2%CVE-2026-68518HIGHGlances: Command injection bypass of action-template sanitizer via cross-field shell-operator reconstructionEPSS 0.2%CVE-2025-20220MEDIUMA vulnerability in the CLI of Cisco Secure Firewall Management Center (FMC) Software and Cisco Secure Firewall Threat Defense (FTD) SoftwareEPSS 0.2%CVE-2026-68939LOWPyenv: Glob/wildcard metacharacters bypass is_version_safe(), causing silent version/interpreter substitution via unquoted expansion (CVE-2022-35861 residual)EPSS 0.2%CVE-2026-20040HIGHCisco IOS XR Software CLI Privilege Escalation VulnerabilityEPSS 0.2%CVE-2026-49219MEDIUMImageMagick: Policy Bypass can read disallowed filesEPSS 0.2%CVE-2026-10805MEDIUMNetworkmanager: networkmanager: local privilege escalation via malformed mud urls in dhclient backendEPSS 0.2%CVE-2026-87088HIGHTanium addressed an unauthorized code execution vulnerability in Enforce.EPSS 0.2%CVE-2025-20213MEDIUMCisco Catalyst SDWAN Manager Arbitrary File Overwrite VulnerabilityEPSS 0.2%CVE-2026-41010HIGHReleaseJob#unpack builds job_dir = File.join(@release_dir, 'jobs', name) and job_tgz = File.join(@release_dir, 'jobs', "#{name}.tgz") where EPSS 0.2%CVE-2026-90894HIGHParallels Desktop local privilege escalation via appliance extract argument injectionEPSS 0.2%CVE-2025-54314LOWThor before 1.4.0 can construct an unsafe shell command from library input. NOTE: this is disputed by the Supplier because "the method that EPSS 0.2%CVE-2025-6183HIGHConfigd InjectionEPSS 0.2%CVE-2026-67180HIGHGoogle Turbinia arbitrary command executionEPSS 0.2%CVE-2026-55448MEDIUMmise: Local credential_command executes untrusted configEPSS 0.2%