Falhas do tipo CWE-78

4.608 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2025-11202CRITICALwin-cli-mcp-server resolveCommandPath Command Injection Remote Code Execution VulnerabilityEPSS 2.8%CVE-2026-19682CRITICALCommand InjectionEPSS 2.8%CVE-2026-24841CRITICALDokploy Vulnerable to Authenticated Remote Code Execution via Command Injection in Docker Container Terminal WebSocket EndpointEPSS 2.8%CVE-2022-35132HIGHUsermin through 1.850 allows a remote authenticated user to execute OS commands via command injection in a filename for the GPG module.EPSS 2.8%CVE-2021-37913CRITICALHGiga OAKlouds - Command Injection-2EPSS 2.8%CVE-2021-37912CRITICALHGiga OAKlouds - Command Injection-1EPSS 2.8%CVE-2026-5663MEDIUMOFFIS DCMTK storescp storescp.cc executeOnEndOfStudy os command injectionEPSS 2.8%CVE-2022-38547HIGHA post-authentication command injection vulnerability in the CLI command of Zyxel ZyWALL/USG series firmware versions 4.20 through 4.72, VPNEPSS 2.8%CVE-2022-37337CRITICALA command execution vulnerability exists in the access control functionality of Netgear Orbi Router RBR750 4.6.8.5. A specially-crafted HTTPEPSS 2.8%CVE-2026-75616HIGHCommand Injection in Router Web Management InterfaceEPSS 2.8%CVE-2025-34335HIGHAudioCodes Fax/IVR Appliance <= 2.6.23 Authenticated Command Injection via ActivateLicense.phpEPSS 2.8%CVE-2013-10049CRITICALRaidsonic NAS Devices Unauthenticated Remote Command ExecutionEPSS 2.8%CVE-2026-3102MEDIUMexiftool PNG File MacOS.pm SetMacOSTags os command injectionEPSS 2.8%CVE-2019-1634HIGHCisco Integrated Management Controller Command Injection VulnerabilityEPSS 2.8%CVE-2025-59360CRITICALOS command injection in Chaos Mesh via the killProcesses mutationEPSS 2.8%CVE-2021-36295HIGHDell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authenticated remote code execution vulnerability. A remote malicious userEPSS 2.8%CVE-2021-36296HIGHDell VNX2 OE for File versions 8.1.21.266 and earlier, contain an authenticated remote code execution vulnerability. A remote malicious userEPSS 2.8%CVE-2023-50651CRITICALTOTOLINK X6000R v9.4.0cu.852_B20230719 was discovered to contain a remote command execution (RCE) vulnerability via the component /cgi-bin/cEPSS 2.8%CVE-2020-12775CRITICALHicos citizen certificate client-side component - Command InjectionEPSS 2.8%CVE-2026-34599HIGHCoolify: Authenticated Remote Code Execution in GetLogs Livewire ComponentEPSS 2.8%