Falhas do tipo CWE-78

4.607 resultados

Injeção de comando do sistema operacional

A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.

Exemplo

Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Como mitigar

Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.

CVE-2024-44342HIGHD-Link DIR-846W A1 FW100A43 was discovered to contain a remote command execution (RCE) vulnerability via the wl(0).(0)_ssid parameter. This EPSS 2.0%CVE-2026-53479HIGHDell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1EPSS 2.0%CVE-2026-20764HIGHCopeland XWEB and XWEB Pro OS Command InjectionEPSS 2.0%CVE-2024-5291HIGHD-Link DIR-2150 GetDeviceSettings Target Command Injection Remote Code Execution VulnerabilityEPSS 2.0%CVE-2024-5295HIGHD-Link G416 flupl self Command Injection Remote Code Execution VulnerabilityEPSS 2.0%CVE-2025-15063CRITICALOllama MCP Server execAsync Command Injection Remote Code Execution VulnerabilityEPSS 2.0%CVE-2022-44844CRITICALTOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the pass parameter in the setting/setEPSS 2.0%CVE-2022-44843CRITICALTOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the port parameter in the setting/setEPSS 2.0%CVE-2021-28203HIGHASUS BMC's firmware: command injection - Web Set Media Image functionEPSS 2.0%CVE-2022-48124CRITICALTOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the FileName parameter in the settingEPSS 2.0%CVE-2022-48126CRITICALTOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the username parameter in the settingEPSS 2.0%CVE-2022-48122CRITICALTOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the dayvalid parameter in the settingEPSS 2.0%CVE-2022-48125CRITICALTOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the password parameter in the settingEPSS 2.0%CVE-2022-48121CRITICALTOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the rsabits parameter in the setting/EPSS 2.0%CVE-2022-48123CRITICALTOTOlink A7100RU V7.4cu.2313_B20191024 was discovered to contain a command injection vulnerability via the servername parameter in the settiEPSS 2.0%CVE-2026-32260HIGHCommand Injection via incomplete shell metacharacter blocklist in node:child_process (bypass of CVE-2026-27190 fix)EPSS 2.0%CVE-2026-16348HIGHCommand Injection Vulnerability in VPN connection of Archer BE800EPSS 2.0%CVE-2026-74770HIGHDell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Neutralization of Special Elements used in an OS Command ('OS CommanEPSS 2.0%CVE-2005-10004HIGHCacti graph_view.php RCE via graph_start Parameter InjectionEPSS 2.0%CVE-2026-72589CRITICALalseambusher crontab-ui - Unauthenticated RCE via Shell Injection in Imported Database hook FieldEPSS 1.9%