Falhas do tipo CWE-78
4.609 resultadosInjeção de comando do sistema operacional
A aplicação constrói comandos do SO usando dados de entrada do usuário sem sanitização adequada, permitindo que um atacante injete comandos adicionais. Quando o comando é executado, instruções maliciosas do atacante rodam com os privilégios da aplicação, comprometendo o servidor.
Exemplo
Um script PHP que executa `system('ping ' . $_GET['host'])` sem validar o parâmetro. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.
Como mitigar
Sempre valide e sanitize entrada de usuário; prefira APIs seguras (como funções que aceitam argumentos separados em vez de strings de comando); execute com menor privilégio necessário; use listas brancas de valores permitidos quando possível.
CVE-2026-70374HIGHHashBrown CMS - OS Command Injection in Media Upload Thumbnail GenerationEPSS 1.9%CVE-2026-78037HIGHXiiaozet LK100W OS Command InjectionEPSS 1.9%CVE-2026-34005HIGHIn Sofia on Xiongmai DVR/NVR (AHB7008T-MH-V2 and NBD7024H-P) 4.03.R11 devices, root OS command injection can occur via shell metacharacters EPSS 1.9%CVE-2026-82774HIGHImproper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS M2M Gateway Series and EPSS 1.9%CVE-2026-27130CRITICALDokploy has Command Injection in its Service OperationsEPSS 1.9%CVE-2026-82766HIGHImproper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in SGA1000. If this vulnerability isEPSS 1.9%CVE-2026-82791HIGHImproper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec CAN 2.0B Communication WirEPSS 1.9%CVE-2026-82779HIGHImproper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS TM Series. If this vulnEPSS 1.9%CVE-2026-70375HIGHHashBrown CMS - OS Command Injection via Git Deployer Branch FieldEPSS 1.9%CVE-2026-82777HIGHImproper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS PAC Series. If this vulEPSS 1.9%CVE-2026-82794HIGHSolarView Compact contains an OS command Injection vulnerability in in Schedule Settings. If this vulnerability is exploited, an arbitrary OEPSS 1.9%CVE-2026-82762HIGHImproper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec FX5000 series, FX4000 seriEPSS 1.9%CVE-2020-3371MEDIUMCisco Integrated Management Controller Command Injection VulnerabilityEPSS 1.9%CVE-2021-43928CRITICALImproper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in mail sending and receiving compoEPSS 1.9%CVE-2023-42123HIGHControl Web Panel mysql_manager Command Injection Remote Code Execution VulnerabilityEPSS 1.9%CVE-2023-7311CRITICALBYTEVALUE Intelligent Flow Control Router Command InjectionEPSS 1.9%CVE-2024-5241MEDIUMHuashi Private Cloud CDN Live Streaming Acceleration Server ipconfig_new.php os command injectionEPSS 1.9%CVE-2022-43973HIGHArbitrary code execution in Linksys WRT54GLEPSS 1.9%CVE-2021-21388HIGHCommand Injection Vulnerability in systeminformationEPSS 1.9%CVE-2026-45633CRITICALDokploy: Command Injection in /docker-container-logs EndpointEPSS 1.9%