Weaknesses of type CWE-94
4,456 resultsInjeção de script
Ocorre quando a aplicação executa código dinâmico (JavaScript, Python, etc.) construído a partir de entrada do usuário sem validação ou sanitização adequada. Um atacante injeta comandos maliciosos que são interpretados e executados no contexto da aplicação, comprometendo dados, sessões ou o servidor.
Example
Um formulário web que avalia expressões matemáticas digitadas pelo usuário com eval() sem filtros. Um atacante entra 'os.system("rm -rf /")' em vez de "2+2", e o servidor executa o comando do sistema.
How to mitigate
Evite usar funções que executem código dinâmico (eval, exec, etc.) com entrada externa. Se inevitável, use sandboxing rigoroso, validação whitelist de entrada, e intérpretes isolados. Prefira APIs seguras que não interprem código arbitrário.
CVE-2025-53836CRITICALXWiki Rendering is vulnerable to RCE attacks when processing nested macrosEPSS 0.6%CVE-2026-27702CRITICALBudibase Vulnerable to Remote Code Execution via Unsafe eval() in View Filter Map Function (Budibase Cloud)EPSS 0.6%CVE-2022-27837MEDIUMA vulnerability using PendingIntent in Accessibility prior to version 12.5.3.2 in Android R(11.0) and 13.0.1.1 in Android S(12.0) allows attEPSS 0.6%CVE-2026-73032CRITICALPapersGPT for Zotero 0.6.1 RCE via Unsanitized LLM Response eval()EPSS 0.6%CVE-2026-21537HIGHMicrosoft Defender for Endpoint Linux Extension Remote Code Execution VulnerabilityEPSS 0.6%CVE-2026-6621MEDIUM1024bit extend-deep index.js prototype pollutionEPSS 0.6%CVE-2026-6594MEDIUMbrikcss merge prototype pollutionEPSS 0.6%CVE-2024-12790MEDIUMcode-projects Hostel Management Site room-details.php cross site scriptingEPSS 0.6%CVE-2024-27705HIGHCross Site Scripting vulnerability in Leantime v3.0.6 allows attackers to execute arbitrary code via upload of crafted PDF file to the filesEPSS 0.6%CVE-2025-56399HIGHalexusmai laravel-file-manager 3.3.1 and before allows an authenticated attacker to achieve Remote Code Execution (RCE) through a crafted fiEPSS 0.6%CVE-2026-46581HIGHIn Eclipse Mojarra versions 2.3 and following, URL handing in `DefaultFaceletFactory` does not properly sanitize and/or block remote URLs, aEPSS 0.6%CVE-2024-12789MEDIUMPbootCMS IndexController.php code injectionEPSS 0.6%CVE-2021-33635CRITICALPull malicious images may cause process to be hijackedEPSS 0.6%CVE-2022-42045—Certain Zemana products are vulnerable to Arbitrary code injection. This affects Watchdog Anti-Malware 4.1.422 and Zemana AntiMalware 3.2.28EPSS 0.6%CVE-2026-92125HIGHJenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject the @GroovyASTTransformationClass annotation, allowing attaEPSS 0.6%CVE-2025-13786MEDIUMtaosir WTCMS index.php fetch code injectionEPSS 0.6%CVE-2024-30567MEDIUMAn issue in JNT Telecom JNT Liftcom UMS V1.J Core Version JM-V15 allows a remote attacker to execute arbitrary code via the Network TroublesEPSS 0.6%CVE-2026-66745HIGHArtica Proxy 4.50 Session Fixation via fw.login.phpEPSS 0.6%CVE-2026-28505HIGHTautulli: RCE via eval() sandbox bypass using lambda nested scope to escape co_names whitelist checkEPSS 0.6%CVE-2024-39915CRITICALAuthenticated remote code execution in ThrukEPSS 0.6%