Weaknesses of type CWE-94
4,456 resultsInjeção de script
Ocorre quando a aplicação executa código dinâmico (JavaScript, Python, etc.) construído a partir de entrada do usuário sem validação ou sanitização adequada. Um atacante injeta comandos maliciosos que são interpretados e executados no contexto da aplicação, comprometendo dados, sessões ou o servidor.
Example
Um formulário web que avalia expressões matemáticas digitadas pelo usuário com eval() sem filtros. Um atacante entra 'os.system("rm -rf /")' em vez de "2+2", e o servidor executa o comando do sistema.
How to mitigate
Evite usar funções que executem código dinâmico (eval, exec, etc.) com entrada externa. Se inevitável, use sandboxing rigoroso, validação whitelist de entrada, e intérpretes isolados. Prefira APIs seguras que não interprem código arbitrário.
CVE-2026-45714CRITICALCubeCart: Server-Side Template Injection (SSTI) in Smarty Templates leading to RCEEPSS 0.5%CVE-2022-29216HIGHCode injection in `saved_model_cli` in TensorFlowEPSS 0.5%CVE-2026-32573CRITICALWordPress Nelio AB Testing plugin <= 8.2.7 - Remote Code Execution (RCE) vulnerabilityEPSS 0.5%CVE-2026-71232HIGHMacCMS10 - Incomplete Function Blacklist in Template Editor Enables Authenticated RCEEPSS 0.5%CVE-2026-32414HIGHWordPress Advanced Woo Labels plugin <= 2.36 - Remote Code Execution (RCE) vulnerabilityEPSS 0.5%CVE-2026-50187HIGHOh My Zsh: Arbitrary Code Execution in oh-my-zsh dotenv plugin via malicious .env filesEPSS 0.5%CVE-2025-1155MEDIUMWebkul QloApps Your Location Search stores cross site scriptingEPSS 0.5%CVE-2022-45177HIGHAn issue was discovered in LIVEBOX Collaboration vDesk through v031. An Observable Response Discrepancy can occur under the /api/v1/vdeskintEPSS 0.5%CVE-2026-30479CRITICALA Dynamic-link Library Injection vulnerability in OSGeo Project MapServer before v8.0 allows attackers to execute arbitrary code via a craftEPSS 0.5%CVE-2026-13749HIGHSnowflake CLI Arbitrary Code Execution via Snowpark Annotation Processor Template InjectionEPSS 0.5%CVE-2026-18874MEDIUMVolsync-addon-controller: volsync-addon-controller: annotation values rendered into yaml via text/template without escaping allows yaml injection into subscriptionEPSS 0.5%CVE-2026-73170HIGHNozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in the Modbus CSV import wEPSS 0.5%CVE-2025-1465LOWlmxcms Maintenance db.inc.php code injectionEPSS 0.5%CVE-2026-15538MEDIUMprimefaces primereact API ObjectUtils.js ObjectUtils.mutateFieldData prototype pollutionEPSS 0.5%CVE-2024-12983MEDIUMcode-projects Hospital Management System Edit Doctor Details Page manage-doctors.php cross site scriptingEPSS 0.5%CVE-2025-67164CRITICALAn authenticated arbitrary file upload vulnerability in the /storage/poc.php component of Pagekit CMS v1.0.18 allows attackers to execute arEPSS 0.5%CVE-2025-1337MEDIUMEastnets PaymentSafe BIC Search cross site scriptingEPSS 0.5%CVE-2026-94572CRITICALIn OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and pool tls_ciphers field for control charactEPSS 0.5%CVE-2026-94571CRITICALIn OpenStack Octavia before 18.0.1, the Amphora provider driver did not reject control characters in the L7 policy redirect_url and redirectEPSS 0.5%CVE-2026-40877HIGHCombodo iTop: PHP Object Injection Leading to Remote Code Execution on user preferencesEPSS 0.5%