Weaknesses of type CWE-94

4,456 results

Injeção de script

Ocorre quando a aplicação executa código dinâmico (JavaScript, Python, etc.) construído a partir de entrada do usuário sem validação ou sanitização adequada. Um atacante injeta comandos maliciosos que são interpretados e executados no contexto da aplicação, comprometendo dados, sessões ou o servidor.

Example

Um formulário web que avalia expressões matemáticas digitadas pelo usuário com eval() sem filtros. Um atacante entra 'os.system("rm -rf /")' em vez de "2+2", e o servidor executa o comando do sistema.

How to mitigate

Evite usar funções que executem código dinâmico (eval, exec, etc.) com entrada externa. Se inevitável, use sandboxing rigoroso, validação whitelist de entrada, e intérpretes isolados. Prefira APIs seguras que não interprem código arbitrário.

CVE-2024-45201HIGHAn issue was discovered in llama_index before 0.10.38. download/integration.py includes an exec call for import {cls_name}.EPSS 0.5%CVE-2026-40877HIGHCombodo iTop: PHP Object Injection Leading to Remote Code Execution on user preferencesEPSS 0.5%CVE-2024-55918MEDIUMAn issue was discovered in the Graphics::ColorNames package before 3.2.0 for Perl. There is an ambiguity between modules and filenames that EPSS 0.5%CVE-2025-46569HIGHOPA server Data API HTTP path injection of RegoEPSS 0.5%CVE-2026-51997HIGHAn issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary code via the open() functionsEPSS 0.5%CVE-2024-37109CRITICALWordPress WishList Member X plugin < 3.26.7 - Authenticated Arbitrary PHP Code Execution vulnerabilityEPSS 0.5%CVE-2024-32492HIGHAn issue was discovered in Znuny 7.0.1 through 7.0.16 where the ticket detail view in the customer front allows the execution of external JaEPSS 0.5%CVE-2025-46725HIGHLangroid has a Code Injection vulnerability in LanceDocChatAgent through vector_storeEPSS 0.5%CVE-2024-11971MEDIUMGuizhou Xiaoma Technology jpress Avatar upload cross site scriptingEPSS 0.5%CVE-2025-58372HIGHRoo Code: Potential Remote Code Execution via .code-workspaceEPSS 0.5%CVE-2026-76335HIGHRemote Code Execution (RCE) through Splunk Web Manager Configuration in Splunk EnterpriseEPSS 0.5%CVE-2026-8635CRITICALArbitrary Code Execution in Python Interpreter ComponentEPSS 0.5%CVE-2026-7873CRITICALCode Injection Vulnerability in Code Validation EndpointEPSS 0.5%CVE-2026-13435CRITICALPython Interpreter Sandbox Bypass Leading to Sensitive Data ExposureEPSS 0.5%CVE-2025-69872CRITICALDiskCache (python-diskcache) through 5.6.3 uses Python pickle for serialization by default. An attacker with write access to the cache direcEPSS 0.5%CVE-2026-16800HIGHImproper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026.2.2 and earlier aEPSS 0.5%CVE-2026-16801HIGHImproper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier EPSS 0.5%CVE-2024-11742MEDIUMSourceCodester Best House Rental Management System ajax.php cross site scriptingEPSS 0.5%CVE-2022-23008—On NGINX Controller API Management versions 3.18.0-3.19.0, an authenticated attacker with access to the "user" or "admin" role can use undisEPSS 0.5%CVE-2026-8056HIGHParameter Injection Vulnerability in API Graph Execution EngineEPSS 0.5%