Weaknesses of type CWE-94
4,461 resultsInjeção de script
Ocorre quando a aplicação executa código dinâmico (JavaScript, Python, etc.) construído a partir de entrada do usuário sem validação ou sanitização adequada. Um atacante injeta comandos maliciosos que são interpretados e executados no contexto da aplicação, comprometendo dados, sessões ou o servidor.
Example
Um formulário web que avalia expressões matemáticas digitadas pelo usuário com eval() sem filtros. Um atacante entra 'os.system("rm -rf /")' em vez de "2+2", e o servidor executa o comando do sistema.
How to mitigate
Evite usar funções que executem código dinâmico (eval, exec, etc.) com entrada externa. Se inevitável, use sandboxing rigoroso, validação whitelist de entrada, e intérpretes isolados. Prefira APIs seguras que não interprem código arbitrário.
CVE-2025-8370MEDIUMPortabilis i-Educar educar_escolaridade_lst.php cross site scriptingEPSS 0.5%CVE-2025-59952HIGHminio-java Client XML Tag is Vulnerable to Value SubstitutionEPSS 0.5%CVE-2025-61732HIGHPotential code smuggling via doc comments in cmd/cgoEPSS 0.5%CVE-2024-36361MEDIUMPug through 3.0.2 allows JavaScript code execution if an application accepts untrusted input for the name option of the compileClient, compiEPSS 0.5%CVE-2023-39956MEDIUMElectron: Out-of-package code execution when launched with arbitrary cwdEPSS 0.5%CVE-2025-8369MEDIUMPortabilis i-Educar educar_avaliacao_desempenho_lst.php cross site scriptingEPSS 0.5%CVE-2025-8368MEDIUMPortabilis i-Educar pesquisa_pessoa_lst.php cross site scriptingEPSS 0.5%CVE-2024-4038MEDIUMBack In Stock Notifier for WooCommerce | WooCommerce Waitlist Pro <= 5.3.1 - Unauthenticated Arbitrary Shortcode ExecutionEPSS 0.5%CVE-2025-0530MEDIUMcode-projects Job Recruitment _feedback_system.php cross site scriptingEPSS 0.5%CVE-2025-8221MEDIUMjerryshensjf JPACookieShop 蛋糕商城JPA版 GoodsCustController.java goodsSearch cross site scriptingEPSS 0.5%CVE-2025-2787HIGHIngress-nginx vulnerability in KNIME Business HubEPSS 0.5%CVE-2022-41882MEDIUMNextcloud Desktop vulnerable to code injection via malicious linkEPSS 0.5%CVE-2025-33183HIGHNVIDIA Isaac-GR00T for all platforms contains a vulnerability in a Python component, where an attacker could cause a code injection issue. AEPSS 0.5%CVE-2026-55415HIGHdatamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statementsEPSS 0.5%CVE-2025-29629CRITICALGardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.12.2026 use weak defaEPSS 0.5%CVE-2025-26182MEDIUMAn issue in xxyopen novel plus v.4.4.0 and before allows a remote attacker to execute arbitrary code via the PageController.java fileEPSS 0.5%CVE-2023-31493MEDIUMRCE (Remote Code Execution) exists in ZoneMinder through 1.36.33 as an attacker can create a new .php log file in language folder, while exeEPSS 0.5%CVE-2025-33184HIGHNVIDIA Isaac-GR00T for all platforms contains a vulnerability in a Python component, where an attacker could cause a code injection issue. AEPSS 0.5%CVE-2026-56264CRITICALCrawl4AI - Arbitrary JavaScript Execution via /execute_js EndpointEPSS 0.5%CVE-2026-3302MEDIUMSourceCodester Doctor Appointment System Sign Up register.php cross site scriptingEPSS 0.5%