Weaknesses of type CWE-94
4,467 resultsInjeção de script
Ocorre quando a aplicação executa código dinâmico (JavaScript, Python, etc.) construído a partir de entrada do usuário sem validação ou sanitização adequada. Um atacante injeta comandos maliciosos que são interpretados e executados no contexto da aplicação, comprometendo dados, sessões ou o servidor.
Example
Um formulário web que avalia expressões matemáticas digitadas pelo usuário com eval() sem filtros. Um atacante entra 'os.system("rm -rf /")' em vez de "2+2", e o servidor executa o comando do sistema.
How to mitigate
Evite usar funções que executem código dinâmico (eval, exec, etc.) com entrada externa. Se inevitável, use sandboxing rigoroso, validação whitelist de entrada, e intérpretes isolados. Prefira APIs seguras que não interprem código arbitrário.
CVE-2026-1744MEDIUMD-Link DSL-6641K sp_pppoe_user.js doSubmitPPP cross site scriptingEPSS 0.4%CVE-2026-4515MEDIUMFoundation Agents MetaGPT operator.py code_generate code injectionEPSS 0.4%CVE-2025-5133MEDIUMTmall Demo Search Box cross site scriptingEPSS 0.4%CVE-2024-45390HIGH@blakeembrey/template vulnerable to code injection when attacker controls template inputEPSS 0.4%CVE-2024-8374HIGHArbitrary Code Injection in CuraEPSS 0.4%CVE-2026-15533MEDIUMDedeCMS Column Management search.php code injectionEPSS 0.4%CVE-2025-53928MEDIUMMaxKB has RCE in MCP callEPSS 0.4%CVE-2024-13069MEDIUMSourceCodester Multi Role Login System add-user.php cross site scriptingEPSS 0.4%CVE-2025-0794MEDIUMESAFENET CDG todoDetail.jsp cross site scriptingEPSS 0.4%CVE-2024-36531MEDIUMnukeviet v.4.5 and before and nukeviet-egov v.1.2.02 and before are vulnerable to arbitrary code execution via the /admin/extensions/upload.EPSS 0.4%CVE-2026-5848MEDIUMjeecgboot JimuReport Data Source testConnection DriverManager.getConnection code injectionEPSS 0.4%CVE-2025-0795MEDIUMESAFENET CDG todolistjump.jsp cross site scriptingEPSS 0.4%CVE-2026-46517HIGHLMDeploy: Hardcoded trust_remote_code=True is an implicit unsafe remote-code load path with no user opt-outEPSS 0.4%CVE-2024-1706MEDIUMZKTeco ZKBio Access IVS Department Name Search Bar cross site scriptingEPSS 0.4%CVE-2023-38576—Hidden functionality vulnerability in LAN-WH300N/RE all versions provided by LOGITEC CORPORATION allows an authenticated user to execute arbEPSS 0.4%CVE-2023-6691HIGHCode Injection vulnerability in Cambium ePMP Force 300-25EPSS 0.4%CVE-2025-23357HIGHNVIDIA Megatron-LM for all platforms contains a vulnerability in a script, where malicious data created by an attacker may cause a code injeEPSS 0.4%CVE-2023-1367MEDIUM Code Injection in alextselegidis/easyappointmentsEPSS 0.4%CVE-2025-3612MEDIUMDemtec Graphytics HTTP GET Parameter visualization cross site scriptingEPSS 0.4%CVE-2025-3326MEDIUMiteaj iboot 物联网网关 File Upload upload cross site scriptingEPSS 0.4%