Weaknesses of type CWE-94
4,404 resultsInjeção de script
Ocorre quando a aplicação executa código dinâmico (JavaScript, Python, etc.) construído a partir de entrada do usuário sem validação ou sanitização adequada. Um atacante injeta comandos maliciosos que são interpretados e executados no contexto da aplicação, comprometendo dados, sessões ou o servidor.
Example
Um formulário web que avalia expressões matemáticas digitadas pelo usuário com eval() sem filtros. Um atacante entra 'os.system("rm -rf /")' em vez de "2+2", e o servidor executa o comando do sistema.
How to mitigate
Evite usar funções que executem código dinâmico (eval, exec, etc.) com entrada externa. Se inevitável, use sandboxing rigoroso, validação whitelist de entrada, e intérpretes isolados. Prefira APIs seguras que não interprem código arbitrário.
CVE-2024-9162HIGHAll-in-One WP Migration and Backup <= 7.86 - Authenticated (Administrator+) Arbitrary PHP Code InjectionEPSS 2.7%CVE-2024-42845HIGHAn eval Injection vulnerability in the component invesalius/reader/dicom.py of InVesalius 3.1.99991 through 3.1.99998 allows attackers to exEPSS 2.7%CVE-2019-10182HIGHIt was found that icedtea-web though 1.7.2 and 1.8.2 did not properly sanitize paths from <jar/> elements in JNLP files. An attacker could tEPSS 2.7%CVE-2019-15597—A code injection exists in node-df v0.1.4 that can allow an attacker to remote code execution by unsanitized input.EPSS 2.7%CVE-2019-15599—A Code Injection exists in tree-kill on Windows which allows a remote code execution when an attacker is able to control the input into the EPSS 2.7%CVE-2019-15598—A Code Injection exists in treekill on Windows which allows a remote code execution when an attacker is able to control the input into the cEPSS 2.7%CVE-2022-39833HIGHFileCloud Versions 20.2 and later allows remote attackers to potentially cause unauthorized remote code execution and access to reported APIEPSS 2.7%CVE-2017-16151—Based on details posted by the ElectronJS team; A remote code execution vulnerability has been discovered in Google Chromium that affects alEPSS 2.7%CVE-2021-1362HIGHCisco Unified Communications Products Remote Code Execution VulnerabilityEPSS 2.7%CVE-2022-25860HIGHVersions of the package simple-git before 3.16.0 are vulnerable to Remote Code Execution (RCE) via the clone(), pull(), push() and listRemotEPSS 2.7%CVE-2006-6975CRITICALPHP remote file inclusion vulnerability in centipaid_class.php in CentiPaid 1.4.3 allows remote attackers to execute arbitrary code via a UREPSS 2.7%CVE-2023-29492CRITICALNovi Survey before 8.9.43676 allows remote attackers to execute arbitrary code on the server in the context of the service account. This doeEPSS 2.7%KEVCVE-2021-40485HIGHMicrosoft Excel Remote Code Execution VulnerabilityEPSS 2.7%CVE-2024-21689HIGHThis High severity RCE (Remote Code Execution) vulnerability CVE-2024-21689 was introduced in versions 9.1.0, 9.2.0, 9.3.0, 9.4.0, 9.5.0, aEPSS 2.7%CVE-2018-19002—LCDS Laquis SCADA prior to version 4.1.0.4150 allows improper control of generation of code when opening a specially crafted project file, wEPSS 2.7%CVE-2026-44403HIGHWing FTP Server < 8.1.3 Authenticated Remote Code Execution via Session SerializationEPSS 2.6%CVE-2022-31691CRITICALSpring Tools 4 for Eclipse version 4.16.0 and below as well as VSCode extensions such as Spring Boot Tools, Concourse CI Pipeline Editor, BoEPSS 2.6%CVE-2025-1550HIGHArbitrary Code Execution via Crafted Keras Config for Model LoadingEPSS 2.6%CVE-2026-77647CRITICALSPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is relatEPSS 2.6%CVE-2020-11079HIGHcommand injection fix in node-dns-syncEPSS 2.6%