Weaknesses of type CWE-94

4,483 results

Injeção de script

Ocorre quando a aplicação executa código dinâmico (JavaScript, Python, etc.) construído a partir de entrada do usuário sem validação ou sanitização adequada. Um atacante injeta comandos maliciosos que são interpretados e executados no contexto da aplicação, comprometendo dados, sessões ou o servidor.

Example

Um formulário web que avalia expressões matemáticas digitadas pelo usuário com eval() sem filtros. Um atacante entra 'os.system("rm -rf /")' em vez de "2+2", e o servidor executa o comando do sistema.

How to mitigate

Evite usar funções que executem código dinâmico (eval, exec, etc.) com entrada externa. Se inevitável, use sandboxing rigoroso, validação whitelist de entrada, e intérpretes isolados. Prefira APIs seguras que não interprem código arbitrário.

CVE-2025-15372MEDIUMyoulaitech vue3-element-admin Notice index.vue cross site scriptingEPSS 0.3%CVE-2025-33178HIGHNVIDIA NeMo Framework for all platforms contains a vulnerability in the bert services component where malicious data created by an attacker EPSS 0.3%CVE-2025-13784MEDIUMyungifez Skuul School Management System SVG File edit cross site scriptingEPSS 0.3%CVE-2025-14801MEDIUMxiweicheng TMS create createComment cross site scriptingEPSS 0.3%CVE-2019-16283HIGHA potential security vulnerability has been identified with a version of the HP Softpaq installer that can lead to arbitrary code execution.EPSS 0.3%CVE-2025-7902MEDIUMyangzongzhuan RuoYi SysNoticeController.java addSave cross site scriptingEPSS 0.3%CVE-2025-8511MEDIUMPortabilis i-Diario Observações diario-de-observacoes cross site scriptingEPSS 0.3%CVE-2025-11027MEDIUMgivanz Vvveb SVG File cross site scriptingEPSS 0.3%CVE-2024-28893HIGHCertain HP software packages (SoftPaqs) are potentially vulnerable to arbitrary code execution when the SoftPaq configuration file has been EPSS 0.3%CVE-2026-2160MEDIUMSourceCodester Simple Responsive Tourism Website Master.php cross site scriptingEPSS 0.3%CVE-2025-8510MEDIUMPortabilis i-Educar educar_matricula_lst.php Gerar cross site scriptingEPSS 0.3%CVE-2025-9306MEDIUMSourceCodester Advanced School Management System addNotice cross site scriptingEPSS 0.3%CVE-2025-14201MEDIUMalokjaiswal Hotel-Management-services-using-MYSQL-and-php dishsub.php cross site scriptingEPSS 0.3%CVE-2025-10631MEDIUMitsourcecode Online Petshop Management System Available Products addcnp.php cross site scriptingEPSS 0.3%CVE-2025-10632MEDIUMitsourcecode Online Petshop Management System Admin Dashboard availableframe.php cross site scriptingEPSS 0.3%CVE-2026-10173MEDIUMOrthanc Explorer 2 URL StudyList.vue cross site scriptingEPSS 0.3%CVE-2026-22314HIGHVendor disputed record. The reported behaviour is documented administrative functionality restricted to dedicated administrative permissioEPSS 0.3%CVE-2024-54997MEDIUMMonicaHQ v4.1.1 was discovered to contain an authenticated Client-Side Injection vulnerability via the entry text field at /journal/entries/EPSS 0.3%CVE-2025-66533MEDIUMWordPress GiveWP plugin <= 4.13.1 - Arbitrary Shortocde Execution vulnerabilityEPSS 0.3%CVE-2025-31365MEDIUMAn Improper Control of Generation of Code ('Code Injection') vulnerability [CWE-94] in FortiClientMac 7.4.0 through 7.4.3, 7.2.1 through 7.2EPSS 0.3%