Weaknesses of type CWE-94

4,412 results

Injeção de script

Ocorre quando a aplicação executa código dinâmico (JavaScript, Python, etc.) construído a partir de entrada do usuário sem validação ou sanitização adequada. Um atacante injeta comandos maliciosos que são interpretados e executados no contexto da aplicação, comprometendo dados, sessões ou o servidor.

Example

Um formulário web que avalia expressões matemáticas digitadas pelo usuário com eval() sem filtros. Um atacante entra 'os.system("rm -rf /")' em vez de "2+2", e o servidor executa o comando do sistema.

How to mitigate

Evite usar funções que executem código dinâmico (eval, exec, etc.) com entrada externa. Se inevitável, use sandboxing rigoroso, validação whitelist de entrada, e intérpretes isolados. Prefira APIs seguras que não interprem código arbitrário.

CVE-2021-43944HIGHThis issue exists to document that a security improvement in the way that Jira Server and Data Center use templates has been implemented. AfEPSS 2.3%CVE-2026-26833CRITICALthumbler through 1.1.2 allows OS command injection via the input, output, time, or size parameter in the thumbnail() function because user iEPSS 2.3%CVE-2023-49109CRITICALRemote Code Execution in Apache DolphinschedulerEPSS 2.3%CVE-2024-13346HIGHAvada Theme <= 7.11.13 - Unauthenticated Arbitrary Shortcode ExecutionEPSS 2.3%CVE-2024-48359CRITICALQualitor v8.24 was discovered to contain a remote code execution (RCE) vulnerability via the gridValoresPopHidden parameter.EPSS 2.3%CVE-2023-24538CRITICALBackticks not treated as string delimiters in html/templateEPSS 2.3%CVE-2022-31860CRITICALAn issue was discovered in OpenRemote through 1.0.4 allows attackers to execute arbitrary code via a crafted Groovy rule.EPSS 2.3%CVE-2022-24735LOWLua scripts can be manipulated to overcome ACL rules in RedisEPSS 2.3%CVE-2025-22906CRITICALRE11S v1.11 was discovered to contain a command injection vulnerability via the L2TPUserName parameter at /goform/setWAN.EPSS 2.3%CVE-2022-41138CRITICALIn Zutty before 0.13, DECRQSS in text written to the terminal can achieve arbitrary code execution.EPSS 2.2%CVE-2022-1575CRITICALArbitrary Code Execution through Sanitizer Bypass in jgraph/drawioEPSS 2.2%CVE-2024-54152CRITICALAngular Expressions - Remote Code Execution when using localsEPSS 2.2%CVE-2022-35772HIGHAzure Site Recovery Remote Code Execution VulnerabilityEPSS 2.2%CVE-2021-23281CRITICALRemote Code executionEPSS 2.2%CVE-2024-21643HIGHMicrosoft.IdentityModel.Protocols.SignedHttpRequest remote code execution vulnerabilityEPSS 2.2%CVE-2023-30404CRITICALAigital Wireless-N Repeater Mini_Router v0.131229 was discovered to contain a remote code execution (RCE) vulnerability via the sysCmd paramEPSS 2.2%CVE-2006-3136CRITICALMultiple PHP remote file inclusion vulnerabilities in Nucleus 3.23 allow remote attackers to execute arbitrary PHP code via a URL the DIR_LIEPSS 2.2%CVE-2022-0921HIGHAbusing Backup/Restore feature to achieve Remote Code Execution in microweber/microweberEPSS 2.2%CVE-2024-42634CRITICALA Command Injection vulnerability exists in formWriteFacMac of the httpd binary in Tenda AC9 v15.03.06.42. As a result, attacker can executeEPSS 2.2%CVE-2023-30179HIGHCraftCMS version 3.7.59 is vulnerable to Server-Side Template Injection (SSTI). An authenticated attacker can inject Twig Template to User PEPSS 2.2%