Weaknesses of type CWE-94
4,497 resultsInjeção de script
Ocorre quando a aplicação executa código dinâmico (JavaScript, Python, etc.) construído a partir de entrada do usuário sem validação ou sanitização adequada. Um atacante injeta comandos maliciosos que são interpretados e executados no contexto da aplicação, comprometendo dados, sessões ou o servidor.
Example
Um formulário web que avalia expressões matemáticas digitadas pelo usuário com eval() sem filtros. Um atacante entra 'os.system("rm -rf /")' em vez de "2+2", e o servidor executa o comando do sistema.
How to mitigate
Evite usar funções que executem código dinâmico (eval, exec, etc.) com entrada externa. Se inevitável, use sandboxing rigoroso, validação whitelist de entrada, e intérpretes isolados. Prefira APIs seguras que não interprem código arbitrário.
CVE-2023-53940HIGHCodigo Markdown Editor 1.0.1 Electron Arbitrary Code Execution via Markdown FileEPSS 0.2%CVE-2025-27998HIGHAn issue in Valvesoftware Steam Client Steam Client 1738026274 allows attackers to escalate privileges via a crafted executable or DLL.EPSS 0.2%CVE-2022-37396MEDIUMIn JetBrains Rider before 2022.2 Trust and Open Project dialog could be bypassed, leading to local code executionEPSS 0.2%CVE-2026-73073HIGHVim: Arbitrary Ex Command Execution in C Omni-CompletionEPSS 0.2%CVE-2024-51330MEDIUMAn issue in UltiMaker Cura v.4.41 and 5.8.1 and before allows a local attacker to execute arbitrary code via Inter-process communication (IPEPSS 0.2%CVE-2026-78367HIGHRpm: rpmbuild gettarspec() crafted tar member name → macro injectionEPSS 0.2%CVE-2026-73248HIGHcalibre: Bypass of Python template restrictions via nested `template()` leading to RCEEPSS 0.2%CVE-2026-101861LOWLangflow Code Execution via eval() in Component Input SchemaEPSS 0.2%CVE-2026-42049HIGHjadx: RCE Via Groovy Code Injection in Gradle ExportEPSS 0.2%CVE-2026-19060MEDIUMFoundationAgents MetaGPT code injectionEPSS 0.2%CVE-2026-7580MEDIUMExiftool JPEG/QuickTime/MOV/MP4 GM.pm Process_mrld code injectionEPSS 0.2%CVE-2026-30960CRITICALRSSN has Arbitrary Code Execution via Unvalidated JIT Instruction Generation in C-FFI InterfaceEPSS 0.2%CVE-2026-8021MEDIUMScript injection in UI in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who convinced a user to engage in specific UI gestuEPSS 0.2%CVE-2026-19058MEDIUMFoundationAgents MetaGPT data_interpreter.py DataInterpreter code injectionEPSS 0.2%CVE-2026-34725HIGHdbgate-web: Stored XSS in applicationIcon leads to potential RCE in Electron due to unsafe renderer configurationEPSS 0.2%CVE-2026-34223HIGHA vulnerability has been identified in Desigo CC ClickOnce Client V6 (All versions), Desigo CC ClickOnce Client V7 (All versions), Desigo CCEPSS 0.2%CVE-2025-3753HIGHUnsafe use of eval() method in rosbag toolEPSS 0.2%CVE-2026-42851HIGH@kitty-edit DCS + --color=geninclude vulnerable to Unauthenticated in-process RCEEPSS 0.2%CVE-2025-67750HIGHLightning Flow Scanner is Vulnerable to Code Injection via Unsafe Use of new Function() in APIVersion RuleEPSS 0.2%CVE-2026-24155HIGHNVIDIA NeMo Framework for all platforms contains a code injection vulnerability. A successful exploit of this vulnerability might lead to coEPSS 0.2%