Weaknesses of type CWE-94

4,497 results

Injeção de script

Ocorre quando a aplicação executa código dinâmico (JavaScript, Python, etc.) construído a partir de entrada do usuário sem validação ou sanitização adequada. Um atacante injeta comandos maliciosos que são interpretados e executados no contexto da aplicação, comprometendo dados, sessões ou o servidor.

Example

Um formulário web que avalia expressões matemáticas digitadas pelo usuário com eval() sem filtros. Um atacante entra 'os.system("rm -rf /")' em vez de "2+2", e o servidor executa o comando do sistema.

How to mitigate

Evite usar funções que executem código dinâmico (eval, exec, etc.) com entrada externa. Se inevitável, use sandboxing rigoroso, validação whitelist de entrada, e intérpretes isolados. Prefira APIs seguras que não interprem código arbitrário.

CVE-2025-33236HIGHNVIDIA NeMo Framework contains a vulnerability where malicious data created by an attacker could cause code injection. A successful exploit EPSS 0.2%CVE-2026-28801MEDIUMNatro Macro: Code Injection through Pattern/Path filesEPSS 0.2%CVE-2023-28796HIGHIPC Bypass Through PLT Section in ELFEPSS 0.2%CVE-2026-44728HIGHImproper Control of Generation of Code when compiling specifically crafted malicious code with @babel/plugin-transform-modules-systemjsEPSS 0.2%CVE-2026-100881LOWzhistaredu StarTraining application.yml cross site scriptingEPSS 0.2%CVE-2026-25797MEDIUMImageMagick vulnerable to Code injection via PostScript header in ps codersEPSS 0.2%CVE-2026-10688MEDIUMahujasid blender-mcp server.py execute_blender_code code injectionEPSS 0.2%CVE-2025-63693MEDIUMThe comment editing template (dzz/comment/template/edit_form.htm) in DzzOffice 2.3.x lacks adequate security escaping for user-controllable EPSS 0.2%CVE-2025-24959LOWEnvironment Variable Injection for dotenv API in zxEPSS 0.2%CVE-2024-39289HIGHUnsafe use of eval() method in rosparam toolEPSS 0.2%CVE-2026-42890MEDIUMactual Allows Electron to Run As NodeEPSS 0.2%CVE-2025-12669MEDIUMImproper Control of Generation of Code ('Code Injection') in GitLabEPSS 0.2%CVE-2025-55313HIGHAn issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. They allow potential arbitrary codEPSS 0.2%CVE-2024-39835HIGHUnsafe use of eval() method in roslaunch toolEPSS 0.2%CVE-2024-48829MEDIUMDell SmartFabric OS10 Software, versions prior to 10.6.1.0, contain an Improper Control of Generation of Code ('Code Injection') vulnerabiliEPSS 0.2%CVE-2026-72718HIGHgoose: Arbitrary command execution in goose CLI via `goose review` via git core.fsmonitorEPSS 0.2%CVE-2026-54057HIGHKitty vulnerable to command injection via unsanitized OSC 21 query replyEPSS 0.2%CVE-2026-0414MEDIUMInsufficient Input Validation Allows Unauthorized Modification of Router Software in certain NETGEAR RoutersEPSS 0.2%CVE-2026-45353CRITICALelecterm: Local code through electerm's single-instance socketEPSS 0.2%CVE-2025-0664MEDIUMA locally authenticated, privileged user can craft a malicious OpenSSL configuration file, potentially leading the agent to load an arbitrarEPSS 0.2%