Weaknesses of type CWE-94
4,363 resultsInjeção de script
Ocorre quando a aplicação executa código dinâmico (JavaScript, Python, etc.) construído a partir de entrada do usuário sem validação ou sanitização adequada. Um atacante injeta comandos maliciosos que são interpretados e executados no contexto da aplicação, comprometendo dados, sessões ou o servidor.
Example
Um formulário web que avalia expressões matemáticas digitadas pelo usuário com eval() sem filtros. Um atacante entra 'os.system("rm -rf /")' em vez de "2+2", e o servidor executa o comando do sistema.
How to mitigate
Evite usar funções que executem código dinâmico (eval, exec, etc.) com entrada externa. Se inevitável, use sandboxing rigoroso, validação whitelist de entrada, e intérpretes isolados. Prefira APIs seguras que não interprem código arbitrário.
CVE-2022-25967HIGHVersions of the package eta before 2.0.0 are vulnerable to Remote Code Execution (RCE) by overwriting template engine configuration variableEPSS 2.0%CVE-2024-27622HIGHA remote code execution vulnerability has been identified in the User Defined Tags module of CMS Made Simple version 2.2.19 / 2.2.21. This vEPSS 2.0%CVE-2011-10018CRITICALmyBB 1.6.4 Backdoor Arbitrary Command ExecutionEPSS 2.0%CVE-2022-40628CRITICALRemote Code Execution Vulnerability in Tacitine FirewallEPSS 2.0%CVE-2025-3472MEDIUMOcean Extra <= 2.4.6 - Unauthenticated Arbitrary Shortcode ExecutionEPSS 2.0%CVE-2024-5082HIGHNexus Repository 2 - Remote Code ExecutionEPSS 2.0%CVE-2021-29465HIGHRemote file overwrite on discord-recon can result in DoS and Remote Code ExecutionEPSS 2.0%CVE-2023-36437HIGHAzure DevOps Server Remote Code Execution VulnerabilityEPSS 2.0%CVE-2023-34112MEDIUMJavaCPP project actions vulnerable to code injection EPSS 1.9%CVE-2021-24312—WP Super Cache < 1.7.3 - Authenticated Remote Code ExecutionEPSS 1.9%CVE-2023-23477HIGHIBM WebSphere Application Server code executionEPSS 1.9%CVE-2022-3242MEDIUMHTML code Injection in template search keyword in microweber/microweberEPSS 1.9%CVE-2021-32673HIGHRemote Command Execution in reg-keygen-git-hash-pluginEPSS 1.9%CVE-2024-6345HIGHRemote Code Execution in pypa/setuptoolsEPSS 1.9%CVE-2023-5540MEDIUMMoodle: authenticated remote code execution risk in imscpEPSS 1.9%CVE-2026-27876CRITICALRCE on Grafana via sqlExpressionsEPSS 1.9%CVE-2021-39159CRITICALRemote code execution in BinderhubEPSS 1.9%CVE-2025-34074CRITICALLucee Admin Interface Authenticated Remote Code Execution via Scheduled Job File WriteEPSS 1.9%CVE-2021-4434CRITICALSocial Warfare <= 3.5.2 - Remote Code ExecutionEPSS 1.9%CVE-2024-31822CRITICALAn issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitraryEPSS 1.9%