Weaknesses of type CWE-94

4,422 results

Injeção de script

Ocorre quando a aplicação executa código dinâmico (JavaScript, Python, etc.) construído a partir de entrada do usuário sem validação ou sanitização adequada. Um atacante injeta comandos maliciosos que são interpretados e executados no contexto da aplicação, comprometendo dados, sessões ou o servidor.

Example

Um formulário web que avalia expressões matemáticas digitadas pelo usuário com eval() sem filtros. Um atacante entra 'os.system("rm -rf /")' em vez de "2+2", e o servidor executa o comando do sistema.

How to mitigate

Evite usar funções que executem código dinâmico (eval, exec, etc.) com entrada externa. Se inevitável, use sandboxing rigoroso, validação whitelist de entrada, e intérpretes isolados. Prefira APIs seguras que não interprem código arbitrário.

CVE-2023-43651HIGHRemote code execution on the host system via MongoDB shell in jumpserverEPSS 1.7%CVE-2022-43333CRITICALTelenia Software s.r.l TVox before v22.0.17 was discovered to contain a remote code execution (RCE) vulnerability in the component action_exEPSS 1.7%CVE-2022-44038CRITICALRussound XSourcePlayer 777D v06.08.03 was discovered to contain a remote code execution vulnerability via the scriptRunner.cgi component.EPSS 1.7%CVE-2024-31666CRITICALAn issue in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via a crafted script to the edit_addon_post.php component.EPSS 1.7%CVE-2026-58231CRITICALImproper Authorization in SAP Commerce Cloud (Data Hub Adapter)EPSS 1.7%CVE-2022-25812—Transposh WordPress Translation < 1.0.8 - Admin+ RCEEPSS 1.7%CVE-2011-10011CRITICALWeBid 1.0.2 converter.php Remote PHP Code InjectionEPSS 1.7%CVE-2026-33937CRITICALHandlebars.js has JavaScript Injection via AST Type ConfusionEPSS 1.7%CVE-2026-24105CRITICALAn issue was discovered in goform/formsetUsbUnload in Tenda AC15V1.0 V15.03.05.18_multi. The value of `v1` was not checked, potentially leadEPSS 1.7%CVE-2025-8191MEDIUMmacrozheng mall Swagger UI index.html cross site scriptingEPSS 1.7%CVE-2018-25357CRITICALDolibarr ERP CRM 7.0.3 Remote Code Execution via install/step1.phpEPSS 1.7%CVE-2024-23742—An issue in Loom on macOS version 0.196.1 and before, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilEPSS 1.7%CVE-2025-27657CRITICALVasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Remote Code Execution V-2023-008.EPSS 1.7%CVE-2021-39114HIGHAffected versions of Atlassian Confluence Server and Data Center allow users with a valid account on a Confluence Data Center instance to exEPSS 1.7%CVE-2024-38396CRITICALAn issue was discovered in iTerm2 3.5.x before 3.5.2. Unfiltered use of an escape sequence to report a window title, in combination with theEPSS 1.7%CVE-2013-10057HIGHSynactis PDF In-The-Box ConnectToSynactic Stack-Based Buffer OverflowEPSS 1.7%CVE-2020-8180—A too lax check in Nextcloud Talk 6.0.4, 7.0.2 and 8.0.7 allowed a code injection when a not correctly sanitized talk command was added by aEPSS 1.7%CVE-2024-42745CRITICALIn TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setUPnPCfg. AuthEPSS 1.7%CVE-2021-37384CRITICALRCE (Remote Code Execution) vulnerability was found in some Furukawa ONU models, this vulnerability allows remote unauthenticated users to sEPSS 1.7%CVE-2024-54804CRITICALNetgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted request to post.cgi, updaEPSS 1.7%