Weaknesses of type CWE-94

4,423 results

Injeção de script

Ocorre quando a aplicação executa código dinâmico (JavaScript, Python, etc.) construído a partir de entrada do usuário sem validação ou sanitização adequada. Um atacante injeta comandos maliciosos que são interpretados e executados no contexto da aplicação, comprometendo dados, sessões ou o servidor.

Example

Um formulário web que avalia expressões matemáticas digitadas pelo usuário com eval() sem filtros. Um atacante entra 'os.system("rm -rf /")' em vez de "2+2", e o servidor executa o comando do sistema.

How to mitigate

Evite usar funções que executem código dinâmico (eval, exec, etc.) com entrada externa. Se inevitável, use sandboxing rigoroso, validação whitelist de entrada, e intérpretes isolados. Prefira APIs seguras que não interprem código arbitrário.

CVE-2026-85978CRITICALUnauthenticated Remote Code Execution in Akana API PlatformEPSS 1.4%CVE-2024-42599HIGHSeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_files.php imposes restrictioEPSS 1.4%CVE-2022-48093HIGHSeacms v12.7 was discovered to contain a remote code execution (RCE) vulnerability via the ip parameter at admin_ ip.php.EPSS 1.4%CVE-2026-6875CRITICALSandbox Escape in ServiceNow AI PlatformEPSS 1.4%CVE-2026-83627CRITICALHummingbird – Speed Optimization, Caching, Minify, Compress & CDN <= 3.21.0 - Unauthenticated Remote Code Execution via Cookie Name in Page Cache Debug LogEPSS 1.4%CVE-2024-33871HIGHAn issue was discovered in Artifex Ghostscript before 10.03.1. contrib/opvp/gdevopvp.c allows arbitrary code execution via a custom Driver lEPSS 1.4%CVE-2026-88062CRITICALOmniRoute ACP Custom-Agent Remote Code Execution (RCE)EPSS 1.4%CVE-2023-5201CRITICALOpenHook <= 4.3.0 - Authenticated (Subscriber+) Remote Code Execution via ShortcodeEPSS 1.4%CVE-2024-25502CRITICALDirectory Traversal vulnerability in flusity CMS v.2.4 allows a remote attacker to execute arbitrary code and obtain sensitive information vEPSS 1.4%CVE-2023-30130HIGHAn issue found in CraftCMS v.3.8.1 allows a remote attacker to execute arbitrary code via a crafted script to the Section parameter.EPSS 1.4%CVE-2024-23208HIGHThe issue was addressed with improved memory handling. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, watchOEPSS 1.4%CVE-2026-59866CRITICALKiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceNameEPSS 1.4%CVE-2023-47840CRITICALWordPress Qode Essential Addons Plugin <= 1.5.2 is vulnerable to Remote Code Execution (RCE)EPSS 1.4%CVE-2023-21553HIGHAzure DevOps Server Remote Code Execution VulnerabilityEPSS 1.4%CVE-2023-24114CRITICALtypecho 1.1/17.10.30 was discovered to contain a remote code execution (RCE) vulnerability via install.php.EPSS 1.4%CVE-2023-24776—Funadmin v3.2.0 was discovered to contain a remote code execution (RCE) vulnerability via the component \controller\Addon.php.EPSS 1.4%CVE-2022-44702HIGHWindows Terminal Remote Code Execution VulnerabilityEPSS 1.4%CVE-2024-45200MEDIUMIn Nintendo Mario Kart 8 Deluxe before 3.0.3, the LAN/LDN local multiplayer implementation allows a remote attacker to exploit a stack-basedEPSS 1.4%CVE-2024-22514HIGHAn issue discovered in iSpyConnect.com Agent DVR 5.1.6.0 allows attackers to run arbitrary files by restoring a crafted backup file.EPSS 1.4%CVE-2021-22646HIGHOvarro TBox Code InjectionEPSS 1.4%