Weaknesses of type CWE-94

4,424 results

Injeção de script

Ocorre quando a aplicação executa código dinâmico (JavaScript, Python, etc.) construído a partir de entrada do usuário sem validação ou sanitização adequada. Um atacante injeta comandos maliciosos que são interpretados e executados no contexto da aplicação, comprometendo dados, sessões ou o servidor.

Example

Um formulário web que avalia expressões matemáticas digitadas pelo usuário com eval() sem filtros. Um atacante entra 'os.system("rm -rf /")' em vez de "2+2", e o servidor executa o comando do sistema.

How to mitigate

Evite usar funções que executem código dinâmico (eval, exec, etc.) com entrada externa. Se inevitável, use sandboxing rigoroso, validação whitelist de entrada, e intérpretes isolados. Prefira APIs seguras que não interprem código arbitrário.

CVE-2016-10548—Arbitrary code execution is possible in reduce-css-calc node module <=1.2.4 through crafted css. This makes cross sites scripting (XSS) possEPSS 1.2%CVE-2024-6365CRITICALProduct Table by WBW <= 2.0.1 - Unauthenticated Remote Code ExecutionEPSS 1.2%CVE-2021-27438—The software contains a hard-coded password it uses for its own inbound authentication or for outbound communication to external components EPSS 1.2%CVE-2023-1306HIGHRapid7 InsightCloudSec resource.db() method accessEPSS 1.2%CVE-2023-24107CRITICALhour_of_code_python_2015 commit 520929797b9ca43bb818b2e8f963fb2025459fa3 was discovered to contain a code execution backdoor via the requestEPSS 1.2%CVE-2022-41061HIGHMicrosoft Word Remote Code Execution VulnerabilityEPSS 1.2%CVE-2021-31635—Server-Side Template Injection (SSTI) vulnerability in jFinal v.4.9.08 allows a remote attacker to execute arbitrary code via the template fEPSS 1.2%CVE-2023-21886HIGHVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are PrioEPSS 1.2%CVE-2023-36022MEDIUMMicrosoft Edge (Chromium-based) Remote Code Execution VulnerabilityEPSS 1.2%CVE-2023-4291CRITICALFrauscher FDS101 for FAdC/FAdCi remote code execution vulnerabilityEPSS 1.2%CVE-2024-47219CRITICALAn issue was discovered in vesoft NebulaGraph through 3.8.0. It allows shell command injection.EPSS 1.2%CVE-2026-31220CRITICALPySyft (Syft Datasite/Server) versions 0.9.5 and earlier are vulnerable to remote code execution due to insufficient validation and sandboxiEPSS 1.2%CVE-2026-30618CRITICALxszyou Fay 4.3.1 contains a remote code execution vulnerability in its MCP STDIO server management and command execution handling. A remote EPSS 1.2%CVE-2026-92937CRITICALvm2 3.11.6 Remote Code Execution via Promise call/applyEPSS 1.2%CVE-2026-26720CRITICALAn issue in Twenty CRM v1.15.0 and before allows a remote attacker to execute arbitrary code via the local.driver.ts module.EPSS 1.2%CVE-2022-43542HIGHVulnerabilities in the Aruba EdgeConnect Enterprise command line interface allow remote authenticated users to run arbitrary commands on theEPSS 1.2%CVE-2024-41997MEDIUMAn issue was discovered in version of Warp Terminal prior to 2024.07.18 (v0.2024.07.16.08.02). A command injection vulnerability exists in tEPSS 1.2%CVE-2026-24780HIGHAutoGPT is Vulnerable to RCE via Disabled Block ExecutionEPSS 1.2%CVE-2025-44022CRITICALAn issue in vvveb CMS v.1.0.6 allows a remote attacker to execute arbitrary code via the Plugin mechanism.EPSS 1.2%CVE-2026-16144HIGHKali Forms <= 2.4.20 - Unauthenticated Remote Code Execution via 'thisPermalink' Field ParameterEPSS 1.2%