Weaknesses of type CWE-94
4,424 resultsInjeção de script
Ocorre quando a aplicação executa código dinâmico (JavaScript, Python, etc.) construído a partir de entrada do usuário sem validação ou sanitização adequada. Um atacante injeta comandos maliciosos que são interpretados e executados no contexto da aplicação, comprometendo dados, sessões ou o servidor.
Example
Um formulário web que avalia expressões matemáticas digitadas pelo usuário com eval() sem filtros. Um atacante entra 'os.system("rm -rf /")' em vez de "2+2", e o servidor executa o comando do sistema.
How to mitigate
Evite usar funções que executem código dinâmico (eval, exec, etc.) com entrada externa. Se inevitável, use sandboxing rigoroso, validação whitelist de entrada, e intérpretes isolados. Prefira APIs seguras que não interprem código arbitrário.
CVE-2024-58284HIGHPopojiCMS 2.0.1 Remote Command Execution via Authenticated Metadata SettingsEPSS 1.1%CVE-2026-66148MEDIUMAn authenticated command injection vulnerability was identified in GMS Command-Line Interface (CLI) 9.5.1 (Build 9510.1044) and earlier versEPSS 1.1%CVE-2026-50223HIGHApache OFBiz: DataResource Low-Privileged Authenticated FreeMarker Template Injection Leads to Remote Code ExecutionEPSS 1.1%CVE-2024-37779HIGHWoodWing Elvis DAM v6.98.1 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the Apache Ant scriptEPSS 1.1%CVE-2022-24817CRITICALImproper kubeconfig validation allows arbitrary code executionEPSS 1.1%CVE-2022-45553—An issue discovered in Shenzhen Zhibotong Electronics WBT WE1626 Router v 21.06.18 allows attacker to execute arbitrary commands via serial EPSS 1.1%CVE-2025-0185HIGHPandas Query Injection in langgenius/difyEPSS 1.1%CVE-2024-6923MEDIUMEmail header injection due to unquoted newlinesEPSS 1.1%CVE-2024-30202HIGHIn Emacs before 29.3, arbitrary Lisp code is evaluated as part of turning on Org mode. This affects Org Mode before 9.6.23.EPSS 1.1%CVE-2017-20064MEDIUMElefant CMS layout code injectionEPSS 1.1%CVE-2025-1087CRITICALArbitrary Code Execution in Kong Insomnia Desktop ApplicationEPSS 1.1%CVE-2024-24525CRITICALAn issue in EpointWebBuilder 5.1.0-sp1, 5.2.1-sp1, 5.4.1 and 5.4.2 allows a remote attacker to execute arbitrary code via the infoid parametEPSS 1.1%CVE-2025-46191CRITICALArbitrary File Upload in user_payment_update.php in SourceCodester Client Database Management System 1.0 allows unauthenticated users to uplEPSS 1.1%CVE-2024-39700CRITICALRemote Code Execution (RCE) vulnerability in jupyterlab extension template `update-integration-tests` GitHub ActionEPSS 1.1%CVE-2023-45144CRITICALRemote code execution from login screen through unescaped URL parameter in OAuth Identity XWiki AppEPSS 1.1%CVE-2024-48581CRITICALFile Upload vulnerability in Best courier management system in php v.1.0 allows a remote attacker to execute arbitrary code via the admin_clEPSS 1.1%CVE-2023-47003CRITICALAn issue in RedisGraph v.2.12.10 allows an attacker to execute arbitrary code and cause a denial of service via a crafted string in DataBlocEPSS 1.1%CVE-2026-27497CRITICALn8n has Potential Remote Code Execution via Merge NodeEPSS 1.1%CVE-2026-53451CRITICALGround Station: Unauthenticated arbitrary file write (path traversal) in save-waterfall-snapshot leads to remote code executionEPSS 1.1%CVE-2026-52103CRITICALA zero-click remote code execution (RCE) vulnerability in the /Terminal/Notification.hs component of SimpleX Chat before v6.5 allows attackeEPSS 1.1%