Weaknesses of type CWE-94
4,442 resultsInjeção de script
Ocorre quando a aplicação executa código dinâmico (JavaScript, Python, etc.) construído a partir de entrada do usuário sem validação ou sanitização adequada. Um atacante injeta comandos maliciosos que são interpretados e executados no contexto da aplicação, comprometendo dados, sessões ou o servidor.
Example
Um formulário web que avalia expressões matemáticas digitadas pelo usuário com eval() sem filtros. Um atacante entra 'os.system("rm -rf /")' em vez de "2+2", e o servidor executa o comando do sistema.
How to mitigate
Evite usar funções que executem código dinâmico (eval, exec, etc.) com entrada externa. Se inevitável, use sandboxing rigoroso, validação whitelist de entrada, e intérpretes isolados. Prefira APIs seguras que não interprem código arbitrário.
CVE-2023-47397CRITICALWeBid <=1.2.2 is vulnerable to code injection via admin/categoriestrans.php.EPSS 1.0%CVE-2026-25510CRITICALCI4MS Vulnerable to Remote Code Execution (RCE) via Arbitrary File Creation and Save in File EditorEPSS 1.0%CVE-2025-44071CRITICALSeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component phomebak.php. This vulnerability allowsEPSS 1.0%CVE-2024-8523MEDIUMlmxcms SQL Command Execution Module admin.php formatData code injectionEPSS 1.0%CVE-2024-3098CRITICALPrompt Injection leading to Arbitrary Code Execution in run-llama/llama_indexEPSS 1.0%CVE-2025-2127MEDIUMJoomlaUX JUX Real Estate realties cross site scriptingEPSS 1.0%CVE-2023-5500HIGHFrauscher: FDS102 for FAdC/FAdCi remote code execution vulnerabilityEPSS 1.0%CVE-2023-31415CRITICALKibana version 8.7.0 contains an arbitrary code execution flaw. An attacker with All privileges to the Uptime/Synthetics feature could send EPSS 1.0%CVE-2024-48453CRITICALAn issue in INOVANCE AM401_CPU1608TPTN allows a remote attacker to execute arbitrary code via the ExecuteUserProgramUpgrade functionEPSS 1.0%CVE-2026-44377CRITICALCubeCart: Server-Side Template Injection (SSTI) in Smarty Templates leading to RCEEPSS 1.0%CVE-2023-30638HIGHAtos Unify OpenScape SBC 10 before 10R3.1.3, OpenScape Branch 10 before 10R3.1.2, and OpenScape BCF 10 before 10R10.7.0 allow remote authentEPSS 1.0%CVE-2024-51243HIGHThe eladmin v2.7 and before contains a remote code execution (RCE) vulnerability that can control all application deployment servers of thisEPSS 1.0%CVE-2023-36702HIGHMicrosoft DirectMusic Remote Code Execution VulnerabilityEPSS 1.0%CVE-2026-15011CRITICALCustomer Support Ticket System & Helpdesk <= 6.0.5 - Unauthenticated Code Injection via 'path' ParameterEPSS 1.0%CVE-2024-34461CRITICALZenario before 9.5.60437 uses Twig filters insecurely in the Twig Snippet plugin, and in the site-wide HEAD and BODY elements, enabling codeEPSS 1.0%CVE-2024-6891HIGHJournyx Authenticated Remote Code ExecutionEPSS 1.0%CVE-2024-39209MEDIUMluci-app-sms-tool v1.9-6 was discovered to contain a command injection vulnerability via the score parameter.EPSS 1.0%CVE-2024-45623CRITICALD-Link DAP-2310 Hardware A Firmware 1.16RC028 allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the ATPEPSS 0.9%CVE-2024-41361CRITICALRPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\manageFilesFolders.phpEPSS 0.9%CVE-2025-5309HIGHRemote Support & Privileged Remote Access server side template injectionEPSS 0.9%