Weaknesses of type CWE-94
4,442 resultsInjeção de script
Ocorre quando a aplicação executa código dinâmico (JavaScript, Python, etc.) construído a partir de entrada do usuário sem validação ou sanitização adequada. Um atacante injeta comandos maliciosos que são interpretados e executados no contexto da aplicação, comprometendo dados, sessões ou o servidor.
Example
Um formulário web que avalia expressões matemáticas digitadas pelo usuário com eval() sem filtros. Um atacante entra 'os.system("rm -rf /")' em vez de "2+2", e o servidor executa o comando do sistema.
How to mitigate
Evite usar funções que executem código dinâmico (eval, exec, etc.) com entrada externa. Se inevitável, use sandboxing rigoroso, validação whitelist de entrada, e intérpretes isolados. Prefira APIs seguras que não interprem código arbitrário.
CVE-2026-33660CRITICALn8n Has Multiple Remote Code Execution Vulnerabilities in Merge Node AlaSQL SQL ModeEPSS 0.9%CVE-2026-90817CRITICALAn unauthenticated Remote Code Execution vulnerability was found in the survey passthrough routing and Data Import processing logic, in whicEPSS 0.9%CVE-2026-8481CRITICALRemote Code Execution via Code Validation EndpointEPSS 0.9%CVE-2026-73268CRITICALCluster-curator-controller: cluster-curator-controller: spec.install.overridejob allows arbitrary job spec injectionEPSS 0.9%CVE-2023-44382CRITICALOctober CMS safe mode bypass using Twig sandbox escapeEPSS 0.9%CVE-2024-48818CRITICALAn issue in IIT Bombay, Mumbai, India Bodhitree of cs101 version allows a remote attacker to execute arbitrary code.EPSS 0.9%CVE-2023-36645CRITICALSQL injection vulnerability in ITB-GmbH TradePro v9.5, allows remote attackers to run SQL queries via oordershow component in customer functEPSS 0.9%CVE-2023-26782MEDIUMAn issue discovered in mccms 2.6.1 allows remote attackers to cause a denial of service via Backend management interface ->System ConfiguratEPSS 0.9%CVE-2022-38745HIGHApache OpenOffice: Empty entry in Java class pathEPSS 0.9%CVE-2023-0626HIGHDocker Desktop before 4.12.0 is vulnerable to RCE via query parameters in message-box route EPSS 0.9%CVE-2024-39236CRITICALGradio v4.36.1 was discovered to contain a code injection vulnerability via the component /gradio/component_meta.py. This vulnerability is tEPSS 0.9%CVE-2023-0625HIGHDocker Desktop before 4.12.0 is vulnerable to RCE via a crafted extension description or changelogEPSS 0.9%CVE-2026-49832HIGHDSpace: Remote Code Execution (RCE) possible in Velocity Templates used by LDNEPSS 0.9%CVE-2024-22144CRITICALWordPress Anti-Malware Security and Brute-Force Firewall plugin <= 4.21.96 - Unauthenticated Predictable Nonce Brute-Force Leading to RCE vulnerabilityEPSS 0.9%CVE-2026-30120CRITICALremotion-dev remotion v4.0.409 was discovered to contain a remote code execution (RCE) vulnerability.EPSS 0.9%CVE-2015-10009MEDIUMnterchange code_caller_controller.php getContent code injectionEPSS 0.9%CVE-2026-12866CRITICALAll versions of the package expr-eval are vulnerable to Code Execution via the toJSFunction() API. An attacker can execute arbitrary JavaScrEPSS 0.9%CVE-2026-38165CRITICALA Server-Side Template Injection (SSTI) vulnerability in the Velocity template engine configuration of xdocreport v0.9.2 to v2.2.0 allows atEPSS 0.9%CVE-2023-37424HIGHUnauthenticated Remote Code Execution in EdgeConnect SD-WAN Orchestrator Web-Based Management InterfaceEPSS 0.9%CVE-2025-28203HIGHVicture RX1800 EN_V1.0.0_r12_110933 was discovered to contain a command injection vulnerability.EPSS 0.9%