Weaknesses of type CWE-94

4,446 results

Injeção de script

Ocorre quando a aplicação executa código dinâmico (JavaScript, Python, etc.) construído a partir de entrada do usuário sem validação ou sanitização adequada. Um atacante injeta comandos maliciosos que são interpretados e executados no contexto da aplicação, comprometendo dados, sessões ou o servidor.

Example

Um formulário web que avalia expressões matemáticas digitadas pelo usuário com eval() sem filtros. Um atacante entra 'os.system("rm -rf /")' em vez de "2+2", e o servidor executa o comando do sistema.

How to mitigate

Evite usar funções que executem código dinâmico (eval, exec, etc.) com entrada externa. Se inevitável, use sandboxing rigoroso, validação whitelist de entrada, e intérpretes isolados. Prefira APIs seguras que não interprem código arbitrário.

CVE-2024-45874CRITICALA DLL hijacking vulnerability in VegaBird Vooki 5.2.9 allows attackers to execute arbitrary code / maintain persistence via placing a crafteEPSS 0.7%CVE-2026-67960CRITICALAn issue in PbootCMS v.3.2.15 allows an attacker to execute arbitrary code via the MemberController.php, UserController.php, CommentControllEPSS 0.7%CVE-2026-25077HIGHApache CloudStack: Unauthenticated Command Injection in Direct Download TemplatesEPSS 0.7%CVE-2026-93603CRITICALvm2 before 3.12.1 Sandbox Escape RCE via Non-Strict Host FunctionEPSS 0.7%CVE-2024-45873CRITICALA DLL hijacking vulnerability in VegaBird Yaazhini 2.0.2 allows attackers to execute arbitrary code / maintain persistence via placing a craEPSS 0.7%CVE-2026-5584MEDIUMFosowl agenticSeek query Endpoint PyInterpreter.py PyInterpreter.execute code injectionEPSS 0.7%CVE-2026-33654HIGHZero-Click Indirect Prompt Injection and Authentication Bypass via Email PollingEPSS 0.7%CVE-2026-27952HIGHAgenta has Python Sandbox Escape, Leading to Remote Code Execution (RCE)EPSS 0.7%CVE-2022-3245MEDIUM Code Injection in display of tag title on saving tags in microweber/microweberEPSS 0.7%CVE-2025-45479CRITICALInsufficient security mechanisms for created containers in educoder challenges v1.0 allow attackers to execute arbitrary code via injecting EPSS 0.7%CVE-2024-40546HIGHAn arbitrary file upload vulnerability in the component /admin/cmsWebFile/save of PublicCMS v4.0.202302.e allows attackers to execute arbitrEPSS 0.7%CVE-2024-40552HIGHPublicCMS v4.0.202302.e was discovered to contain a remote commande execution (RCE) vulnerability via the cmdarray parameter at /site/ScriptEPSS 0.7%CVE-2024-56072HIGHAn issue was discovered in FastNetMon Community Edition through 1.2.7. The sFlow v5 plugin allows remote attackers to cause a denial of servEPSS 0.7%CVE-2026-9072HIGHWebSphere Application Server Remote Code ExecutionEPSS 0.7%CVE-2024-32491CRITICALAn issue was discovered in Znuny and Znuny LTS 6.0.31 through 6.5.7 and Znuny 7.0.1 through 7.0.16 where a logged-in user can upload a file EPSS 0.7%CVE-2026-77413CRITICALJSONata: Arbitrary Code Execution via crafted JSONata expressionsEPSS 0.7%CVE-2026-18667CRITICALSensor Proxy Version 1.4.2 Fixes One VulnerabilityEPSS 0.7%CVE-2024-48070CRITICALAn issue in Weaver E-cology v. attackers construct special requests to insert remote malicious code and to trigger malicious code execution,EPSS 0.7%CVE-2025-30057CRITICALAuthenticated RCE with uhcapache privileges in ConvertToPDFEPSS 0.7%CVE-2022-3713HIGHA code injection vulnerability allows adjacent attackers to execute code in the Wifi controller of Sophos Firewall releases older than versiEPSS 0.7%