Weaknesses of type CWE-94

4,446 results

Injeção de script

Ocorre quando a aplicação executa código dinâmico (JavaScript, Python, etc.) construído a partir de entrada do usuário sem validação ou sanitização adequada. Um atacante injeta comandos maliciosos que são interpretados e executados no contexto da aplicação, comprometendo dados, sessões ou o servidor.

Example

Um formulário web que avalia expressões matemáticas digitadas pelo usuário com eval() sem filtros. Um atacante entra 'os.system("rm -rf /")' em vez de "2+2", e o servidor executa o comando do sistema.

How to mitigate

Evite usar funções que executem código dinâmico (eval, exec, etc.) com entrada externa. Se inevitável, use sandboxing rigoroso, validação whitelist de entrada, e intérpretes isolados. Prefira APIs seguras que não interprem código arbitrário.

CVE-2024-57061CRITICALAn issue in Termius Version 9.9.0 through v.9.16.0 allows a physically proximate attacker to execute arbitrary code via the insecure ElectroEPSS 0.7%CVE-2024-37743CRITICALAn issue in mmzdev KnowledgeGPT V.0.0.5 allows a remote attacker to execute arbitrary code via the Document Display Component.EPSS 0.7%CVE-2026-79310HIGHwebpy web.py 0.76 is vulnerable to server-side template injection (SSTI). The template engine can be tricked into executing attacker-controlEPSS 0.7%CVE-2023-39157CRITICALWordPress JetElements For Elementor Plugin <= 2.6.10 is vulnerable to Remote Code Execution (RCE)EPSS 0.7%CVE-2024-13645CRITICALTagDiv Composer <= 5.3 - Unauthenticated Arbitrary PHP Object InstantiationEPSS 0.7%CVE-2026-69255CRITICALFlowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell VerifiedEPSS 0.7%CVE-2026-46586HIGHApache OFBiz: Improper Validation in traverseContent Service Enables Authenticated Groovy Code ExecutionEPSS 0.7%CVE-2024-13487HIGHCURCY – Multi Currency for WooCommerce <= 2.2.5 - Unauthenticated Arbitrary Shortcode Execution via get_products_price FunctionEPSS 0.7%CVE-2025-66916CRITICALThe snailjob component in RuoYi-Vue-Plus versions 5.5.1 and earlier, interface /snail-job/workflow/check-node-expression can execute QLExpreEPSS 0.7%CVE-2024-24230HIGHKomm.One CMS 10.4.2.14 has a Server-Side Template Injection (SSTI) vulnerability via the Velocity template engine. It allows remote attackerEPSS 0.7%CVE-2026-78654MEDIUMcleverbrush framework/deep deepExtend.ts deepExtend prototype pollutionEPSS 0.7%CVE-2025-65716HIGHAn issue in Visual Studio Code Extensions Markdown Preview Enhanced v0.8.18 allows attackers to execute arbitrary code via uploading a craftEPSS 0.7%CVE-2026-5971MEDIUMFoundationAgents MetaGPT XML action_node.py ActionNode.xml_fill eval injectionEPSS 0.7%CVE-2026-5970MEDIUMFoundationAgents MetaGPT HumanEvalBenchmark/MBPPBenchmark check_solution code injectionEPSS 0.7%CVE-2026-6110MEDIUMFoundationAgents MetaGPT Tree-of-Thought Solver tot.py generate_thoughts code injectionEPSS 0.7%CVE-2024-28424HIGHzenml v0.55.4 was discovered to contain an arbitrary file upload vulnerability in the load function at /materializers/cloudpickle_materializEPSS 0.7%CVE-2024-10505MEDIUMwuzhicms block.php edit code injectionEPSS 0.7%CVE-2025-23051HIGHAuthenticated Remote Code Execution in AOS Web-based Management InterfaceEPSS 0.7%CVE-2024-7899MEDIUMInnoCMS Backend edit code injectionEPSS 0.7%CVE-2026-6543HIGHAuthenticated Remote Code Execution Vulnerability in Langflow Code Validation EndpointEPSS 0.7%