Weaknesses of type CWE-94

4,447 results

Injeção de script

Ocorre quando a aplicação executa código dinâmico (JavaScript, Python, etc.) construído a partir de entrada do usuário sem validação ou sanitização adequada. Um atacante injeta comandos maliciosos que são interpretados e executados no contexto da aplicação, comprometendo dados, sessões ou o servidor.

Example

Um formulário web que avalia expressões matemáticas digitadas pelo usuário com eval() sem filtros. Um atacante entra 'os.system("rm -rf /")' em vez de "2+2", e o servidor executa o comando do sistema.

How to mitigate

Evite usar funções que executem código dinâmico (eval, exec, etc.) com entrada externa. Se inevitável, use sandboxing rigoroso, validação whitelist de entrada, e intérpretes isolados. Prefira APIs seguras que não interprem código arbitrário.

CVE-2026-75031CRITICALIn the interchange/interchange project, a critical remote code execution (RCE) vulnerability was found in the “quick question” admin featurEPSS 0.7%CVE-2024-57609HIGHAn issue in Kanaries Inc Pygwalker before v.0.4.9.9 allows a remote attacker to obtain sensitive information and execute arbitrary code via EPSS 0.7%CVE-2026-54653HIGH`datamodel-code-generator` vulnerable to code injection in via attacker-controlled `default_factory` schema fieldEPSS 0.7%CVE-2026-26699HIGHsourcecodester Personnel Property Equipment System v1.0 is vulnerable to arbitrary code execution in ip/ppes/admin/admin_change_picture.php.EPSS 0.7%CVE-2024-12900MEDIUMFoxCMS Configuration File installdb.php code injectionEPSS 0.7%CVE-2026-14439CRITICALPath Traversal in Altium Git Service Allows Remote Code ExecutionEPSS 0.7%CVE-2026-71320HIGHNuxt: Server-Side Remote Code Execution via Runtime Template Injection in Nuxt Server Island PropsEPSS 0.7%CVE-2021-47964HIGHSchlix CMS 2.2.6-6 Remote Code Execution via core.blockmanagerEPSS 0.7%CVE-2026-22793CRITICAL5ire vulnerable to Remote Code Execution (RCE) via EChartsEPSS 0.7%CVE-2025-37099CRITICALA remote code execution vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646.EPSS 0.7%CVE-2024-24278HIGHAn issue in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker to obtain sensitive information via a crafted pEPSS 0.7%CVE-2026-1829HIGHContent Visibility for Divi Builder <= 4.02 - Authenticated (Contributor+) Remote Code ExecutionEPSS 0.7%CVE-2026-86730HIGHCraft CMS 5.0.0-RC1 before 5.10.12 Behavior Injection RCEEPSS 0.7%CVE-2026-85610HIGHOpenPanel before 2.3.0 Remote Code Execution via chart formulasEPSS 0.7%CVE-2024-8268HIGHFrontend Dashboard <= 2.2.4 - Authenticated (Subscriber+) Arbitrary Function CallEPSS 0.7%CVE-2024-56334HIGHCommand injection vulnerability in getWindowsIEEE8021x (SSID) function in systeminformationEPSS 0.7%CVE-2024-33443HIGHAn issue in onethink v.1.1 allows a remote attacker to execute arbitrary code via a crafted script to the AddonsController.class.php componeEPSS 0.7%CVE-2026-33334MEDIUMVikunja Desktop: Any frontend XSS escalates to Remote Code Execution due to nodeIntegrationEPSS 0.7%CVE-2026-47252CRITICALAnyquery: AppleScript/JXA Code Injection via Unescaped URL in macOS plugins (Brave, Chrome, Edge, Reminders, Safari)EPSS 0.7%CVE-2025-55204HIGHmuffon has One-click Remote Code Execution via XSS and Custom URL HandlingEPSS 0.7%