Weaknesses of type CWE-94
4,447 resultsInjeção de script
Ocorre quando a aplicação executa código dinâmico (JavaScript, Python, etc.) construído a partir de entrada do usuário sem validação ou sanitização adequada. Um atacante injeta comandos maliciosos que são interpretados e executados no contexto da aplicação, comprometendo dados, sessões ou o servidor.
Example
Um formulário web que avalia expressões matemáticas digitadas pelo usuário com eval() sem filtros. Um atacante entra 'os.system("rm -rf /")' em vez de "2+2", e o servidor executa o comando do sistema.
How to mitigate
Evite usar funções que executem código dinâmico (eval, exec, etc.) com entrada externa. Se inevitável, use sandboxing rigoroso, validação whitelist de entrada, e intérpretes isolados. Prefira APIs seguras que não interprem código arbitrário.
CVE-2026-45583HIGHMicrosoft Exchange Server Remote Code Execution VulnerabilityEPSS 0.7%CVE-2025-8417HIGHCatalog Importer, Scraper & Crawler <= 5.1.4 - Unauthenticated PHP Code InjectionEPSS 0.7%CVE-2021-47952CRITICALpython jsonpickle 2.0.0 Remote Code Execution via py/reprEPSS 0.7%CVE-2026-89083CRITICALHP Advance – Potential Elevation of Privilege, Remote Code Execution & Arbitrary File WriteEPSS 0.7%CVE-2026-31379MEDIUMApache OFBiz: Path Traversal and File Upload Validation Bypass Leading to Arbitrary File Write, Stored XSS and RCE in Catalog ManagerEPSS 0.7%CVE-2026-76605CRITICALJoomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.2EPSS 0.7%CVE-2026-76604CRITICALJoomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.2EPSS 0.7%CVE-2026-89082CRITICALHP Advance – Potential Elevation of Privilege, Remote Code Execution & Arbitrary File WriteEPSS 0.7%CVE-2024-30868CRITICALnetentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/add_getlogin.php.EPSS 0.7%CVE-2026-12257CRITICALRemote code execution in Mura Software’s CMSEPSS 0.7%CVE-2026-6902HIGHCode Injection in Perforce P4 (Helix Core)EPSS 0.7%CVE-2024-55505HIGHAn issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the mess-view.php component.EPSS 0.7%CVE-2026-82340CRITICALIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 0.7%CVE-2026-73453CRITICALSecurity Advisory 0174EPSS 0.7%CVE-2026-79574CRITICALAn issue in the gateway server of mpush v0.8.1 allows attackers to execute arbitrary code via sending a crafted broadcast message.EPSS 0.7%CVE-2026-50880CRITICALAn issue in the sendmail transport integration component of YouTransfer v1.0.6 allows attackers to execute arbitrary code via supplying a crEPSS 0.7%CVE-2026-25141CRITICALOrval has a code injection via unsanitized x-enum-descriptions uing JS commentsEPSS 0.7%CVE-2026-30117CRITICALscalar/astro v0.1.13 was discovered to contain an arbitrary file upload vulnerability in the the scalar_url query parameter of the Scalar PrEPSS 0.7%CVE-2026-25879CRITICALLangroid has Prompt to SQL Injection, Leading to RCEEPSS 0.7%CVE-2026-36433CRITICALAn issue in Actions Semiconductor Co. Ltd Tool- Media Player Utilities v.4.46 allows a physically proximate attacker execute arbitrary code EPSS 0.7%