Weaknesses of type CWE-94
4,448 resultsInjeção de script
Ocorre quando a aplicação executa código dinâmico (JavaScript, Python, etc.) construído a partir de entrada do usuário sem validação ou sanitização adequada. Um atacante injeta comandos maliciosos que são interpretados e executados no contexto da aplicação, comprometendo dados, sessões ou o servidor.
Example
Um formulário web que avalia expressões matemáticas digitadas pelo usuário com eval() sem filtros. Um atacante entra 'os.system("rm -rf /")' em vez de "2+2", e o servidor executa o comando do sistema.
How to mitigate
Evite usar funções que executem código dinâmico (eval, exec, etc.) com entrada externa. Se inevitável, use sandboxing rigoroso, validação whitelist de entrada, e intérpretes isolados. Prefira APIs seguras que não interprem código arbitrário.
CVE-2026-46633HIGHTwig: PHP code injection via `{% use %}` template nameEPSS 0.7%CVE-2025-3563MEDIUMWuzhiCMS Setting index.php set code injectionEPSS 0.7%CVE-2026-53510HIGHSavon::Model evaluates WSDL operation names as Ruby sourceEPSS 0.7%CVE-2023-6126MEDIUMCode Injection in salesagility/suitecrmEPSS 0.7%CVE-2026-100864HIGHheym before 0.0.91 Remote Code Execution via Expression EngineEPSS 0.7%CVE-2026-45311CRITICALCodeWhale: run_tests Tool Enables RCE via Malicious Repository Without ApprovalEPSS 0.7%CVE-2025-10370MEDIUMMiczFlor RPi-Jukebox-RFID userScripts.php cross site scriptingEPSS 0.7%CVE-2025-26003CRITICALTelesquare TLR-2005KSH 1.1.4 is affected by an unauthorized command execution vulnerability when requesting the admin.cgi parameter with setEPSS 0.7%CVE-2023-44392HIGHArbitrary code execution vulnerability when using shared Kubernetes clusterEPSS 0.7%CVE-2024-9132HIGHThe administrator is able to configure an insecure captive portal scriptEPSS 0.7%CVE-2026-33646CRITICALmise: Arbitrary Code Execution via Tera Templates in .tool-versions Files (Trust Bypass)EPSS 0.7%CVE-2025-70073HIGHAn issue in ChestnutCMS v.1.5.8 and before allows a remote attacker to execute arbitrary code via the template creation functionEPSS 0.7%CVE-2023-21569MEDIUMAzure DevOps Server Spoofing VulnerabilityEPSS 0.7%CVE-2010-5153MEDIUMRace condition in Avira Premium Security Suite 10.0.0.536 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute EPSS 0.7%CVE-2024-11699HIGHMemory safety bugs present in Firefox 132, Firefox ESR 128.4, and Thunderbird 128.4. Some of these bugs showed evidence of memory corruptionEPSS 0.7%CVE-2025-6213HIGHNginx Cache Purge Preload <= 2.1.1 - Authenticated (Administrator+) Remote Code ExecutionEPSS 0.7%CVE-2024-8880MEDIUMplaySMS Template index.php code injectionEPSS 0.7%CVE-2024-25096CRITICALWordPress canto plugin <= 3.0.7 - Unauth. Remote Code Execution (RCE) vulnerabilityEPSS 0.7%CVE-2025-13658CRITICALIndustrial Video & Control Longwatch has a Code Injection vulnerabilityEPSS 0.7%CVE-2026-41196CRITICALLuanti has a mod security sandbox escapeEPSS 0.7%