Weaknesses of type CWE-94

4,448 results

Injeção de script

Ocorre quando a aplicação executa código dinâmico (JavaScript, Python, etc.) construído a partir de entrada do usuário sem validação ou sanitização adequada. Um atacante injeta comandos maliciosos que são interpretados e executados no contexto da aplicação, comprometendo dados, sessões ou o servidor.

Example

Um formulário web que avalia expressões matemáticas digitadas pelo usuário com eval() sem filtros. Um atacante entra 'os.system("rm -rf /")' em vez de "2+2", e o servidor executa o comando do sistema.

How to mitigate

Evite usar funções que executem código dinâmico (eval, exec, etc.) com entrada externa. Se inevitável, use sandboxing rigoroso, validação whitelist de entrada, e intérpretes isolados. Prefira APIs seguras que não interprem código arbitrário.

CVE-2026-8478HIGHLangflow OSS is affected by arbitrary code execution in component generation, validation, and custom component handlingEPSS 0.6%CVE-2026-43898CRITICALSandboxJS: Sandbox escape via Function.caller leakage of internal call opEPSS 0.6%CVE-2024-11977HIGHkk Star Ratings – Rate Post & Collect User Feedbacks <= 5.4.10 - Unauthenticated Arbitrary Shortcode ExecutionEPSS 0.6%CVE-2026-12946CRITICALRemote Code Execution in CUGA Component CodeAgentEPSS 0.6%CVE-2024-33442MEDIUMAn issue in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the add_post.php component.EPSS 0.6%CVE-2026-22771HIGHEnvoy Extension Policy lua scripts injection causes arbitrary command executionEPSS 0.6%CVE-2024-21552CRITICALAll versions of `SuperAGI` are vulnerable to Arbitrary Code Execution due to unsafe use of the ‘eval’ function. An attacker could induce theEPSS 0.6%CVE-2024-42393CRITICALUnauthenticated Stack-Based Buffer Overflow Remote Command Execution (RCE) in the Soft AP Daemon Service Accessed by the PAPI ProtocolEPSS 0.6%CVE-2026-35086MEDIUMApache OFBiz: Authenticated Remote Code Execution via Unsafe Template Expansion in email servicesEPSS 0.6%CVE-2024-8478HIGHAffiliate Super Assistent <= 1.5.3 - Unauthenticated Arbitrary Shortcode ExecutionEPSS 0.6%CVE-2024-50804HIGHInsecure Permissions vulnerability in Micro-star International MSI Center Pro 2.1.37.0 allows a local attacker to execute arbitrary code viaEPSS 0.6%CVE-2026-71319CRITICALNuxt.js Unauthenticated WebSocket RPC Call Leading to Remote Code ExecutionEPSS 0.6%CVE-2024-25350CRITICALSQL Injection vulnerability in /zms/admin/edit-ticket.php in PHPGurukul Zoo Management System 1.0 via tickettype and tprice parameters.EPSS 0.6%CVE-2026-8094CRITICALOther issue in the WebRTC componentEPSS 0.6%CVE-2024-0400HIGHSCM Software is a client and server application. An Authenticated System manager client can execute LINQ query in the SCM server, for customEPSS 0.6%CVE-2026-79362HIGHCertain Woltlab products are affected by RCE via Cache Poisoning. WCF >= 6.1.0 until < 6.1.23 and WCF >= 6.2.0 until < 6.2.6. An authenticatEPSS 0.6%CVE-2023-31315HIGHImproper validation in a model specific register (MSR) could allow a malicious program with ring0 access to modify SMM configuration while SEPSS 0.6%CVE-2026-45833CRITICALA code injection vulnerability in version 0.4.17 or later of the ChromaDB Python project allows an authenticated attacker to run arbitrary cEPSS 0.6%CVE-2026-82393HIGHpnpm: A tarball dependency's manifest `name` escapes node_modules → arbitrary file write/overwrite on installEPSS 0.6%CVE-2025-8550MEDIUMatjiu pybbs list cross site scriptingEPSS 0.6%