Fallos del tipo CWE-94

4456 resultados

Injeção de script

A aplicação executa código dinâmico (JavaScript, Python, etc.) construído a partir de entrada do usuário sem validação ou sanitização adequada. Um atacante injeta comandos maliciosos que são interpretados e executados pelo servidor ou navegador como se fossem parte legítima do programa.

Ejemplo

Um formulário de contato concatena o nome do usuário diretamente em um script JavaScript enviado ao navegador: `<script>var usuario = '` + entrada_usuario + `';</script>`. Se o usuário envia `'; alert('xss'); //`, o navegador executa o alerta indesejado.

Cómo mitigar

Nunca construa código dinâmico a partir de entrada de usuário. Use APIs seguras (como `JSON.parse()` ao invés de `eval()`, ou templates com escape automático), valide e sanitize rigorosamente todas as entradas, e aplique listas brancas de caracteres permitidos quando possível.

CVE-2026-45714CRITICALCubeCart: Server-Side Template Injection (SSTI) in Smarty Templates leading to RCEEPSS 0.5%CVE-2022-29216HIGHCode injection in `saved_model_cli` in TensorFlowEPSS 0.5%CVE-2026-32573CRITICALWordPress Nelio AB Testing plugin <= 8.2.7 - Remote Code Execution (RCE) vulnerabilityEPSS 0.5%CVE-2026-71232HIGHMacCMS10 - Incomplete Function Blacklist in Template Editor Enables Authenticated RCEEPSS 0.5%CVE-2026-32414HIGHWordPress Advanced Woo Labels plugin <= 2.36 - Remote Code Execution (RCE) vulnerabilityEPSS 0.5%CVE-2026-50187HIGHOh My Zsh: Arbitrary Code Execution in oh-my-zsh dotenv plugin via malicious .env filesEPSS 0.5%CVE-2025-1155MEDIUMWebkul QloApps Your Location Search stores cross site scriptingEPSS 0.5%CVE-2022-45177HIGHAn issue was discovered in LIVEBOX Collaboration vDesk through v031. An Observable Response Discrepancy can occur under the /api/v1/vdeskintEPSS 0.5%CVE-2026-30479CRITICALA Dynamic-link Library Injection vulnerability in OSGeo Project MapServer before v8.0 allows attackers to execute arbitrary code via a craftEPSS 0.5%CVE-2026-13749HIGHSnowflake CLI Arbitrary Code Execution via Snowpark Annotation Processor Template InjectionEPSS 0.5%CVE-2026-18874MEDIUMVolsync-addon-controller: volsync-addon-controller: annotation values rendered into yaml via text/template without escaping allows yaml injection into subscriptionEPSS 0.5%CVE-2026-73170HIGHNozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in the Modbus CSV import wEPSS 0.5%CVE-2025-1465LOWlmxcms Maintenance db.inc.php code injectionEPSS 0.5%CVE-2026-15538MEDIUMprimefaces primereact API ObjectUtils.js ObjectUtils.mutateFieldData prototype pollutionEPSS 0.5%CVE-2024-12983MEDIUMcode-projects Hospital Management System Edit Doctor Details Page manage-doctors.php cross site scriptingEPSS 0.5%CVE-2025-67164CRITICALAn authenticated arbitrary file upload vulnerability in the /storage/poc.php component of Pagekit CMS v1.0.18 allows attackers to execute arEPSS 0.5%CVE-2025-1337MEDIUMEastnets PaymentSafe BIC Search cross site scriptingEPSS 0.5%CVE-2026-94572CRITICALIn OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and pool tls_ciphers field for control charactEPSS 0.5%CVE-2026-94571CRITICALIn OpenStack Octavia before 18.0.1, the Amphora provider driver did not reject control characters in the L7 policy redirect_url and redirectEPSS 0.5%CVE-2026-40877HIGHCombodo iTop: PHP Object Injection Leading to Remote Code Execution on user preferencesEPSS 0.5%