Fallos del tipo CWE-94

4460 resultados

Injeção de script

A aplicação executa código dinâmico (JavaScript, Python, etc.) construído a partir de entrada do usuário sem validação ou sanitização adequada. Um atacante injeta comandos maliciosos que são interpretados e executados pelo servidor ou navegador como se fossem parte legítima do programa.

Ejemplo

Um formulário de contato concatena o nome do usuário diretamente em um script JavaScript enviado ao navegador: `<script>var usuario = '` + entrada_usuario + `';</script>`. Se o usuário envia `'; alert('xss'); //`, o navegador executa o alerta indesejado.

Cómo mitigar

Nunca construa código dinâmico a partir de entrada de usuário. Use APIs seguras (como `JSON.parse()` ao invés de `eval()`, ou templates com escape automático), valide e sanitize rigorosamente todas as entradas, e aplique listas brancas de caracteres permitidos quando possível.

CVE-2026-61536HIGHBanks: Unsafe importlib.import_module of attacker-controlled Tool.import_path in CompletionExtension allows RCEEPSS 0.5%CVE-2024-7093CRITICALServer-Side Template Injection in Dispatch Message TemplatesEPSS 0.5%CVE-2025-65099HIGHClaude Code vulnerable to command execution prior to startup trust dialogEPSS 0.5%CVE-2024-37124CRITICALUse of potentially dangerous function issue exists in Ricoh Streamline NX PC Client. If this vulnerability is exploited, an attacker may creEPSS 0.5%CVE-2024-35226HIGHPHP Code Injection by malicious attribute in extends-tag in SmartyEPSS 0.5%CVE-2024-12980MEDIUMcode-projects Job Recruitment _all_edits.php fln_update cross site scriptingEPSS 0.5%CVE-2024-12979MEDIUMcode-projects Job Recruitment _all_edits.php cn_update cross site scriptingEPSS 0.5%CVE-2025-0844MEDIUMneedyamin Library Card System Registration Page signup.php cross site scriptingEPSS 0.5%CVE-2024-46076CRITICALRuoYi v4.7.9 and before has a security flaw that allows escaping from comments within the code generation feature, enabling the injection ofEPSS 0.5%CVE-2026-82666MEDIUMyaojingang GEOFlow Superadmin Theme Editor SiteThemeEditorController.php preview code injectionEPSS 0.5%CVE-2026-62674CRITICALOmnigent: Shared Agent Bundle Overwrite Leads to Authenticated Runner RCEEPSS 0.5%CVE-2025-11344MEDIUMILIAS Certificate Import code injectionEPSS 0.5%CVE-2025-24677CRITICALWordPress Post/Page Copying Tool to Export and Import post/page for Cross site Migration Plugin <= 2.0.3 - Remote Code Execution (RCE) vulnerabilityEPSS 0.5%CVE-2024-44722CRITICALSysAK v2.0 and before is vulnerable to command execution via aaa;cat /etc/passwd.EPSS 0.5%CVE-2026-76635HIGHbaserCMS < 5.3.0 SQL Injection and Code Injection via BcDatabaseService.phpEPSS 0.5%CVE-2024-11733HIGHWordPress Popular Posts <= 7.1.0 - Unauthenticated Arbitrary Shortcode ExecutionEPSS 0.5%CVE-2026-58025MEDIUMRemote Code Execution via Unsafe Deserialization in LogItem ImportEPSS 0.5%CVE-2025-56588HIGHDolibarr ERP & CRM v21.0.1 were discovered to contain a remote code execution (RCE) vulnerability in the User module configuration via the cEPSS 0.5%CVE-2025-9334HIGHBetter Find and Replace <= 1.7.7 - Authenticated (Subscriber+) Limited Code InjectionEPSS 0.5%CVE-2025-63665CRITICALAn issue in GT Edge AI Community Edition Versions before v2.0.12 allows attackers to execute arbitrary code via injecting a crafted JSON payEPSS 0.5%