Fallos del tipo CWE-94

4461 resultados

Injeção de script

A aplicação executa código dinâmico (JavaScript, Python, etc.) construído a partir de entrada do usuário sem validação ou sanitização adequada. Um atacante injeta comandos maliciosos que são interpretados e executados pelo servidor ou navegador como se fossem parte legítima do programa.

Ejemplo

Um formulário de contato concatena o nome do usuário diretamente em um script JavaScript enviado ao navegador: `<script>var usuario = '` + entrada_usuario + `';</script>`. Se o usuário envia `'; alert('xss'); //`, o navegador executa o alerta indesejado.

Cómo mitigar

Nunca construa código dinâmico a partir de entrada de usuário. Use APIs seguras (como `JSON.parse()` ao invés de `eval()`, ou templates com escape automático), valide e sanitize rigorosamente todas as entradas, e aplique listas brancas de caracteres permitidos quando possível.

CVE-2025-8370MEDIUMPortabilis i-Educar educar_escolaridade_lst.php cross site scriptingEPSS 0.5%CVE-2025-59952HIGHminio-java Client XML Tag is Vulnerable to Value SubstitutionEPSS 0.5%CVE-2025-61732HIGHPotential code smuggling via doc comments in cmd/cgoEPSS 0.5%CVE-2024-36361MEDIUMPug through 3.0.2 allows JavaScript code execution if an application accepts untrusted input for the name option of the compileClient, compiEPSS 0.5%CVE-2023-39956MEDIUMElectron: Out-of-package code execution when launched with arbitrary cwdEPSS 0.5%CVE-2025-8369MEDIUMPortabilis i-Educar educar_avaliacao_desempenho_lst.php cross site scriptingEPSS 0.5%CVE-2025-8368MEDIUMPortabilis i-Educar pesquisa_pessoa_lst.php cross site scriptingEPSS 0.5%CVE-2024-4038MEDIUMBack In Stock Notifier for WooCommerce | WooCommerce Waitlist Pro <= 5.3.1 - Unauthenticated Arbitrary Shortcode ExecutionEPSS 0.5%CVE-2025-0530MEDIUMcode-projects Job Recruitment _feedback_system.php cross site scriptingEPSS 0.5%CVE-2025-8221MEDIUMjerryshensjf JPACookieShop 蛋糕商城JPA版 GoodsCustController.java goodsSearch cross site scriptingEPSS 0.5%CVE-2025-2787HIGHIngress-nginx vulnerability in KNIME Business HubEPSS 0.5%CVE-2022-41882MEDIUMNextcloud Desktop vulnerable to code injection via malicious linkEPSS 0.5%CVE-2025-33183HIGHNVIDIA Isaac-GR00T for all platforms contains a vulnerability in a Python component, where an attacker could cause a code injection issue. AEPSS 0.5%CVE-2026-55415HIGHdatamodel-code-generator vulnerable to code injection via `x-python-import` / `customTypePath` in generated import statementsEPSS 0.5%CVE-2025-29629CRITICALGardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.12.2026 use weak defaEPSS 0.5%CVE-2025-26182MEDIUMAn issue in xxyopen novel plus v.4.4.0 and before allows a remote attacker to execute arbitrary code via the PageController.java fileEPSS 0.5%CVE-2023-31493MEDIUMRCE (Remote Code Execution) exists in ZoneMinder through 1.36.33 as an attacker can create a new .php log file in language folder, while exeEPSS 0.5%CVE-2025-33184HIGHNVIDIA Isaac-GR00T for all platforms contains a vulnerability in a Python component, where an attacker could cause a code injection issue. AEPSS 0.5%CVE-2026-56264CRITICALCrawl4AI - Arbitrary JavaScript Execution via /execute_js EndpointEPSS 0.5%CVE-2026-3302MEDIUMSourceCodester Doctor Appointment System Sign Up register.php cross site scriptingEPSS 0.5%