Fallos del tipo CWE-94

4497 resultados

Injeção de script

A aplicação executa código dinâmico (JavaScript, Python, etc.) construído a partir de entrada do usuário sem validação ou sanitização adequada. Um atacante injeta comandos maliciosos que são interpretados e executados pelo servidor ou navegador como se fossem parte legítima do programa.

Ejemplo

Um formulário de contato concatena o nome do usuário diretamente em um script JavaScript enviado ao navegador: `<script>var usuario = '` + entrada_usuario + `';</script>`. Se o usuário envia `'; alert('xss'); //`, o navegador executa o alerta indesejado.

Cómo mitigar

Nunca construa código dinâmico a partir de entrada de usuário. Use APIs seguras (como `JSON.parse()` ao invés de `eval()`, ou templates com escape automático), valide e sanitize rigorosamente todas as entradas, e aplique listas brancas de caracteres permitidos quando possível.

CVE-2023-53940HIGHCodigo Markdown Editor 1.0.1 Electron Arbitrary Code Execution via Markdown FileEPSS 0.2%CVE-2025-27998HIGHAn issue in Valvesoftware Steam Client Steam Client 1738026274 allows attackers to escalate privileges via a crafted executable or DLL.EPSS 0.2%CVE-2022-37396MEDIUMIn JetBrains Rider before 2022.2 Trust and Open Project dialog could be bypassed, leading to local code executionEPSS 0.2%CVE-2026-73073HIGHVim: Arbitrary Ex Command Execution in C Omni-CompletionEPSS 0.2%CVE-2024-51330MEDIUMAn issue in UltiMaker Cura v.4.41 and 5.8.1 and before allows a local attacker to execute arbitrary code via Inter-process communication (IPEPSS 0.2%CVE-2026-78367HIGHRpm: rpmbuild gettarspec() crafted tar member name → macro injectionEPSS 0.2%CVE-2026-73248HIGHcalibre: Bypass of Python template restrictions via nested `template()` leading to RCEEPSS 0.2%CVE-2026-101861LOWLangflow Code Execution via eval() in Component Input SchemaEPSS 0.2%CVE-2026-42049HIGHjadx: RCE Via Groovy Code Injection in Gradle ExportEPSS 0.2%CVE-2026-19060MEDIUMFoundationAgents MetaGPT code injectionEPSS 0.2%CVE-2026-7580MEDIUMExiftool JPEG/QuickTime/MOV/MP4 GM.pm Process_mrld code injectionEPSS 0.2%CVE-2026-30960CRITICALRSSN has Arbitrary Code Execution via Unvalidated JIT Instruction Generation in C-FFI InterfaceEPSS 0.2%CVE-2026-8021MEDIUMScript injection in UI in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who convinced a user to engage in specific UI gestuEPSS 0.2%CVE-2026-19058MEDIUMFoundationAgents MetaGPT data_interpreter.py DataInterpreter code injectionEPSS 0.2%CVE-2026-34725HIGHdbgate-web: Stored XSS in applicationIcon leads to potential RCE in Electron due to unsafe renderer configurationEPSS 0.2%CVE-2026-34223HIGHA vulnerability has been identified in Desigo CC ClickOnce Client V6 (All versions), Desigo CC ClickOnce Client V7 (All versions), Desigo CCEPSS 0.2%CVE-2025-3753HIGHUnsafe use of eval() method in rosbag toolEPSS 0.2%CVE-2026-42851HIGH@kitty-edit DCS + --color=geninclude vulnerable to Unauthenticated in-process RCEEPSS 0.2%CVE-2025-67750HIGHLightning Flow Scanner is Vulnerable to Code Injection via Unsafe Use of new Function() in APIVersion RuleEPSS 0.2%CVE-2026-24155HIGHNVIDIA NeMo Framework for all platforms contains a code injection vulnerability. A successful exploit of this vulnerability might lead to coEPSS 0.2%