Fallos del tipo CWE-94

4497 resultados

Injeção de script

A aplicação executa código dinâmico (JavaScript, Python, etc.) construído a partir de entrada do usuário sem validação ou sanitização adequada. Um atacante injeta comandos maliciosos que são interpretados e executados pelo servidor ou navegador como se fossem parte legítima do programa.

Ejemplo

Um formulário de contato concatena o nome do usuário diretamente em um script JavaScript enviado ao navegador: `<script>var usuario = '` + entrada_usuario + `';</script>`. Se o usuário envia `'; alert('xss'); //`, o navegador executa o alerta indesejado.

Cómo mitigar

Nunca construa código dinâmico a partir de entrada de usuário. Use APIs seguras (como `JSON.parse()` ao invés de `eval()`, ou templates com escape automático), valide e sanitize rigorosamente todas as entradas, e aplique listas brancas de caracteres permitidos quando possível.

CVE-2025-33236HIGHNVIDIA NeMo Framework contains a vulnerability where malicious data created by an attacker could cause code injection. A successful exploit EPSS 0.2%CVE-2026-28801MEDIUMNatro Macro: Code Injection through Pattern/Path filesEPSS 0.2%CVE-2023-28796HIGHIPC Bypass Through PLT Section in ELFEPSS 0.2%CVE-2026-44728HIGHImproper Control of Generation of Code when compiling specifically crafted malicious code with @babel/plugin-transform-modules-systemjsEPSS 0.2%CVE-2026-100881LOWzhistaredu StarTraining application.yml cross site scriptingEPSS 0.2%CVE-2026-25797MEDIUMImageMagick vulnerable to Code injection via PostScript header in ps codersEPSS 0.2%CVE-2026-10688MEDIUMahujasid blender-mcp server.py execute_blender_code code injectionEPSS 0.2%CVE-2025-63693MEDIUMThe comment editing template (dzz/comment/template/edit_form.htm) in DzzOffice 2.3.x lacks adequate security escaping for user-controllable EPSS 0.2%CVE-2025-24959LOWEnvironment Variable Injection for dotenv API in zxEPSS 0.2%CVE-2024-39289HIGHUnsafe use of eval() method in rosparam toolEPSS 0.2%CVE-2026-42890MEDIUMactual Allows Electron to Run As NodeEPSS 0.2%CVE-2025-12669MEDIUMImproper Control of Generation of Code ('Code Injection') in GitLabEPSS 0.2%CVE-2025-55313HIGHAn issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. They allow potential arbitrary codEPSS 0.2%CVE-2024-39835HIGHUnsafe use of eval() method in roslaunch toolEPSS 0.2%CVE-2024-48829MEDIUMDell SmartFabric OS10 Software, versions prior to 10.6.1.0, contain an Improper Control of Generation of Code ('Code Injection') vulnerabiliEPSS 0.2%CVE-2026-72718HIGHgoose: Arbitrary command execution in goose CLI via `goose review` via git core.fsmonitorEPSS 0.2%CVE-2026-54057HIGHKitty vulnerable to command injection via unsanitized OSC 21 query replyEPSS 0.2%CVE-2026-0414MEDIUMInsufficient Input Validation Allows Unauthorized Modification of Router Software in certain NETGEAR RoutersEPSS 0.2%CVE-2026-45353CRITICALelecterm: Local code through electerm's single-instance socketEPSS 0.2%CVE-2025-0664MEDIUMA locally authenticated, privileged user can craft a malicious OpenSSL configuration file, potentially leading the agent to load an arbitrarEPSS 0.2%