Fallos del tipo CWE-94

4422 resultados

Injeção de script

A aplicação executa código dinâmico (JavaScript, Python, etc.) construído a partir de entrada do usuário sem validação ou sanitização adequada. Um atacante injeta comandos maliciosos que são interpretados e executados pelo servidor ou navegador como se fossem parte legítima do programa.

Ejemplo

Um formulário de contato concatena o nome do usuário diretamente em um script JavaScript enviado ao navegador: `<script>var usuario = '` + entrada_usuario + `';</script>`. Se o usuário envia `'; alert('xss'); //`, o navegador executa o alerta indesejado.

Cómo mitigar

Nunca construa código dinâmico a partir de entrada de usuário. Use APIs seguras (como `JSON.parse()` ao invés de `eval()`, ou templates com escape automático), valide e sanitize rigorosamente todas as entradas, e aplique listas brancas de caracteres permitidos quando possível.

CVE-2023-45590CRITICALAn improper control of generation of code ('code injection') in Fortinet FortiClientLinux version 7.2.0, 7.0.6 through 7.0.10 and 7.0.3 throEPSS 1.5%CVE-2025-63706CRITICALNPM package next-npm-version1.0.1 is vulnerable to Command injection.EPSS 1.5%CVE-2022-46333HIGHProofpoint Enterprise Protection perl eval() arbitrary command executionEPSS 1.5%CVE-2024-12471HIGHPost Saint: ChatGPT, GPT4, DALL-E, Stable Diffusion, Pexels, Dezgo AI Text & Image Generator <= 1.3.1 - Missing Authorization to Authenticated (Subscriber+) Arbitrary File UploadEPSS 1.5%CVE-2023-24059HIGHGrand Theft Auto V for PC allows attackers to achieve partial remote code execution or modify files on a PC, as exploited in the wild in JanEPSS 1.5%CVE-2023-46980CRITICALAn issue in Best Courier Management System v.1.0 allows a remote attacker to execute arbitrary code and escalate privileges via a crafted scEPSS 1.5%CVE-2024-10954HIGHPrompt Injection Leading to RCE in binary-husky/gpt_academic Plugin `manim`EPSS 1.5%CVE-2024-10950HIGHCode Injection in binary-husky/gpt_academicEPSS 1.5%CVE-2024-21673HIGHThis High severity Remote Code Execution (RCE) vulnerability was introduced in versions 7.13.0 of Confluence Data Center and Server. RemoteEPSS 1.5%CVE-2024-31004HIGHAn issue in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the Ap4StsdAtom.cpp,AP4_StsdAtom::AP4_StsdAtom,mEPSS 1.5%CVE-2025-61937CRITICALAVEVA Process Optimization Code InjectionEPSS 1.5%CVE-2023-26817HIGHcodefever before 2023.2.7-commit-b1c2e7f was discovered to contain a remote code execution (RCE) vulnerability via the component /controllerEPSS 1.5%CVE-2018-0461MEDIUMCisco IP Phone 8800 Series Arbitrary Script Injection VulnerabilityEPSS 1.5%CVE-2021-36800HIGHAkaunting OS Command Injection in 'Money.php'EPSS 1.5%CVE-2024-31003HIGHBuffer Overflow vulnerability in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the AP4_MemoryByteStream::WEPSS 1.5%CVE-2025-11837HIGHMalware RemoverEPSS 1.5%CVE-2023-51066HIGHAn authenticated remote code execution vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows attackers to arbiEPSS 1.5%CVE-2024-38395CRITICALIn iTerm2 before 3.5.2, the "Terminal may report window title" setting is not honored, and thus remote code execution might occur but "is noEPSS 1.5%CVE-2024-25249CRITICALAn issue in He3 App for macOS version 2.0.17, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArEPSS 1.5%CVE-2024-25301HIGHRedaxo v5.15.1 was discovered to contain a remote code execution (RCE) vulnerability via the component /pages/templates.php.EPSS 1.5%