Fallos del tipo CWE-94

4442 resultados

Injeção de script

A aplicação executa código dinâmico (JavaScript, Python, etc.) construído a partir de entrada do usuário sem validação ou sanitização adequada. Um atacante injeta comandos maliciosos que são interpretados e executados pelo servidor ou navegador como se fossem parte legítima do programa.

Ejemplo

Um formulário de contato concatena o nome do usuário diretamente em um script JavaScript enviado ao navegador: `<script>var usuario = '` + entrada_usuario + `';</script>`. Se o usuário envia `'; alert('xss'); //`, o navegador executa o alerta indesejado.

Cómo mitigar

Nunca construa código dinâmico a partir de entrada de usuário. Use APIs seguras (como `JSON.parse()` ao invés de `eval()`, ou templates com escape automático), valide e sanitize rigorosamente todas as entradas, e aplique listas brancas de caracteres permitidos quando possível.

CVE-2023-47397CRITICALWeBid <=1.2.2 is vulnerable to code injection via admin/categoriestrans.php.EPSS 1.0%CVE-2026-25510CRITICALCI4MS Vulnerable to Remote Code Execution (RCE) via Arbitrary File Creation and Save in File EditorEPSS 1.0%CVE-2025-44071CRITICALSeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component phomebak.php. This vulnerability allowsEPSS 1.0%CVE-2024-8523MEDIUMlmxcms SQL Command Execution Module admin.php formatData code injectionEPSS 1.0%CVE-2024-3098CRITICALPrompt Injection leading to Arbitrary Code Execution in run-llama/llama_indexEPSS 1.0%CVE-2025-2127MEDIUMJoomlaUX JUX Real Estate realties cross site scriptingEPSS 1.0%CVE-2023-5500HIGHFrauscher: FDS102 for FAdC/FAdCi remote code execution vulnerabilityEPSS 1.0%CVE-2023-31415CRITICALKibana version 8.7.0 contains an arbitrary code execution flaw. An attacker with All privileges to the Uptime/Synthetics feature could send EPSS 1.0%CVE-2024-48453CRITICALAn issue in INOVANCE AM401_CPU1608TPTN allows a remote attacker to execute arbitrary code via the ExecuteUserProgramUpgrade functionEPSS 1.0%CVE-2026-44377CRITICALCubeCart: Server-Side Template Injection (SSTI) in Smarty Templates leading to RCEEPSS 1.0%CVE-2023-30638HIGHAtos Unify OpenScape SBC 10 before 10R3.1.3, OpenScape Branch 10 before 10R3.1.2, and OpenScape BCF 10 before 10R10.7.0 allow remote authentEPSS 1.0%CVE-2024-51243HIGHThe eladmin v2.7 and before contains a remote code execution (RCE) vulnerability that can control all application deployment servers of thisEPSS 1.0%CVE-2023-36702HIGHMicrosoft DirectMusic Remote Code Execution VulnerabilityEPSS 1.0%CVE-2026-15011CRITICALCustomer Support Ticket System & Helpdesk <= 6.0.5 - Unauthenticated Code Injection via 'path' ParameterEPSS 1.0%CVE-2024-34461CRITICALZenario before 9.5.60437 uses Twig filters insecurely in the Twig Snippet plugin, and in the site-wide HEAD and BODY elements, enabling codeEPSS 1.0%CVE-2024-6891HIGHJournyx Authenticated Remote Code ExecutionEPSS 1.0%CVE-2024-39209MEDIUMluci-app-sms-tool v1.9-6 was discovered to contain a command injection vulnerability via the score parameter.EPSS 1.0%CVE-2024-45623CRITICALD-Link DAP-2310 Hardware A Firmware 1.16RC028 allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the ATPEPSS 0.9%CVE-2024-41361CRITICALRPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\manageFilesFolders.phpEPSS 0.9%CVE-2025-5309HIGHRemote Support & Privileged Remote Access server side template injectionEPSS 0.9%