Fallos del tipo CWE-94

4446 resultados

Injeção de script

A aplicação executa código dinâmico (JavaScript, Python, etc.) construído a partir de entrada do usuário sem validação ou sanitização adequada. Um atacante injeta comandos maliciosos que são interpretados e executados pelo servidor ou navegador como se fossem parte legítima do programa.

Ejemplo

Um formulário de contato concatena o nome do usuário diretamente em um script JavaScript enviado ao navegador: `<script>var usuario = '` + entrada_usuario + `';</script>`. Se o usuário envia `'; alert('xss'); //`, o navegador executa o alerta indesejado.

Cómo mitigar

Nunca construa código dinâmico a partir de entrada de usuário. Use APIs seguras (como `JSON.parse()` ao invés de `eval()`, ou templates com escape automático), valide e sanitize rigorosamente todas as entradas, e aplique listas brancas de caracteres permitidos quando possível.

CVE-2024-45874CRITICALA DLL hijacking vulnerability in VegaBird Vooki 5.2.9 allows attackers to execute arbitrary code / maintain persistence via placing a crafteEPSS 0.7%CVE-2026-67960CRITICALAn issue in PbootCMS v.3.2.15 allows an attacker to execute arbitrary code via the MemberController.php, UserController.php, CommentControllEPSS 0.7%CVE-2026-25077HIGHApache CloudStack: Unauthenticated Command Injection in Direct Download TemplatesEPSS 0.7%CVE-2026-93603CRITICALvm2 before 3.12.1 Sandbox Escape RCE via Non-Strict Host FunctionEPSS 0.7%CVE-2024-45873CRITICALA DLL hijacking vulnerability in VegaBird Yaazhini 2.0.2 allows attackers to execute arbitrary code / maintain persistence via placing a craEPSS 0.7%CVE-2026-5584MEDIUMFosowl agenticSeek query Endpoint PyInterpreter.py PyInterpreter.execute code injectionEPSS 0.7%CVE-2026-33654HIGHZero-Click Indirect Prompt Injection and Authentication Bypass via Email PollingEPSS 0.7%CVE-2026-27952HIGHAgenta has Python Sandbox Escape, Leading to Remote Code Execution (RCE)EPSS 0.7%CVE-2022-3245MEDIUM Code Injection in display of tag title on saving tags in microweber/microweberEPSS 0.7%CVE-2025-45479CRITICALInsufficient security mechanisms for created containers in educoder challenges v1.0 allow attackers to execute arbitrary code via injecting EPSS 0.7%CVE-2024-40546HIGHAn arbitrary file upload vulnerability in the component /admin/cmsWebFile/save of PublicCMS v4.0.202302.e allows attackers to execute arbitrEPSS 0.7%CVE-2024-40552HIGHPublicCMS v4.0.202302.e was discovered to contain a remote commande execution (RCE) vulnerability via the cmdarray parameter at /site/ScriptEPSS 0.7%CVE-2024-56072HIGHAn issue was discovered in FastNetMon Community Edition through 1.2.7. The sFlow v5 plugin allows remote attackers to cause a denial of servEPSS 0.7%CVE-2026-9072HIGHWebSphere Application Server Remote Code ExecutionEPSS 0.7%CVE-2024-32491CRITICALAn issue was discovered in Znuny and Znuny LTS 6.0.31 through 6.5.7 and Znuny 7.0.1 through 7.0.16 where a logged-in user can upload a file EPSS 0.7%CVE-2026-77413CRITICALJSONata: Arbitrary Code Execution via crafted JSONata expressionsEPSS 0.7%CVE-2026-18667CRITICALSensor Proxy Version 1.4.2 Fixes One VulnerabilityEPSS 0.7%CVE-2024-48070CRITICALAn issue in Weaver E-cology v. attackers construct special requests to insert remote malicious code and to trigger malicious code execution,EPSS 0.7%CVE-2025-30057CRITICALAuthenticated RCE with uhcapache privileges in ConvertToPDFEPSS 0.7%CVE-2022-3713HIGHA code injection vulnerability allows adjacent attackers to execute code in the Wifi controller of Sophos Firewall releases older than versiEPSS 0.7%