Fallos del tipo CWE-94

4446 resultados

Injeção de script

A aplicação executa código dinâmico (JavaScript, Python, etc.) construído a partir de entrada do usuário sem validação ou sanitização adequada. Um atacante injeta comandos maliciosos que são interpretados e executados pelo servidor ou navegador como se fossem parte legítima do programa.

Ejemplo

Um formulário de contato concatena o nome do usuário diretamente em um script JavaScript enviado ao navegador: `<script>var usuario = '` + entrada_usuario + `';</script>`. Se o usuário envia `'; alert('xss'); //`, o navegador executa o alerta indesejado.

Cómo mitigar

Nunca construa código dinâmico a partir de entrada de usuário. Use APIs seguras (como `JSON.parse()` ao invés de `eval()`, ou templates com escape automático), valide e sanitize rigorosamente todas as entradas, e aplique listas brancas de caracteres permitidos quando possível.

CVE-2024-57061CRITICALAn issue in Termius Version 9.9.0 through v.9.16.0 allows a physically proximate attacker to execute arbitrary code via the insecure ElectroEPSS 0.7%CVE-2024-37743CRITICALAn issue in mmzdev KnowledgeGPT V.0.0.5 allows a remote attacker to execute arbitrary code via the Document Display Component.EPSS 0.7%CVE-2026-79310HIGHwebpy web.py 0.76 is vulnerable to server-side template injection (SSTI). The template engine can be tricked into executing attacker-controlEPSS 0.7%CVE-2023-39157CRITICALWordPress JetElements For Elementor Plugin <= 2.6.10 is vulnerable to Remote Code Execution (RCE)EPSS 0.7%CVE-2024-13645CRITICALTagDiv Composer <= 5.3 - Unauthenticated Arbitrary PHP Object InstantiationEPSS 0.7%CVE-2026-69255CRITICALFlowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell VerifiedEPSS 0.7%CVE-2026-46586HIGHApache OFBiz: Improper Validation in traverseContent Service Enables Authenticated Groovy Code ExecutionEPSS 0.7%CVE-2024-13487HIGHCURCY – Multi Currency for WooCommerce <= 2.2.5 - Unauthenticated Arbitrary Shortcode Execution via get_products_price FunctionEPSS 0.7%CVE-2025-66916CRITICALThe snailjob component in RuoYi-Vue-Plus versions 5.5.1 and earlier, interface /snail-job/workflow/check-node-expression can execute QLExpreEPSS 0.7%CVE-2024-24230HIGHKomm.One CMS 10.4.2.14 has a Server-Side Template Injection (SSTI) vulnerability via the Velocity template engine. It allows remote attackerEPSS 0.7%CVE-2026-78654MEDIUMcleverbrush framework/deep deepExtend.ts deepExtend prototype pollutionEPSS 0.7%CVE-2025-65716HIGHAn issue in Visual Studio Code Extensions Markdown Preview Enhanced v0.8.18 allows attackers to execute arbitrary code via uploading a craftEPSS 0.7%CVE-2026-5971MEDIUMFoundationAgents MetaGPT XML action_node.py ActionNode.xml_fill eval injectionEPSS 0.7%CVE-2026-5970MEDIUMFoundationAgents MetaGPT HumanEvalBenchmark/MBPPBenchmark check_solution code injectionEPSS 0.7%CVE-2026-6110MEDIUMFoundationAgents MetaGPT Tree-of-Thought Solver tot.py generate_thoughts code injectionEPSS 0.7%CVE-2024-28424HIGHzenml v0.55.4 was discovered to contain an arbitrary file upload vulnerability in the load function at /materializers/cloudpickle_materializEPSS 0.7%CVE-2024-10505MEDIUMwuzhicms block.php edit code injectionEPSS 0.7%CVE-2025-23051HIGHAuthenticated Remote Code Execution in AOS Web-based Management InterfaceEPSS 0.7%CVE-2024-7899MEDIUMInnoCMS Backend edit code injectionEPSS 0.7%CVE-2026-6543HIGHAuthenticated Remote Code Execution Vulnerability in Langflow Code Validation EndpointEPSS 0.7%