Fallos del tipo CWE-94

4447 resultados

Injeção de script

A aplicação executa código dinâmico (JavaScript, Python, etc.) construído a partir de entrada do usuário sem validação ou sanitização adequada. Um atacante injeta comandos maliciosos que são interpretados e executados pelo servidor ou navegador como se fossem parte legítima do programa.

Ejemplo

Um formulário de contato concatena o nome do usuário diretamente em um script JavaScript enviado ao navegador: `<script>var usuario = '` + entrada_usuario + `';</script>`. Se o usuário envia `'; alert('xss'); //`, o navegador executa o alerta indesejado.

Cómo mitigar

Nunca construa código dinâmico a partir de entrada de usuário. Use APIs seguras (como `JSON.parse()` ao invés de `eval()`, ou templates com escape automático), valide e sanitize rigorosamente todas as entradas, e aplique listas brancas de caracteres permitidos quando possível.

CVE-2026-45583HIGHMicrosoft Exchange Server Remote Code Execution VulnerabilityEPSS 0.7%CVE-2025-8417HIGHCatalog Importer, Scraper & Crawler <= 5.1.4 - Unauthenticated PHP Code InjectionEPSS 0.7%CVE-2021-47952CRITICALpython jsonpickle 2.0.0 Remote Code Execution via py/reprEPSS 0.7%CVE-2026-89083CRITICALHP Advance – Potential Elevation of Privilege, Remote Code Execution & Arbitrary File WriteEPSS 0.7%CVE-2026-31379MEDIUMApache OFBiz: Path Traversal and File Upload Validation Bypass Leading to Arbitrary File Write, Stored XSS and RCE in Catalog ManagerEPSS 0.7%CVE-2026-76605CRITICALJoomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.2EPSS 0.7%CVE-2026-76604CRITICALJoomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.2EPSS 0.7%CVE-2026-89082CRITICALHP Advance – Potential Elevation of Privilege, Remote Code Execution & Arbitrary File WriteEPSS 0.7%CVE-2024-30868CRITICALnetentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/add_getlogin.php.EPSS 0.7%CVE-2026-12257CRITICALRemote code execution in Mura Software’s CMSEPSS 0.7%CVE-2026-6902HIGHCode Injection in Perforce P4 (Helix Core)EPSS 0.7%CVE-2024-55505HIGHAn issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the mess-view.php component.EPSS 0.7%CVE-2026-82340CRITICALIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 0.7%CVE-2026-73453CRITICALSecurity Advisory 0174EPSS 0.7%CVE-2026-79574CRITICALAn issue in the gateway server of mpush v0.8.1 allows attackers to execute arbitrary code via sending a crafted broadcast message.EPSS 0.7%CVE-2026-50880CRITICALAn issue in the sendmail transport integration component of YouTransfer v1.0.6 allows attackers to execute arbitrary code via supplying a crEPSS 0.7%CVE-2026-25141CRITICALOrval has a code injection via unsanitized x-enum-descriptions uing JS commentsEPSS 0.7%CVE-2026-30117CRITICALscalar/astro v0.1.13 was discovered to contain an arbitrary file upload vulnerability in the the scalar_url query parameter of the Scalar PrEPSS 0.7%CVE-2026-25879CRITICALLangroid has Prompt to SQL Injection, Leading to RCEEPSS 0.7%CVE-2026-36433CRITICALAn issue in Actions Semiconductor Co. Ltd Tool- Media Player Utilities v.4.46 allows a physically proximate attacker execute arbitrary code EPSS 0.7%