Fallos del tipo CWE-94

4448 resultados

Injeção de script

A aplicação executa código dinâmico (JavaScript, Python, etc.) construído a partir de entrada do usuário sem validação ou sanitização adequada. Um atacante injeta comandos maliciosos que são interpretados e executados pelo servidor ou navegador como se fossem parte legítima do programa.

Ejemplo

Um formulário de contato concatena o nome do usuário diretamente em um script JavaScript enviado ao navegador: `<script>var usuario = '` + entrada_usuario + `';</script>`. Se o usuário envia `'; alert('xss'); //`, o navegador executa o alerta indesejado.

Cómo mitigar

Nunca construa código dinâmico a partir de entrada de usuário. Use APIs seguras (como `JSON.parse()` ao invés de `eval()`, ou templates com escape automático), valide e sanitize rigorosamente todas as entradas, e aplique listas brancas de caracteres permitidos quando possível.

CVE-2026-61962CRITICALWordPress WP BASE Booking plugin <= 6.3.0 - Arbitrary Code Execution vulnerabilityEPSS 0.7%CVE-2026-82340CRITICALIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 0.7%CVE-2024-37899CRITICALDisabling a user account changes its author, allowing RCE from user account in XWikiEPSS 0.7%CVE-2024-13929HIGHAuthenticated Servlet Command InjectionEPSS 0.7%CVE-2023-45560—An issue in Yasukawa memberscard v.13.6.1 allows attackers to send crafted notifications via leakage of the channel access token.EPSS 0.7%CVE-2026-33976CRITICALNotesnook vulnerable to RCE via stored XSS in Web Clipper renderingEPSS 0.7%CVE-2024-11620HIGHWordPress Rank Math SEO plugin <= 1.0.231 - Arbitrary .htaccess Overwrite to Remote Code Execution (RCE) vulnerabilityEPSS 0.7%CVE-2024-9006MEDIUMjeanmarc77 123solar config_invt1.php code injectionEPSS 0.7%CVE-2026-29202MEDIUMInsufficient input validation of the `plugin` parameter of the `create_user` plugin allows arbitrary Perl code execution on behalf of the alEPSS 0.7%CVE-2026-41229CRITICALFroxlor has a PHP Code Injection via Unescaped Single Quotes in userdata.inc.php Generation (MysqlServer API)EPSS 0.7%CVE-2024-31266CRITICALWordPress Advanced Order Export For WooCommerce plugin <= 3.4.4 - Remote Code Execution (RCE) vulnerabilityEPSS 0.7%CVE-2026-69254CRITICALFlowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions OverrideEPSS 0.7%CVE-2024-39015CRITICALcafebazaar hod v0.4.14 was discovered to contain a prototype pollution via the function request. This vulnerability allows attackers to execEPSS 0.7%CVE-2019-5443—A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= EPSS 0.7%CVE-2025-1976HIGHCode injection exposure in Fabric OS 9.1.0 through 9.1.1d6EPSS 0.7%KEVCVE-2026-56446HIGHAuthenticated Remote Code Execution via Arbitrary NDJSON Error Log Path in MISPEPSS 0.7%CVE-2020-8140—A code injection in Nextcloud Desktop Client 2.6.2 for macOS allowed to load arbitrary code when starting the client with DYLD_INSERT_LIBRAREPSS 0.7%CVE-2026-46633HIGHTwig: PHP code injection via `{% use %}` template nameEPSS 0.7%CVE-2025-25246HIGHNETGEAR XR1000 before 1.0.0.74, XR1000v2 before 1.1.0.22, and XR500 before 2.3.2.134 allow remote code execution by unauthenticated users.EPSS 0.7%CVE-2025-23251HIGHNVIDIA NeMo Framework contains a vulnerability where a user could cause an improper control of generation of code by remote code execution. EPSS 0.7%