Fallos del tipo CWE-94

4448 resultados

Injeção de script

A aplicação executa código dinâmico (JavaScript, Python, etc.) construído a partir de entrada do usuário sem validação ou sanitização adequada. Um atacante injeta comandos maliciosos que são interpretados e executados pelo servidor ou navegador como se fossem parte legítima do programa.

Ejemplo

Um formulário de contato concatena o nome do usuário diretamente em um script JavaScript enviado ao navegador: `<script>var usuario = '` + entrada_usuario + `';</script>`. Se o usuário envia `'; alert('xss'); //`, o navegador executa o alerta indesejado.

Cómo mitigar

Nunca construa código dinâmico a partir de entrada de usuário. Use APIs seguras (como `JSON.parse()` ao invés de `eval()`, ou templates com escape automático), valide e sanitize rigorosamente todas as entradas, e aplique listas brancas de caracteres permitidos quando possível.

CVE-2026-46633HIGHTwig: PHP code injection via `{% use %}` template nameEPSS 0.7%CVE-2025-3563MEDIUMWuzhiCMS Setting index.php set code injectionEPSS 0.7%CVE-2026-53510HIGHSavon::Model evaluates WSDL operation names as Ruby sourceEPSS 0.7%CVE-2023-6126MEDIUMCode Injection in salesagility/suitecrmEPSS 0.7%CVE-2026-100864HIGHheym before 0.0.91 Remote Code Execution via Expression EngineEPSS 0.7%CVE-2026-45311CRITICALCodeWhale: run_tests Tool Enables RCE via Malicious Repository Without ApprovalEPSS 0.7%CVE-2025-10370MEDIUMMiczFlor RPi-Jukebox-RFID userScripts.php cross site scriptingEPSS 0.7%CVE-2025-26003CRITICALTelesquare TLR-2005KSH 1.1.4 is affected by an unauthorized command execution vulnerability when requesting the admin.cgi parameter with setEPSS 0.7%CVE-2023-44392HIGHArbitrary code execution vulnerability when using shared Kubernetes clusterEPSS 0.7%CVE-2024-9132HIGHThe administrator is able to configure an insecure captive portal scriptEPSS 0.7%CVE-2026-33646CRITICALmise: Arbitrary Code Execution via Tera Templates in .tool-versions Files (Trust Bypass)EPSS 0.7%CVE-2025-70073HIGHAn issue in ChestnutCMS v.1.5.8 and before allows a remote attacker to execute arbitrary code via the template creation functionEPSS 0.7%CVE-2023-21569MEDIUMAzure DevOps Server Spoofing VulnerabilityEPSS 0.7%CVE-2010-5153MEDIUMRace condition in Avira Premium Security Suite 10.0.0.536 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute EPSS 0.7%CVE-2024-11699HIGHMemory safety bugs present in Firefox 132, Firefox ESR 128.4, and Thunderbird 128.4. Some of these bugs showed evidence of memory corruptionEPSS 0.7%CVE-2025-6213HIGHNginx Cache Purge Preload <= 2.1.1 - Authenticated (Administrator+) Remote Code ExecutionEPSS 0.7%CVE-2024-8880MEDIUMplaySMS Template index.php code injectionEPSS 0.7%CVE-2024-25096CRITICALWordPress canto plugin <= 3.0.7 - Unauth. Remote Code Execution (RCE) vulnerabilityEPSS 0.7%CVE-2025-13658CRITICALIndustrial Video & Control Longwatch has a Code Injection vulnerabilityEPSS 0.7%CVE-2026-41196CRITICALLuanti has a mod security sandbox escapeEPSS 0.7%