Falhas do tipo CWE-94

4.456 resultados

Injeção de script

Ocorre quando a aplicação constrói e executa código (JavaScript, Python, shell, etc.) usando dados não validados fornecidos pelo usuário. O atacante consegue injetar comandos arbitrários que serão executados com os privilégios da aplicação, comprometendo a segurança e integridade do sistema.

Exemplo

Um formulário que avalia expressões matemáticas recebidas do usuário: se a entrada é concatenada direto em um eval() ou equivalente, um atacante pode passar `__import__('os').system('rm -rf /')` em vez de uma expressão legítima, executando comandos do sistema.

Como mitigar

Nunca execute código construído a partir de entrada do usuário. Use parsers/validadores que aceitam apenas formatos esperados (whitelist), sandboxes para execução controlada, ou bibliotecas seguras que não avaliam código dinâmico. Se inevitável, isole rigidamente o ambiente de execução.

CVE-2025-53836CRITICALXWiki Rendering is vulnerable to RCE attacks when processing nested macrosEPSS 0.6%CVE-2026-27702CRITICALBudibase Vulnerable to Remote Code Execution via Unsafe eval() in View Filter Map Function (Budibase Cloud)EPSS 0.6%CVE-2022-27837MEDIUMA vulnerability using PendingIntent in Accessibility prior to version 12.5.3.2 in Android R(11.0) and 13.0.1.1 in Android S(12.0) allows attEPSS 0.6%CVE-2026-73032CRITICALPapersGPT for Zotero 0.6.1 RCE via Unsanitized LLM Response eval()EPSS 0.6%CVE-2026-21537HIGHMicrosoft Defender for Endpoint Linux Extension Remote Code Execution VulnerabilityEPSS 0.6%CVE-2026-6621MEDIUM1024bit extend-deep index.js prototype pollutionEPSS 0.6%CVE-2026-6594MEDIUMbrikcss merge prototype pollutionEPSS 0.6%CVE-2024-12790MEDIUMcode-projects Hostel Management Site room-details.php cross site scriptingEPSS 0.6%CVE-2024-27705HIGHCross Site Scripting vulnerability in Leantime v3.0.6 allows attackers to execute arbitrary code via upload of crafted PDF file to the filesEPSS 0.6%CVE-2025-56399HIGHalexusmai laravel-file-manager 3.3.1 and before allows an authenticated attacker to achieve Remote Code Execution (RCE) through a crafted fiEPSS 0.6%CVE-2026-46581HIGHIn Eclipse Mojarra versions 2.3 and following, URL handing in `DefaultFaceletFactory` does not properly sanitize and/or block remote URLs, aEPSS 0.6%CVE-2024-12789MEDIUMPbootCMS IndexController.php code injectionEPSS 0.6%CVE-2021-33635CRITICALPull malicious images may cause process to be hijackedEPSS 0.6%CVE-2022-42045—Certain Zemana products are vulnerable to Arbitrary code injection. This affects Watchdog Anti-Malware 4.1.422 and Zemana AntiMalware 3.2.28EPSS 0.6%CVE-2025-13786MEDIUMtaosir WTCMS index.php fetch code injectionEPSS 0.6%CVE-2026-92125HIGHJenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject the @GroovyASTTransformationClass annotation, allowing attaEPSS 0.6%CVE-2024-30567MEDIUMAn issue in JNT Telecom JNT Liftcom UMS V1.J Core Version JM-V15 allows a remote attacker to execute arbitrary code via the Network TroublesEPSS 0.6%CVE-2026-66745HIGHArtica Proxy 4.50 Session Fixation via fw.login.phpEPSS 0.6%CVE-2026-28505HIGHTautulli: RCE via eval() sandbox bypass using lambda nested scope to escape co_names whitelist checkEPSS 0.6%CVE-2024-39915CRITICALAuthenticated remote code execution in ThrukEPSS 0.6%