Falhas do tipo CWE-94

4.456 resultados

Injeção de script

Ocorre quando a aplicação constrói e executa código (JavaScript, Python, shell, etc.) usando dados não validados fornecidos pelo usuário. O atacante consegue injetar comandos arbitrários que serão executados com os privilégios da aplicação, comprometendo a segurança e integridade do sistema.

Exemplo

Um formulário que avalia expressões matemáticas recebidas do usuário: se a entrada é concatenada direto em um eval() ou equivalente, um atacante pode passar `__import__('os').system('rm -rf /')` em vez de uma expressão legítima, executando comandos do sistema.

Como mitigar

Nunca execute código construído a partir de entrada do usuário. Use parsers/validadores que aceitam apenas formatos esperados (whitelist), sandboxes para execução controlada, ou bibliotecas seguras que não avaliam código dinâmico. Se inevitável, isole rigidamente o ambiente de execução.

CVE-2026-45714CRITICALCubeCart: Server-Side Template Injection (SSTI) in Smarty Templates leading to RCEEPSS 0.5%CVE-2022-29216HIGHCode injection in `saved_model_cli` in TensorFlowEPSS 0.5%CVE-2026-32573CRITICALWordPress Nelio AB Testing plugin <= 8.2.7 - Remote Code Execution (RCE) vulnerabilityEPSS 0.5%CVE-2026-71232HIGHMacCMS10 - Incomplete Function Blacklist in Template Editor Enables Authenticated RCEEPSS 0.5%CVE-2026-32414HIGHWordPress Advanced Woo Labels plugin <= 2.36 - Remote Code Execution (RCE) vulnerabilityEPSS 0.5%CVE-2026-50187HIGHOh My Zsh: Arbitrary Code Execution in oh-my-zsh dotenv plugin via malicious .env filesEPSS 0.5%CVE-2025-1155MEDIUMWebkul QloApps Your Location Search stores cross site scriptingEPSS 0.5%CVE-2022-45177HIGHAn issue was discovered in LIVEBOX Collaboration vDesk through v031. An Observable Response Discrepancy can occur under the /api/v1/vdeskintEPSS 0.5%CVE-2026-30479CRITICALA Dynamic-link Library Injection vulnerability in OSGeo Project MapServer before v8.0 allows attackers to execute arbitrary code via a craftEPSS 0.5%CVE-2026-13749HIGHSnowflake CLI Arbitrary Code Execution via Snowpark Annotation Processor Template InjectionEPSS 0.5%CVE-2026-18874MEDIUMVolsync-addon-controller: volsync-addon-controller: annotation values rendered into yaml via text/template without escaping allows yaml injection into subscriptionEPSS 0.5%CVE-2026-73170HIGHNozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in the Modbus CSV import wEPSS 0.5%CVE-2025-1465LOWlmxcms Maintenance db.inc.php code injectionEPSS 0.5%CVE-2026-15538MEDIUMprimefaces primereact API ObjectUtils.js ObjectUtils.mutateFieldData prototype pollutionEPSS 0.5%CVE-2024-12983MEDIUMcode-projects Hospital Management System Edit Doctor Details Page manage-doctors.php cross site scriptingEPSS 0.5%CVE-2025-67164CRITICALAn authenticated arbitrary file upload vulnerability in the /storage/poc.php component of Pagekit CMS v1.0.18 allows attackers to execute arEPSS 0.5%CVE-2025-1337MEDIUMEastnets PaymentSafe BIC Search cross site scriptingEPSS 0.5%CVE-2026-94572CRITICALIn OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and pool tls_ciphers field for control charactEPSS 0.5%CVE-2026-94571CRITICALIn OpenStack Octavia before 18.0.1, the Amphora provider driver did not reject control characters in the L7 policy redirect_url and redirectEPSS 0.5%CVE-2026-40877HIGHCombodo iTop: PHP Object Injection Leading to Remote Code Execution on user preferencesEPSS 0.5%