Falhas do tipo CWE-94

4.456 resultados

Injeção de script

Ocorre quando a aplicação constrói e executa código (JavaScript, Python, shell, etc.) usando dados não validados fornecidos pelo usuário. O atacante consegue injetar comandos arbitrários que serão executados com os privilégios da aplicação, comprometendo a segurança e integridade do sistema.

Exemplo

Um formulário que avalia expressões matemáticas recebidas do usuário: se a entrada é concatenada direto em um eval() ou equivalente, um atacante pode passar `__import__('os').system('rm -rf /')` em vez de uma expressão legítima, executando comandos do sistema.

Como mitigar

Nunca execute código construído a partir de entrada do usuário. Use parsers/validadores que aceitam apenas formatos esperados (whitelist), sandboxes para execução controlada, ou bibliotecas seguras que não avaliam código dinâmico. Se inevitável, isole rigidamente o ambiente de execução.

CVE-2024-45201HIGHAn issue was discovered in llama_index before 0.10.38. download/integration.py includes an exec call for import {cls_name}.EPSS 0.5%CVE-2026-40877HIGHCombodo iTop: PHP Object Injection Leading to Remote Code Execution on user preferencesEPSS 0.5%CVE-2024-55918MEDIUMAn issue was discovered in the Graphics::ColorNames package before 3.2.0 for Perl. There is an ambiguity between modules and filenames that EPSS 0.5%CVE-2025-46569HIGHOPA server Data API HTTP path injection of RegoEPSS 0.5%CVE-2026-51997HIGHAn issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary code via the open() functionsEPSS 0.5%CVE-2024-37109CRITICALWordPress WishList Member X plugin < 3.26.7 - Authenticated Arbitrary PHP Code Execution vulnerabilityEPSS 0.5%CVE-2024-32492HIGHAn issue was discovered in Znuny 7.0.1 through 7.0.16 where the ticket detail view in the customer front allows the execution of external JaEPSS 0.5%CVE-2025-46725HIGHLangroid has a Code Injection vulnerability in LanceDocChatAgent through vector_storeEPSS 0.5%CVE-2024-11971MEDIUMGuizhou Xiaoma Technology jpress Avatar upload cross site scriptingEPSS 0.5%CVE-2025-58372HIGHRoo Code: Potential Remote Code Execution via .code-workspaceEPSS 0.5%CVE-2026-76335HIGHRemote Code Execution (RCE) through Splunk Web Manager Configuration in Splunk EnterpriseEPSS 0.5%CVE-2026-8635CRITICALArbitrary Code Execution in Python Interpreter ComponentEPSS 0.5%CVE-2026-7873CRITICALCode Injection Vulnerability in Code Validation EndpointEPSS 0.5%CVE-2026-13435CRITICALPython Interpreter Sandbox Bypass Leading to Sensitive Data ExposureEPSS 0.5%CVE-2025-69872CRITICALDiskCache (python-diskcache) through 5.6.3 uses Python pickle for serialization by default. An attacker with write access to the cache direcEPSS 0.5%CVE-2026-16800HIGHImproper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026.2.2 and earlier aEPSS 0.5%CVE-2026-16801HIGHImproper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier EPSS 0.5%CVE-2024-11742MEDIUMSourceCodester Best House Rental Management System ajax.php cross site scriptingEPSS 0.5%CVE-2022-23008—On NGINX Controller API Management versions 3.18.0-3.19.0, an authenticated attacker with access to the "user" or "admin" role can use undisEPSS 0.5%CVE-2026-8056HIGHParameter Injection Vulnerability in API Graph Execution EngineEPSS 0.5%