Falhas do tipo CWE-94

4.417 resultados

Injeção de script

Ocorre quando a aplicação constrói e executa código (JavaScript, Python, shell, etc.) usando dados não validados fornecidos pelo usuário. O atacante consegue injetar comandos arbitrários que serão executados com os privilégios da aplicação, comprometendo a segurança e integridade do sistema.

Exemplo

Um formulário que avalia expressões matemáticas recebidas do usuário: se a entrada é concatenada direto em um eval() ou equivalente, um atacante pode passar `__import__('os').system('rm -rf /')` em vez de uma expressão legítima, executando comandos do sistema.

Como mitigar

Nunca execute código construído a partir de entrada do usuário. Use parsers/validadores que aceitam apenas formatos esperados (whitelist), sandboxes para execução controlada, ou bibliotecas seguras que não avaliam código dinâmico. Se inevitável, isole rigidamente o ambiente de execução.

CVE-2023-32528—Trend Micro Mobile Security (Enterprise) 9.8 SP5 contains vulnerable .php files that could allow a remote attacker to execute arbitrary codeEPSS 3.0%CVE-2021-21433CRITICALRemote code execution on discord-recon .dirsearch and .arjun commands due to improper input validationEPSS 3.0%CVE-2020-8129—An unintended require vulnerability in script-manager npm package version 0.8.6 and earlier may allow attackers to execute arbitrary code.EPSS 2.9%CVE-2021-27446CRITICALWeintek EasyWeb cMT Code InjectionEPSS 2.9%CVE-2023-32527—Trend Micro Mobile Security (Enterprise) 9.8 SP5 contains vulnerable .php files that could allow a remote attacker to execute arbitrary codeEPSS 2.9%CVE-2008-1511CRITICALMultiple PHP remote file inclusion vulnerabilities in ooComments 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the PEPSS 2.9%CVE-2021-32829CRITICALPost-authentication Remote Code Execution (RCE) in ZStack REST APIEPSS 2.9%CVE-2026-53753CRITICALCrawl4AI: AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE in Docker APIEPSS 2.9%CVE-2023-40621MEDIUMCode Injection vulnerability in SAP PowerDesigner ClientEPSS 2.9%CVE-2022-3383HIGHUltimate Member – User Profile, User Registration, Login & Membership Plugin <= 2.5.0 - Authenticated (Admin+) Remote Code Execution via Multi-SelectEPSS 2.9%CVE-2019-13558—In WebAccess versions 8.4.1 and prior, an exploit executed over the network may cause improper control of generation of code, which may alloEPSS 2.9%CVE-2024-36622CRITICALIn RaspAP raspap-webgui 3.0.9 and earlier, a command injection vulnerability exists in the clearlog.php script. The vulnerability is due to EPSS 2.8%CVE-2022-39833HIGHFileCloud Versions 20.2 and later allows remote attackers to potentially cause unauthorized remote code execution and access to reported APIEPSS 2.8%CVE-2022-3384HIGHUltimate Member – User Profile, User Registration, Login & Membership Plugin <= 2.5.0 - Authenticated (Admin+) Limited Remote Code Execution via um_populate_dropdown_optionsEPSS 2.8%CVE-2024-48839CRITICALRemote Code Execution, RCEEPSS 2.8%CVE-2024-10644CRITICALCode injection in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticatEPSS 2.8%CVE-2025-66294HIGHGrav is vulnerable to RCE via SSTI through Twig Sandbox BypassEPSS 2.8%CVE-2024-7627HIGHBit File Manager 6.0 - 6.5.5 - Unauthenticated Remote Code Execution via Race ConditionEPSS 2.8%CVE-2024-3105CRITICALWoody code snippets – Insert Header Footer Code, AdSense Ads <= 2.5.0 -Authenticated (Contributor+) Remote Code ExecutionEPSS 2.8%CVE-2023-28706CRITICALApache Airflow Hive Provider Beeline Remote Command ExecutionEPSS 2.8%