Falhas do tipo CWE-94

4.417 resultados

Injeção de script

Ocorre quando a aplicação constrói e executa código (JavaScript, Python, shell, etc.) usando dados não validados fornecidos pelo usuário. O atacante consegue injetar comandos arbitrários que serão executados com os privilégios da aplicação, comprometendo a segurança e integridade do sistema.

Exemplo

Um formulário que avalia expressões matemáticas recebidas do usuário: se a entrada é concatenada direto em um eval() ou equivalente, um atacante pode passar `__import__('os').system('rm -rf /')` em vez de uma expressão legítima, executando comandos do sistema.

Como mitigar

Nunca execute código construído a partir de entrada do usuário. Use parsers/validadores que aceitam apenas formatos esperados (whitelist), sandboxes para execução controlada, ou bibliotecas seguras que não avaliam código dinâmico. Se inevitável, isole rigidamente o ambiente de execução.

CVE-2026-4800HIGHlodash vulnerable to Code Injection via `_.template` imports key namesEPSS 2.8%CVE-2024-9162HIGHAll-in-One WP Migration and Backup <= 7.86 - Authenticated (Administrator+) Arbitrary PHP Code InjectionEPSS 2.7%CVE-2024-42845HIGHAn eval Injection vulnerability in the component invesalius/reader/dicom.py of InVesalius 3.1.99991 through 3.1.99998 allows attackers to exEPSS 2.7%CVE-2019-10182HIGHIt was found that icedtea-web though 1.7.2 and 1.8.2 did not properly sanitize paths from <jar/> elements in JNLP files. An attacker could tEPSS 2.7%CVE-2019-15598—A Code Injection exists in treekill on Windows which allows a remote code execution when an attacker is able to control the input into the cEPSS 2.7%CVE-2019-15597—A code injection exists in node-df v0.1.4 that can allow an attacker to remote code execution by unsanitized input.EPSS 2.7%CVE-2019-15599—A Code Injection exists in tree-kill on Windows which allows a remote code execution when an attacker is able to control the input into the EPSS 2.7%CVE-2017-16151—Based on details posted by the ElectronJS team; A remote code execution vulnerability has been discovered in Google Chromium that affects alEPSS 2.7%CVE-2021-1362HIGHCisco Unified Communications Products Remote Code Execution VulnerabilityEPSS 2.7%CVE-2022-25860HIGHVersions of the package simple-git before 3.16.0 are vulnerable to Remote Code Execution (RCE) via the clone(), pull(), push() and listRemotEPSS 2.7%CVE-2006-6975CRITICALPHP remote file inclusion vulnerability in centipaid_class.php in CentiPaid 1.4.3 allows remote attackers to execute arbitrary code via a UREPSS 2.7%CVE-2023-29492CRITICALNovi Survey before 8.9.43676 allows remote attackers to execute arbitrary code on the server in the context of the service account. This doeEPSS 2.7%KEVCVE-2021-40485HIGHMicrosoft Excel Remote Code Execution VulnerabilityEPSS 2.7%CVE-2024-21689HIGHThis High severity RCE (Remote Code Execution) vulnerability CVE-2024-21689  was introduced in versions 9.1.0, 9.2.0, 9.3.0, 9.4.0, 9.5.0, aEPSS 2.7%CVE-2018-19002—LCDS Laquis SCADA prior to version 4.1.0.4150 allows improper control of generation of code when opening a specially crafted project file, wEPSS 2.7%CVE-2022-31691CRITICALSpring Tools 4 for Eclipse version 4.16.0 and below as well as VSCode extensions such as Spring Boot Tools, Concourse CI Pipeline Editor, BoEPSS 2.6%CVE-2026-44403HIGHWing FTP Server < 8.1.3 Authenticated Remote Code Execution via Session SerializationEPSS 2.6%CVE-2025-1550HIGHArbitrary Code Execution via Crafted Keras Config for Model LoadingEPSS 2.6%CVE-2020-11079HIGHcommand injection fix in node-dns-syncEPSS 2.6%CVE-2026-77647CRITICALSPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is relatEPSS 2.6%