Falhas do tipo CWE-94

4.497 resultados

Injeção de script

Ocorre quando a aplicação constrói e executa código (JavaScript, Python, shell, etc.) usando dados não validados fornecidos pelo usuário. O atacante consegue injetar comandos arbitrários que serão executados com os privilégios da aplicação, comprometendo a segurança e integridade do sistema.

Exemplo

Um formulário que avalia expressões matemáticas recebidas do usuário: se a entrada é concatenada direto em um eval() ou equivalente, um atacante pode passar `__import__('os').system('rm -rf /')` em vez de uma expressão legítima, executando comandos do sistema.

Como mitigar

Nunca execute código construído a partir de entrada do usuário. Use parsers/validadores que aceitam apenas formatos esperados (whitelist), sandboxes para execução controlada, ou bibliotecas seguras que não avaliam código dinâmico. Se inevitável, isole rigidamente o ambiente de execução.

CVE-2023-53940HIGHCodigo Markdown Editor 1.0.1 Electron Arbitrary Code Execution via Markdown FileEPSS 0.2%CVE-2022-37396MEDIUMIn JetBrains Rider before 2022.2 Trust and Open Project dialog could be bypassed, leading to local code executionEPSS 0.2%CVE-2025-27998HIGHAn issue in Valvesoftware Steam Client Steam Client 1738026274 allows attackers to escalate privileges via a crafted executable or DLL.EPSS 0.2%CVE-2026-73073HIGHVim: Arbitrary Ex Command Execution in C Omni-CompletionEPSS 0.2%CVE-2026-78367HIGHRpm: rpmbuild gettarspec() crafted tar member name → macro injectionEPSS 0.2%CVE-2024-51330MEDIUMAn issue in UltiMaker Cura v.4.41 and 5.8.1 and before allows a local attacker to execute arbitrary code via Inter-process communication (IPEPSS 0.2%CVE-2026-42049HIGHjadx: RCE Via Groovy Code Injection in Gradle ExportEPSS 0.2%CVE-2026-101861LOWLangflow Code Execution via eval() in Component Input SchemaEPSS 0.2%CVE-2026-73248HIGHcalibre: Bypass of Python template restrictions via nested `template()` leading to RCEEPSS 0.2%CVE-2026-30960CRITICALRSSN has Arbitrary Code Execution via Unvalidated JIT Instruction Generation in C-FFI InterfaceEPSS 0.2%CVE-2026-7580MEDIUMExiftool JPEG/QuickTime/MOV/MP4 GM.pm Process_mrld code injectionEPSS 0.2%CVE-2026-8021MEDIUMScript injection in UI in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who convinced a user to engage in specific UI gestuEPSS 0.2%CVE-2026-19060MEDIUMFoundationAgents MetaGPT code injectionEPSS 0.2%CVE-2026-34725HIGHdbgate-web: Stored XSS in applicationIcon leads to potential RCE in Electron due to unsafe renderer configurationEPSS 0.2%CVE-2026-19058MEDIUMFoundationAgents MetaGPT data_interpreter.py DataInterpreter code injectionEPSS 0.2%CVE-2026-42851HIGH@kitty-edit DCS + --color=geninclude vulnerable to Unauthenticated in-process RCEEPSS 0.2%CVE-2025-3753HIGHUnsafe use of eval() method in rosbag toolEPSS 0.2%CVE-2026-34223HIGHA vulnerability has been identified in Desigo CC ClickOnce Client V6 (All versions), Desigo CC ClickOnce Client V7 (All versions), Desigo CCEPSS 0.2%CVE-2026-24155HIGHNVIDIA NeMo Framework for all platforms contains a code injection vulnerability. A successful exploit of this vulnerability might lead to coEPSS 0.2%CVE-2025-67750HIGHLightning Flow Scanner is Vulnerable to Code Injection via Unsafe Use of new Function() in APIVersion RuleEPSS 0.2%