Falhas do tipo CWE-94

4.421 resultados

Injeção de script

Ocorre quando a aplicação constrói e executa código (JavaScript, Python, shell, etc.) usando dados não validados fornecidos pelo usuário. O atacante consegue injetar comandos arbitrários que serão executados com os privilégios da aplicação, comprometendo a segurança e integridade do sistema.

Exemplo

Um formulário que avalia expressões matemáticas recebidas do usuário: se a entrada é concatenada direto em um eval() ou equivalente, um atacante pode passar `__import__('os').system('rm -rf /')` em vez de uma expressão legítima, executando comandos do sistema.

Como mitigar

Nunca execute código construído a partir de entrada do usuário. Use parsers/validadores que aceitam apenas formatos esperados (whitelist), sandboxes para execução controlada, ou bibliotecas seguras que não avaliam código dinâmico. Se inevitável, isole rigidamente o ambiente de execução.

CVE-2024-42634CRITICALA Command Injection vulnerability exists in formWriteFacMac of the httpd binary in Tenda AC9 v15.03.06.42. As a result, attacker can executeEPSS 2.2%CVE-2023-30179HIGHCraftCMS version 3.7.59 is vulnerable to Server-Side Template Injection (SSTI). An authenticated attacker can inject Twig Template to User PEPSS 2.2%CVE-2022-40628CRITICALRemote Code Execution Vulnerability in Tacitine FirewallEPSS 2.2%CVE-2026-29955HIGHThe `/registercrd` endpoint in KubePlus 4.14 in the kubeconfiggenerator component is vulnerable to command injection. The component uses `suEPSS 2.2%CVE-2023-5843CRITICALAds by datafeedr.com <= 1.1.3 - Unauthenticated (Limited) Remote Code ExecutionEPSS 2.2%CVE-2024-32350HIGHTOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "ipsEPSS 2.2%CVE-2024-32352HIGHTOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "ipsEPSS 2.2%CVE-2020-21016CRITICALD-Link DIR-846 devices with firmware 100A35 allow remote attackers to execute arbitrary code as root via HNAP1/control/SetGuestWLanSettings.EPSS 2.2%CVE-2026-24107CRITICALAn issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Failure to validate the value of `usbPartitionName`, which is directly used in `doSEPSS 2.2%CVE-2023-29566CRITICALhuedawn-tesseract 0.3.3 and dawnsparks-node-tesseract 0.4.0 to 0.4.1 was discovered to contain a remote code execution (RCE) vulnerability vEPSS 2.2%CVE-2023-26785CRITICALMariaDB v10.5 was discovered to contain a remote code execution (RCE) vulnerability via UDF Code in a Shared Object File, followed by a "creEPSS 2.2%CVE-2020-11057CRITICALCode Injection in XWiki PlatformEPSS 2.2%CVE-2024-43202CRITICALApache DolphinScheduler: Remote Code Execution VulnerabilityEPSS 2.1%CVE-2020-7013—Kibana versions before 6.8.9 and 7.7.0 contain a prototype pollution flaw in TSVB. An authenticated attacker with privileges to create TSVB EPSS 2.1%CVE-2020-8141—The dot package v1.1.2 uses Function() to compile templates. This can be exploited by the attacker if they can control the given template orEPSS 2.1%CVE-2023-27650CRITICALAn issue found in APUS Group Launcher v.3.10.73 and v.3.10.88 allows a remote attacker to execute arbitrary code via the FONT_FILE parameterEPSS 2.1%CVE-2024-4181HIGHCommand Injection in run-llama/llama_indexEPSS 2.1%CVE-2013-10035HIGHProcessMaker Open Source < 2.5.2 neoclassic Skin PHP Code ExecutionEPSS 2.1%CVE-2023-33733HIGHReportlab up to v3.6.12 allows attackers to execute arbitrary code via supplying a crafted PDF file.EPSS 2.1%CVE-2025-34074CRITICALLucee Admin Interface Authenticated Remote Code Execution via Scheduled Job File WriteEPSS 2.1%