Falhas do tipo CWE-94

4.422 resultados

Injeção de script

Ocorre quando a aplicação constrói e executa código (JavaScript, Python, shell, etc.) usando dados não validados fornecidos pelo usuário. O atacante consegue injetar comandos arbitrários que serão executados com os privilégios da aplicação, comprometendo a segurança e integridade do sistema.

Exemplo

Um formulário que avalia expressões matemáticas recebidas do usuário: se a entrada é concatenada direto em um eval() ou equivalente, um atacante pode passar `__import__('os').system('rm -rf /')` em vez de uma expressão legítima, executando comandos do sistema.

Como mitigar

Nunca execute código construído a partir de entrada do usuário. Use parsers/validadores que aceitam apenas formatos esperados (whitelist), sandboxes para execução controlada, ou bibliotecas seguras que não avaliam código dinâmico. Se inevitável, isole rigidamente o ambiente de execução.

CVE-2023-43651HIGHRemote code execution on the host system via MongoDB shell in jumpserverEPSS 1.7%CVE-2022-43333CRITICALTelenia Software s.r.l TVox before v22.0.17 was discovered to contain a remote code execution (RCE) vulnerability in the component action_exEPSS 1.7%CVE-2022-44038CRITICALRussound XSourcePlayer 777D v06.08.03 was discovered to contain a remote code execution vulnerability via the scriptRunner.cgi component.EPSS 1.7%CVE-2024-31666CRITICALAn issue in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via a crafted script to the edit_addon_post.php component.EPSS 1.7%CVE-2026-58231CRITICALImproper Authorization in SAP Commerce Cloud (Data Hub Adapter)EPSS 1.7%CVE-2022-25812—Transposh WordPress Translation < 1.0.8 - Admin+ RCEEPSS 1.7%CVE-2011-10011CRITICALWeBid 1.0.2 converter.php Remote PHP Code InjectionEPSS 1.7%CVE-2026-33937CRITICALHandlebars.js has JavaScript Injection via AST Type ConfusionEPSS 1.7%CVE-2026-24105CRITICALAn issue was discovered in goform/formsetUsbUnload in Tenda AC15V1.0 V15.03.05.18_multi. The value of `v1` was not checked, potentially leadEPSS 1.7%CVE-2025-8191MEDIUMmacrozheng mall Swagger UI index.html cross site scriptingEPSS 1.7%CVE-2018-25357CRITICALDolibarr ERP CRM 7.0.3 Remote Code Execution via install/step1.phpEPSS 1.7%CVE-2024-23742—An issue in Loom on macOS version 0.196.1 and before, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilEPSS 1.7%CVE-2025-27657CRITICALVasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Remote Code Execution V-2023-008.EPSS 1.7%CVE-2021-39114HIGHAffected versions of Atlassian Confluence Server and Data Center allow users with a valid account on a Confluence Data Center instance to exEPSS 1.7%CVE-2024-38396CRITICALAn issue was discovered in iTerm2 3.5.x before 3.5.2. Unfiltered use of an escape sequence to report a window title, in combination with theEPSS 1.7%CVE-2013-10057HIGHSynactis PDF In-The-Box ConnectToSynactic Stack-Based Buffer OverflowEPSS 1.7%CVE-2020-8180—A too lax check in Nextcloud Talk 6.0.4, 7.0.2 and 8.0.7 allowed a code injection when a not correctly sanitized talk command was added by aEPSS 1.7%CVE-2024-42745CRITICALIn TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setUPnPCfg. AuthEPSS 1.7%CVE-2021-37384CRITICALRCE (Remote Code Execution) vulnerability was found in some Furukawa ONU models, this vulnerability allows remote unauthenticated users to sEPSS 1.7%CVE-2024-54803CRITICALNetgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted request to post.cgi, updaEPSS 1.7%