Falhas do tipo CWE-94

4.446 resultados

Injeção de script

Ocorre quando a aplicação constrói e executa código (JavaScript, Python, shell, etc.) usando dados não validados fornecidos pelo usuário. O atacante consegue injetar comandos arbitrários que serão executados com os privilégios da aplicação, comprometendo a segurança e integridade do sistema.

Exemplo

Um formulário que avalia expressões matemáticas recebidas do usuário: se a entrada é concatenada direto em um eval() ou equivalente, um atacante pode passar `__import__('os').system('rm -rf /')` em vez de uma expressão legítima, executando comandos do sistema.

Como mitigar

Nunca execute código construído a partir de entrada do usuário. Use parsers/validadores que aceitam apenas formatos esperados (whitelist), sandboxes para execução controlada, ou bibliotecas seguras que não avaliam código dinâmico. Se inevitável, isole rigidamente o ambiente de execução.

CVE-2026-66148MEDIUMAn authenticated command injection vulnerability was identified in GMS Command-Line Interface (CLI) 9.5.1 (Build 9510.1044) and earlier versEPSS 1.1%CVE-2026-50223HIGHApache OFBiz: DataResource Low-Privileged Authenticated FreeMarker Template Injection Leads to Remote Code ExecutionEPSS 1.1%CVE-2024-37779HIGHWoodWing Elvis DAM v6.98.1 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the Apache Ant scriptEPSS 1.1%CVE-2022-45553—An issue discovered in Shenzhen Zhibotong Electronics WBT WE1626 Router v 21.06.18 allows attacker to execute arbitrary commands via serial EPSS 1.1%CVE-2025-0185HIGHPandas Query Injection in langgenius/difyEPSS 1.1%CVE-2024-6923MEDIUMEmail header injection due to unquoted newlinesEPSS 1.1%CVE-2017-20064MEDIUMElefant CMS layout code injectionEPSS 1.1%CVE-2024-30202HIGHIn Emacs before 29.3, arbitrary Lisp code is evaluated as part of turning on Org mode. This affects Org Mode before 9.6.23.EPSS 1.1%CVE-2025-1087CRITICALArbitrary Code Execution in Kong Insomnia Desktop ApplicationEPSS 1.1%CVE-2024-24525CRITICALAn issue in EpointWebBuilder 5.1.0-sp1, 5.2.1-sp1, 5.4.1 and 5.4.2 allows a remote attacker to execute arbitrary code via the infoid parametEPSS 1.1%CVE-2024-39700CRITICALRemote Code Execution (RCE) vulnerability in jupyterlab extension template `update-integration-tests` GitHub ActionEPSS 1.1%CVE-2025-46191CRITICALArbitrary File Upload in user_payment_update.php in SourceCodester Client Database Management System 1.0 allows unauthenticated users to uplEPSS 1.1%CVE-2023-45144CRITICALRemote code execution from login screen through unescaped URL parameter in OAuth Identity XWiki AppEPSS 1.1%CVE-2024-48581CRITICALFile Upload vulnerability in Best courier management system in php v.1.0 allows a remote attacker to execute arbitrary code via the admin_clEPSS 1.1%CVE-2023-47003CRITICALAn issue in RedisGraph v.2.12.10 allows an attacker to execute arbitrary code and cause a denial of service via a crafted string in DataBlocEPSS 1.1%CVE-2026-27497CRITICALn8n has Potential Remote Code Execution via Merge NodeEPSS 1.1%CVE-2024-21541MEDIUMVersions of the package dom-iterator before 1.0.1 are vulnerable to Arbitrary Code Execution due to use of the Function constructor without EPSS 1.1%CVE-2026-53451CRITICALGround Station: Unauthenticated arbitrary file write (path traversal) in save-waterfall-snapshot leads to remote code executionEPSS 1.1%CVE-2026-52103CRITICALA zero-click remote code execution (RCE) vulnerability in the /Terminal/Notification.hs component of SimpleX Chat before v6.5 allows attackeEPSS 1.1%CVE-2025-26014CRITICALA Remote Code Execution (RCE) vulnerability in Loggrove v.1.0 allows a remote attacker to execute arbitrary code via the path parameter.EPSS 1.1%