Falhas do tipo CWE-94

4.446 resultados

Injeção de script

Ocorre quando a aplicação constrói e executa código (JavaScript, Python, shell, etc.) usando dados não validados fornecidos pelo usuário. O atacante consegue injetar comandos arbitrários que serão executados com os privilégios da aplicação, comprometendo a segurança e integridade do sistema.

Exemplo

Um formulário que avalia expressões matemáticas recebidas do usuário: se a entrada é concatenada direto em um eval() ou equivalente, um atacante pode passar `__import__('os').system('rm -rf /')` em vez de uma expressão legítima, executando comandos do sistema.

Como mitigar

Nunca execute código construído a partir de entrada do usuário. Use parsers/validadores que aceitam apenas formatos esperados (whitelist), sandboxes para execução controlada, ou bibliotecas seguras que não avaliam código dinâmico. Se inevitável, isole rigidamente o ambiente de execução.

CVE-2026-31040CRITICALA vulnerability was identified in stata-mcp prior to v1.13.0 where insufficient validation of user-supplied Stata do-file content can lead tEPSS 1.1%CVE-2025-66848CRITICALJD Cloud NAS routers AX1800 (4.3.1.r4308 and earlier), AX3000 (4.3.1.r4318 and earlier), AX6600 (4.5.1.r4533 and earlier), BE6500 (4.4.1.r43EPSS 1.1%CVE-2023-46958CRITICALAn issue in lmxcms v.1.41 allows a remote attacker to execute arbitrary code via a crafted script to the admin.php file.EPSS 1.1%CVE-2024-56373HIGHApache Airflow: SSTI to Code Execution in Airflow through Shared DB InformationEPSS 1.1%CVE-2023-43481CRITICALAn issue in Shenzhen TCL Browser TV Web BrowseHere (aka com.tcl.browser) 6.65.022_dab24cc6_231221_gp allows a remote attacker to execute arbEPSS 1.1%CVE-2017-20086MEDIUMVaultPress Plugin code injectionEPSS 1.1%CVE-2025-69262HIGHpnpm vulnerable to Command Injection via environment variable substitutionEPSS 1.1%CVE-2023-1947MEDIUMtaoCMS admin.php code injectionEPSS 1.1%CVE-2024-42733CRITICALAn issue in Docmosis Tornado v.2.9.7 and before allows a remote attacker to execute arbitrary code via a crafted script to the UNC path inpuEPSS 1.1%CVE-2024-48694CRITICALFile Upload vulnerability in Xi'an Daxi Information technology OfficeWeb365 v.8.6.1.0 and v7.18.23.0 allows a remote attacker to execute arbEPSS 1.1%CVE-2025-52385CRITICALAn issue in Studio 3T v.2025.1.0 and before allows a remote attacker to execute arbitrary code via a crafted payload to the child_process moEPSS 1.1%CVE-2024-23755HIGHClickUp Desktop before 3.3.77 on macOS and Windows allows code injection because of specific Electron Fuses. There is inadequate protection EPSS 1.1%CVE-2023-33570—Bagisto v1.5.1 is vulnerable to Server-Side Template Injection (SSTI).EPSS 1.1%CVE-2023-51018CRITICALTOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘opmode’ parameter of the setWiFiAEPSS 1.0%CVE-2023-51026—TOTOlink EX1800T V9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘hour’ parameter of the setRebootSEPSS 1.0%CVE-2023-51015—TOTOLINX EX1800T v9.1.0cu.2112_B20220316 is vulnerable to arbitrary command execution in the ‘enable parameter’ of the setDmzCfg interface oEPSS 1.0%CVE-2026-33309CRITICALLangflow has an Arbitrary File Write (RCE) via v2 APIEPSS 1.0%CVE-2025-1497CRITICALRemote Code Execution in PlotAIEPSS 1.0%CVE-2025-3053HIGHUiPress lite | Effortless custom dashboards, admin themes and pages <= 3.5.07 - Authenticated (Subscriber+) Remote Code ExecutionEPSS 1.0%CVE-2023-48978CRITICALAn issue in NCR ITM Web terminal v.4.4.0 and v.4.4.4 allows a remote attacker to execute arbitrary code via a crafted script to the IP camerEPSS 1.0%