Falhas do tipo CWE-94

4.447 resultados

Injeção de script

Ocorre quando a aplicação constrói e executa código (JavaScript, Python, shell, etc.) usando dados não validados fornecidos pelo usuário. O atacante consegue injetar comandos arbitrários que serão executados com os privilégios da aplicação, comprometendo a segurança e integridade do sistema.

Exemplo

Um formulário que avalia expressões matemáticas recebidas do usuário: se a entrada é concatenada direto em um eval() ou equivalente, um atacante pode passar `__import__('os').system('rm -rf /')` em vez de uma expressão legítima, executando comandos do sistema.

Como mitigar

Nunca execute código construído a partir de entrada do usuário. Use parsers/validadores que aceitam apenas formatos esperados (whitelist), sandboxes para execução controlada, ou bibliotecas seguras que não avaliam código dinâmico. Se inevitável, isole rigidamente o ambiente de execução.

CVE-2023-3393HIGHCode Injection in fossbilling/fossbillingEPSS 1.0%CVE-2026-92937CRITICALvm2 3.11.6 Remote Code Execution via Promise call/applyEPSS 1.0%CVE-2024-49362HIGHRemote Code Execution on click of <a> Link in markdown previewEPSS 1.0%CVE-2024-3734MEDIUMFOX – Currency Switcher Professional for WooCommerce <= 1.4.1.8 - Unauthenticated Arbitrary Shortcode ExecutionEPSS 1.0%CVE-2023-35853—In Suricata before 6.0.13, an adversary who controls an external source of Lua rules may be able to execute Lua code. This is addressed in 6EPSS 1.0%CVE-2024-22632CRITICALSetor Informatica Sistema Inteligente para Laboratorios (S.I.L.) 388 was discovered to contain a remote code execution (RCE) vulnerability vEPSS 1.0%CVE-2023-24576HIGH EMC NetWorker may potentially be vulnerable to an unauthenticated remote code execution vulnerability in the NetWorker Client execution sEPSS 1.0%CVE-2025-50707CRITICALAn issue in thinkphp3 v.3.2.5 allows a remote attacker to execute arbitrary code via the index.php componentEPSS 1.0%CVE-2020-11056HIGHPotential Code Injection in Sprout FormsEPSS 1.0%CVE-2026-76841HIGHXinference through 2.11.0 Remote Code Execution via Hardcoded trust_remote_code in Model LoadersEPSS 1.0%CVE-2023-6899MEDIUMrmountjoy92 DashMachine Config save_config code injectionEPSS 1.0%CVE-2025-50706CRITICALAn issue in thinkphp v.5.1 allows a remote attacker to execute arbitrary code via the routecheck functionEPSS 1.0%CVE-2024-22533CRITICALBefore Beetl v3.15.12, the rendering template has a server-side template injection (SSTI) vulnerability. When the incoming template is contrEPSS 1.0%CVE-2023-45673HIGHArbitrary code execution on click of PDF links in JoplinEPSS 1.0%CVE-2023-25344—An issue was discovered in swig-templates thru 2.0.4 and swig thru 1.4.2, allows attackers to execute arbitrary code via crafted Object.protEPSS 1.0%CVE-2024-21511CRITICALVersions of the package mysql2 before 3.9.7 are vulnerable to Arbitrary Code Injection due to improper sanitization of the timezone parameteEPSS 1.0%CVE-2023-27866MEDIUMIBM Informix JDBC code executionEPSS 1.0%CVE-2024-2016MEDIUMZhiCms setcontroller.php index code injectionEPSS 1.0%CVE-2026-45829CRITICALA pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attackEPSS 1.0%CVE-2021-22952—A vulnerability found in UniFi Talk application V1.12.3 and earlier permits a malicious actor who has already gained access to a network to EPSS 1.0%