Falhas do tipo CWE-94

4.448 resultados

Injeção de script

Ocorre quando a aplicação constrói e executa código (JavaScript, Python, shell, etc.) usando dados não validados fornecidos pelo usuário. O atacante consegue injetar comandos arbitrários que serão executados com os privilégios da aplicação, comprometendo a segurança e integridade do sistema.

Exemplo

Um formulário que avalia expressões matemáticas recebidas do usuário: se a entrada é concatenada direto em um eval() ou equivalente, um atacante pode passar `__import__('os').system('rm -rf /')` em vez de uma expressão legítima, executando comandos do sistema.

Como mitigar

Nunca execute código construído a partir de entrada do usuário. Use parsers/validadores que aceitam apenas formatos esperados (whitelist), sandboxes para execução controlada, ou bibliotecas seguras que não avaliam código dinâmico. Se inevitável, isole rigidamente o ambiente de execução.

CVE-2026-41242CRITICALprotobufjs has an arbitrary code execution issueEPSS 1.0%CVE-2024-48514CRITICALphp-heic-to-jpg <= 1.0.5 is vulnerable to code injection (fixed in 1.0.6). An attacker who can upload heic images is able to execute code onEPSS 1.0%CVE-2024-37273CRITICALAn arbitrary file upload vulnerability in the /v1/app/appendFileSync interface of Jan v0.4.12 allows attackers to execute arbitrary code viaEPSS 1.0%CVE-2026-42898CRITICALMicrosoft Dynamics 365 On-Premises Remote Code Execution VulnerabilityEPSS 1.0%CVE-2026-77908HIGHMicrosoft Dynamics 365 On-Premises Remote Code Execution VulnerabilityEPSS 1.0%CVE-2026-18245MEDIUMIncomplete fix for CVE-2025-4318 code injection in Amazon @aws-amplify/codegen-ui-reactEPSS 1.0%CVE-2023-46243CRITICALCode execution via the edit action in XWiki platformEPSS 1.0%CVE-2024-6602CRITICALMemory corruption in NSSEPSS 1.0%CVE-2025-3641HIGHMoodle: authenticated remote code execution risk in the moodle lms dropbox repositoryEPSS 1.0%CVE-2023-23645CRITICALWordPress MainWP Code Snippets Extension Plugin <= 4.0.2 - Subscriber+ Arbitrary PHP Code Injection/Execution VulnerabilityEPSS 1.0%CVE-2026-30308CRITICALIn its design for automatic terminal command execution, HAI Build Code Generator offers two options: Execute safe commands and Execute all cEPSS 1.0%CVE-2026-30306CRITICALIn its design for automatic terminal command execution, SakaDev offers two options: Execute safe commands and execute all commands. The descEPSS 1.0%CVE-2026-8931CRITICALCritical RCE vulnerability in Disig Web SignerEPSS 1.0%CVE-2025-65294CRITICALAqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 contain an undocumented remote access mechaniEPSS 1.0%CVE-2026-29091HIGHLocutus: Remote Code Execution (RCE) in locutus call_user_func_array due to Code InjectionEPSS 1.0%CVE-2024-46489HIGHA remote command execution (RCE) vulnerability in promptr v6.0.7 allows attackers to execute arbitrary commands via a crafted URL.EPSS 1.0%CVE-2026-46562CRITICALYamcs: Remote Code Execution via Mission Database algorithm overrideEPSS 1.0%CVE-2026-30694CRITICALAn issue in DedeCMS v.5.7.118 and before allows a remote attacker to execute arbitrary code via the array_filter componentEPSS 1.0%CVE-2024-53924CRITICALPycel through 1.0b30, when operating on an untrusted spreadsheet, allows code execution via a crafted formula in a cell, such as one beginniEPSS 1.0%CVE-2014-10065—Certain input when passed into remarkable before 1.4.1 will bypass the bad protocol check that disallows the javascript: scheme allowing forEPSS 1.0%