Falhas do tipo CWE-94

4.448 resultados

Injeção de script

Ocorre quando a aplicação constrói e executa código (JavaScript, Python, shell, etc.) usando dados não validados fornecidos pelo usuário. O atacante consegue injetar comandos arbitrários que serão executados com os privilégios da aplicação, comprometendo a segurança e integridade do sistema.

Exemplo

Um formulário que avalia expressões matemáticas recebidas do usuário: se a entrada é concatenada direto em um eval() ou equivalente, um atacante pode passar `__import__('os').system('rm -rf /')` em vez de uma expressão legítima, executando comandos do sistema.

Como mitigar

Nunca execute código construído a partir de entrada do usuário. Use parsers/validadores que aceitam apenas formatos esperados (whitelist), sandboxes para execução controlada, ou bibliotecas seguras que não avaliam código dinâmico. Se inevitável, isole rigidamente o ambiente de execução.

CVE-2024-48168CRITICALA stack overflow vulnerability exists in the sub_402280 function of the HNAP service of D-Link DCS-960L 1.09, allowing an attacker to executEPSS 1.0%CVE-2023-47397CRITICALWeBid <=1.2.2 is vulnerable to code injection via admin/categoriestrans.php.EPSS 1.0%CVE-2023-0462HIGHArbitrary code execution through yaml global parametersEPSS 1.0%CVE-2025-44071CRITICALSeaCMS v13.3 was discovered to contain a remote code execution (RCE) vulnerability via the component phomebak.php. This vulnerability allowsEPSS 1.0%CVE-2026-25510CRITICALCI4MS Vulnerable to Remote Code Execution (RCE) via Arbitrary File Creation and Save in File EditorEPSS 1.0%CVE-2024-8523MEDIUMlmxcms SQL Command Execution Module admin.php formatData code injectionEPSS 1.0%CVE-2024-3098CRITICALPrompt Injection leading to Arbitrary Code Execution in run-llama/llama_indexEPSS 1.0%CVE-2025-2127MEDIUMJoomlaUX JUX Real Estate realties cross site scriptingEPSS 1.0%CVE-2023-5500HIGHFrauscher: FDS102 for FAdC/FAdCi remote code execution vulnerabilityEPSS 1.0%CVE-2024-48453CRITICALAn issue in INOVANCE AM401_CPU1608TPTN allows a remote attacker to execute arbitrary code via the ExecuteUserProgramUpgrade functionEPSS 1.0%CVE-2023-31415CRITICALKibana version 8.7.0 contains an arbitrary code execution flaw. An attacker with All privileges to the Uptime/Synthetics feature could send EPSS 1.0%CVE-2023-30638HIGHAtos Unify OpenScape SBC 10 before 10R3.1.3, OpenScape Branch 10 before 10R3.1.2, and OpenScape BCF 10 before 10R10.7.0 allow remote authentEPSS 1.0%CVE-2023-23912HIGHA vulnerability, found in EdgeRouters Version 2.0.9-hotfix.5 and earlier and UniFi Security Gateways (USG) Version 4.4.56 and earlier with tEPSS 1.0%CVE-2026-44377CRITICALCubeCart: Server-Side Template Injection (SSTI) in Smarty Templates leading to RCEEPSS 1.0%CVE-2024-51243HIGHThe eladmin v2.7 and before contains a remote code execution (RCE) vulnerability that can control all application deployment servers of thisEPSS 1.0%CVE-2023-36702HIGHMicrosoft DirectMusic Remote Code Execution VulnerabilityEPSS 1.0%CVE-2024-34461CRITICALZenario before 9.5.60437 uses Twig filters insecurely in the Twig Snippet plugin, and in the site-wide HEAD and BODY elements, enabling codeEPSS 1.0%CVE-2026-15011CRITICALCustomer Support Ticket System & Helpdesk <= 6.0.5 - Unauthenticated Code Injection via 'path' ParameterEPSS 1.0%CVE-2024-6891HIGHJournyx Authenticated Remote Code ExecutionEPSS 1.0%CVE-2024-39209MEDIUMluci-app-sms-tool v1.9-6 was discovered to contain a command injection vulnerability via the score parameter.EPSS 1.0%