Falhas do tipo CWE-94

4.448 resultados

Injeção de script

Ocorre quando a aplicação constrói e executa código (JavaScript, Python, shell, etc.) usando dados não validados fornecidos pelo usuário. O atacante consegue injetar comandos arbitrários que serão executados com os privilégios da aplicação, comprometendo a segurança e integridade do sistema.

Exemplo

Um formulário que avalia expressões matemáticas recebidas do usuário: se a entrada é concatenada direto em um eval() ou equivalente, um atacante pode passar `__import__('os').system('rm -rf /')` em vez de uma expressão legítima, executando comandos do sistema.

Como mitigar

Nunca execute código construído a partir de entrada do usuário. Use parsers/validadores que aceitam apenas formatos esperados (whitelist), sandboxes para execução controlada, ou bibliotecas seguras que não avaliam código dinâmico. Se inevitável, isole rigidamente o ambiente de execução.

CVE-2022-35944MEDIUMOctober CMS Safe Mode bypass leads to authenticated RCE (Remote Code Execution)EPSS 0.9%CVE-2021-24721—Loco Translate < 2.5.4 - Authenticated PHP Code InjectionEPSS 0.9%CVE-2023-31447—user_login.cgi on Draytek Vigor2620 devices before 3.9.8.4 (and on all versions of Vigor2925 devices) allows attackers to send a crafted payEPSS 0.9%CVE-2026-57572CRITICALCrawl4AI: Unauthenticated RCE via Chromium launch-argument injection in browser_config.extra_argsEPSS 0.9%CVE-2024-36456CRITICALSymantec Privileged Access Manager Remote Command Execution vulnerabilityEPSS 0.9%CVE-2025-2711MEDIUMYonyou UFIDA ERP-NC systop.jsp cross site scriptingEPSS 0.9%CVE-2025-2709MEDIUMYonyou UFIDA ERP-NC login.jsp cross site scriptingEPSS 0.9%CVE-2017-20095MEDIUMSimple Ads Manager Plugin code injectionEPSS 0.9%CVE-2025-2710MEDIUMYonyou UFIDA ERP-NC menu.jsp cross site scriptingEPSS 0.9%CVE-2023-22853HIGHTiki before 24.1, when feature_create_webhelp is enabled, allows lib/structures/structlib.php PHP Object Injection because of an eval.EPSS 0.9%CVE-2021-29493MEDIUMKennnyshiwa-cogs vulnerable to Remote Code Execution in Tickets ModuleEPSS 0.9%CVE-2023-39333MEDIUMMaliciously crafted export names in an imported WebAssembly module can inject JavaScript code. The injected code may be able to access data EPSS 0.9%CVE-2023-41319HIGHRemote Code Execution in Custom Integration Upload in FidesEPSS 0.9%CVE-2025-4859MEDIUMD-Link DAP-2695 MAC Bypass Settings Page adv_macbypass.php cross site scriptingEPSS 0.9%CVE-2023-44847—An issue in SeaCMS v.12.8 allows an attacker to execute arbitrary code via the admin_ Weixin.php component.EPSS 0.9%CVE-2026-34202CRITICALZebra node crash — V5 transaction hash panic (P2P reachable)EPSS 0.9%CVE-2025-29806MEDIUMMicrosoft Edge (Chromium-based) Remote Code Execution VulnerabilityEPSS 0.9%CVE-2023-24835HIGHSoftnext SPAM SQR - Code InjectionEPSS 0.9%CVE-2021-47935HIGHSentry 8.2.0 Remote Code Execution via Pickle DeserializationEPSS 0.9%CVE-2025-30067HIGHApache Kylin: The remote code execution via jdbc urlEPSS 0.9%