Falhas do tipo CWE-94

4.448 resultados

Injeção de script

Ocorre quando a aplicação constrói e executa código (JavaScript, Python, shell, etc.) usando dados não validados fornecidos pelo usuário. O atacante consegue injetar comandos arbitrários que serão executados com os privilégios da aplicação, comprometendo a segurança e integridade do sistema.

Exemplo

Um formulário que avalia expressões matemáticas recebidas do usuário: se a entrada é concatenada direto em um eval() ou equivalente, um atacante pode passar `__import__('os').system('rm -rf /')` em vez de uma expressão legítima, executando comandos do sistema.

Como mitigar

Nunca execute código construído a partir de entrada do usuário. Use parsers/validadores que aceitam apenas formatos esperados (whitelist), sandboxes para execução controlada, ou bibliotecas seguras que não avaliam código dinâmico. Se inevitável, isole rigidamente o ambiente de execução.

CVE-2025-47988HIGHAzure Monitor Agent Remote Code Execution VulnerabilityEPSS 0.9%CVE-2026-90817CRITICALAn unauthenticated Remote Code Execution vulnerability was found in the survey passthrough routing and Data Import processing logic, in whicEPSS 0.9%CVE-2026-33660CRITICALn8n Has Multiple Remote Code Execution Vulnerabilities in Merge Node AlaSQL SQL ModeEPSS 0.9%CVE-2026-8481CRITICALRemote Code Execution via Code Validation EndpointEPSS 0.9%CVE-2026-73268CRITICALCluster-curator-controller: cluster-curator-controller: spec.install.overridejob allows arbitrary job spec injectionEPSS 0.9%CVE-2024-48818CRITICALAn issue in IIT Bombay, Mumbai, India Bodhitree of cs101 version allows a remote attacker to execute arbitrary code.EPSS 0.9%CVE-2023-44382CRITICALOctober CMS safe mode bypass using Twig sandbox escapeEPSS 0.9%CVE-2023-26782MEDIUMAn issue discovered in mccms 2.6.1 allows remote attackers to cause a denial of service via Backend management interface ->System ConfiguratEPSS 0.9%CVE-2023-36645CRITICALSQL injection vulnerability in ITB-GmbH TradePro v9.5, allows remote attackers to run SQL queries via oordershow component in customer functEPSS 0.9%CVE-2022-38745HIGHApache OpenOffice: Empty entry in Java class pathEPSS 0.9%CVE-2023-0626HIGHDocker Desktop before 4.12.0 is vulnerable to RCE via query parameters in message-box route EPSS 0.9%CVE-2023-0625HIGHDocker Desktop before 4.12.0 is vulnerable to RCE via a crafted extension description or changelogEPSS 0.9%CVE-2024-39236CRITICALGradio v4.36.1 was discovered to contain a code injection vulnerability via the component /gradio/component_meta.py. This vulnerability is tEPSS 0.9%CVE-2026-49832HIGHDSpace: Remote Code Execution (RCE) possible in Velocity Templates used by LDNEPSS 0.9%CVE-2024-22144CRITICALWordPress Anti-Malware Security and Brute-Force Firewall plugin <= 4.21.96 - Unauthenticated Predictable Nonce Brute-Force Leading to RCE vulnerabilityEPSS 0.9%CVE-2026-30120CRITICALremotion-dev remotion v4.0.409 was discovered to contain a remote code execution (RCE) vulnerability.EPSS 0.9%CVE-2015-10009MEDIUMnterchange code_caller_controller.php getContent code injectionEPSS 0.9%CVE-2026-12866CRITICALAll versions of the package expr-eval are vulnerable to Code Execution via the toJSFunction() API. An attacker can execute arbitrary JavaScrEPSS 0.9%CVE-2026-38165CRITICALA Server-Side Template Injection (SSTI) vulnerability in the Velocity template engine configuration of xdocreport v0.9.2 to v2.2.0 allows atEPSS 0.9%CVE-2023-37424HIGHUnauthenticated Remote Code Execution in EdgeConnect SD-WAN Orchestrator Web-Based Management InterfaceEPSS 0.9%