Falhas do tipo CWE-94

4.446 resultados

Injeção de script

Ocorre quando a aplicação constrói e executa código (JavaScript, Python, shell, etc.) usando dados não validados fornecidos pelo usuário. O atacante consegue injetar comandos arbitrários que serão executados com os privilégios da aplicação, comprometendo a segurança e integridade do sistema.

Exemplo

Um formulário que avalia expressões matemáticas recebidas do usuário: se a entrada é concatenada direto em um eval() ou equivalente, um atacante pode passar `__import__('os').system('rm -rf /')` em vez de uma expressão legítima, executando comandos do sistema.

Como mitigar

Nunca execute código construído a partir de entrada do usuário. Use parsers/validadores que aceitam apenas formatos esperados (whitelist), sandboxes para execução controlada, ou bibliotecas seguras que não avaliam código dinâmico. Se inevitável, isole rigidamente o ambiente de execução.

CVE-2026-55546CRITICALQWED-MCP: Unsafe SymPy `parse_expr()` Remote Code Execution via Unsanitized Math Expression InputEPSS 0.7%CVE-2026-67960CRITICALAn issue in PbootCMS v.3.2.15 allows an attacker to execute arbitrary code via the MemberController.php, UserController.php, CommentControllEPSS 0.7%CVE-2026-25077HIGHApache CloudStack: Unauthenticated Command Injection in Direct Download TemplatesEPSS 0.7%CVE-2026-93603CRITICALvm2 before 3.12.1 Sandbox Escape RCE via Non-Strict Host FunctionEPSS 0.7%CVE-2024-45873CRITICALA DLL hijacking vulnerability in VegaBird Yaazhini 2.0.2 allows attackers to execute arbitrary code / maintain persistence via placing a craEPSS 0.7%CVE-2026-5584MEDIUMFosowl agenticSeek query Endpoint PyInterpreter.py PyInterpreter.execute code injectionEPSS 0.7%CVE-2026-33654HIGHZero-Click Indirect Prompt Injection and Authentication Bypass via Email PollingEPSS 0.7%CVE-2026-27952HIGHAgenta has Python Sandbox Escape, Leading to Remote Code Execution (RCE)EPSS 0.7%CVE-2022-3245MEDIUM Code Injection in display of tag title on saving tags in microweber/microweberEPSS 0.7%CVE-2025-45479CRITICALInsufficient security mechanisms for created containers in educoder challenges v1.0 allow attackers to execute arbitrary code via injecting EPSS 0.7%CVE-2024-40546HIGHAn arbitrary file upload vulnerability in the component /admin/cmsWebFile/save of PublicCMS v4.0.202302.e allows attackers to execute arbitrEPSS 0.7%CVE-2024-40552HIGHPublicCMS v4.0.202302.e was discovered to contain a remote commande execution (RCE) vulnerability via the cmdarray parameter at /site/ScriptEPSS 0.7%CVE-2024-56072HIGHAn issue was discovered in FastNetMon Community Edition through 1.2.7. The sFlow v5 plugin allows remote attackers to cause a denial of servEPSS 0.7%CVE-2026-9072HIGHWebSphere Application Server Remote Code ExecutionEPSS 0.7%CVE-2024-32491CRITICALAn issue was discovered in Znuny and Znuny LTS 6.0.31 through 6.5.7 and Znuny 7.0.1 through 7.0.16 where a logged-in user can upload a file EPSS 0.7%CVE-2026-77413CRITICALJSONata: Arbitrary Code Execution via crafted JSONata expressionsEPSS 0.7%CVE-2026-18667CRITICALSensor Proxy Version 1.4.2 Fixes One VulnerabilityEPSS 0.7%CVE-2024-48070CRITICALAn issue in Weaver E-cology v. attackers construct special requests to insert remote malicious code and to trigger malicious code execution,EPSS 0.7%CVE-2025-30057CRITICALAuthenticated RCE with uhcapache privileges in ConvertToPDFEPSS 0.7%CVE-2022-3713HIGHA code injection vulnerability allows adjacent attackers to execute code in the Wifi controller of Sophos Firewall releases older than versiEPSS 0.7%