Falhas do tipo CWE-94

4.447 resultados

Injeção de script

Ocorre quando a aplicação constrói e executa código (JavaScript, Python, shell, etc.) usando dados não validados fornecidos pelo usuário. O atacante consegue injetar comandos arbitrários que serão executados com os privilégios da aplicação, comprometendo a segurança e integridade do sistema.

Exemplo

Um formulário que avalia expressões matemáticas recebidas do usuário: se a entrada é concatenada direto em um eval() ou equivalente, um atacante pode passar `__import__('os').system('rm -rf /')` em vez de uma expressão legítima, executando comandos do sistema.

Como mitigar

Nunca execute código construído a partir de entrada do usuário. Use parsers/validadores que aceitam apenas formatos esperados (whitelist), sandboxes para execução controlada, ou bibliotecas seguras que não avaliam código dinâmico. Se inevitável, isole rigidamente o ambiente de execução.

CVE-2024-57061CRITICALAn issue in Termius Version 9.9.0 through v.9.16.0 allows a physically proximate attacker to execute arbitrary code via the insecure ElectroEPSS 0.7%CVE-2024-37743CRITICALAn issue in mmzdev KnowledgeGPT V.0.0.5 allows a remote attacker to execute arbitrary code via the Document Display Component.EPSS 0.7%CVE-2026-79310HIGHwebpy web.py 0.76 is vulnerable to server-side template injection (SSTI). The template engine can be tricked into executing attacker-controlEPSS 0.7%CVE-2024-13645CRITICALTagDiv Composer <= 5.3 - Unauthenticated Arbitrary PHP Object InstantiationEPSS 0.7%CVE-2023-39157CRITICALWordPress JetElements For Elementor Plugin <= 2.6.10 is vulnerable to Remote Code Execution (RCE)EPSS 0.7%CVE-2026-69255CRITICALFlowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell VerifiedEPSS 0.7%CVE-2025-68619HIGHSignal K Server Vulnerable to Remote Code Execution via Malicious npm PackageEPSS 0.7%CVE-2024-13487HIGHCURCY – Multi Currency for WooCommerce <= 2.2.5 - Unauthenticated Arbitrary Shortcode Execution via get_products_price FunctionEPSS 0.7%CVE-2024-24230HIGHKomm.One CMS 10.4.2.14 has a Server-Side Template Injection (SSTI) vulnerability via the Velocity template engine. It allows remote attackerEPSS 0.7%CVE-2025-66916CRITICALThe snailjob component in RuoYi-Vue-Plus versions 5.5.1 and earlier, interface /snail-job/workflow/check-node-expression can execute QLExpreEPSS 0.7%CVE-2026-46586HIGHApache OFBiz: Improper Validation in traverseContent Service Enables Authenticated Groovy Code ExecutionEPSS 0.7%CVE-2026-78654MEDIUMcleverbrush framework/deep deepExtend.ts deepExtend prototype pollutionEPSS 0.7%CVE-2025-65716HIGHAn issue in Visual Studio Code Extensions Markdown Preview Enhanced v0.8.18 allows attackers to execute arbitrary code via uploading a craftEPSS 0.7%CVE-2026-6110MEDIUMFoundationAgents MetaGPT Tree-of-Thought Solver tot.py generate_thoughts code injectionEPSS 0.7%CVE-2026-5970MEDIUMFoundationAgents MetaGPT HumanEvalBenchmark/MBPPBenchmark check_solution code injectionEPSS 0.7%CVE-2025-23051HIGHAuthenticated Remote Code Execution in AOS Web-based Management InterfaceEPSS 0.7%CVE-2024-28424HIGHzenml v0.55.4 was discovered to contain an arbitrary file upload vulnerability in the load function at /materializers/cloudpickle_materializEPSS 0.7%CVE-2024-10505MEDIUMwuzhicms block.php edit code injectionEPSS 0.7%CVE-2026-5971MEDIUMFoundationAgents MetaGPT XML action_node.py ActionNode.xml_fill eval injectionEPSS 0.7%CVE-2024-7899MEDIUMInnoCMS Backend edit code injectionEPSS 0.7%