Falhas do tipo CWE-94

4.448 resultados

Injeção de script

Ocorre quando a aplicação constrói e executa código (JavaScript, Python, shell, etc.) usando dados não validados fornecidos pelo usuário. O atacante consegue injetar comandos arbitrários que serão executados com os privilégios da aplicação, comprometendo a segurança e integridade do sistema.

Exemplo

Um formulário que avalia expressões matemáticas recebidas do usuário: se a entrada é concatenada direto em um eval() ou equivalente, um atacante pode passar `__import__('os').system('rm -rf /')` em vez de uma expressão legítima, executando comandos do sistema.

Como mitigar

Nunca execute código construído a partir de entrada do usuário. Use parsers/validadores que aceitam apenas formatos esperados (whitelist), sandboxes para execução controlada, ou bibliotecas seguras que não avaliam código dinâmico. Se inevitável, isole rigidamente o ambiente de execução.

CVE-2026-45583HIGHMicrosoft Exchange Server Remote Code Execution VulnerabilityEPSS 0.7%CVE-2025-8417HIGHCatalog Importer, Scraper & Crawler <= 5.1.4 - Unauthenticated PHP Code InjectionEPSS 0.7%CVE-2021-47952CRITICALpython jsonpickle 2.0.0 Remote Code Execution via py/reprEPSS 0.7%CVE-2026-89083CRITICALHP Advance – Potential Elevation of Privilege, Remote Code Execution & Arbitrary File WriteEPSS 0.7%CVE-2026-31379MEDIUMApache OFBiz: Path Traversal and File Upload Validation Bypass Leading to Arbitrary File Write, Stored XSS and RCE in Catalog ManagerEPSS 0.7%CVE-2026-76605CRITICALJoomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.2EPSS 0.7%CVE-2026-76604CRITICALJoomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.2EPSS 0.7%CVE-2026-89082CRITICALHP Advance – Potential Elevation of Privilege, Remote Code Execution & Arbitrary File WriteEPSS 0.7%CVE-2026-6902HIGHCode Injection in Perforce P4 (Helix Core)EPSS 0.7%CVE-2024-30868CRITICALnetentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/add_getlogin.php.EPSS 0.7%CVE-2026-12257CRITICALRemote code execution in Mura Software’s CMSEPSS 0.7%CVE-2024-55505HIGHAn issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the mess-view.php component.EPSS 0.7%CVE-2026-79574CRITICALAn issue in the gateway server of mpush v0.8.1 allows attackers to execute arbitrary code via sending a crafted broadcast message.EPSS 0.7%CVE-2026-82340CRITICALIBM Guardium Data Protection is affected by multiple vulnerabilities.EPSS 0.7%CVE-2026-73453CRITICALSecurity Advisory 0174EPSS 0.7%CVE-2026-50880CRITICALAn issue in the sendmail transport integration component of YouTransfer v1.0.6 allows attackers to execute arbitrary code via supplying a crEPSS 0.7%CVE-2026-25141CRITICALOrval has a code injection via unsanitized x-enum-descriptions uing JS commentsEPSS 0.7%CVE-2026-25879CRITICALLangroid has Prompt to SQL Injection, Leading to RCEEPSS 0.7%CVE-2026-30117CRITICALscalar/astro v0.1.13 was discovered to contain an arbitrary file upload vulnerability in the the scalar_url query parameter of the Scalar PrEPSS 0.7%CVE-2026-36433CRITICALAn issue in Actions Semiconductor Co. Ltd Tool- Media Player Utilities v.4.46 allows a physically proximate attacker execute arbitrary code EPSS 0.7%