Falhas do tipo CWE-94

4.452 resultados

Injeção de script

Ocorre quando a aplicação constrói e executa código (JavaScript, Python, shell, etc.) usando dados não validados fornecidos pelo usuário. O atacante consegue injetar comandos arbitrários que serão executados com os privilégios da aplicação, comprometendo a segurança e integridade do sistema.

Exemplo

Um formulário que avalia expressões matemáticas recebidas do usuário: se a entrada é concatenada direto em um eval() ou equivalente, um atacante pode passar `__import__('os').system('rm -rf /')` em vez de uma expressão legítima, executando comandos do sistema.

Como mitigar

Nunca execute código construído a partir de entrada do usuário. Use parsers/validadores que aceitam apenas formatos esperados (whitelist), sandboxes para execução controlada, ou bibliotecas seguras que não avaliam código dinâmico. Se inevitável, isole rigidamente o ambiente de execução.

CVE-2026-77939HIGHFlextype CMS 1.0.0-dev RCE via POST /api/v1/query EndpointEPSS 0.6%CVE-2024-9837HIGHAADMY – Add Auto Date Month Year Into Posts <= 2.0.1 - Unauthenticated Arbitrary Shortcode ExecutionEPSS 0.6%CVE-2025-52122CRITICALFreeform 5.0.0 to before 5.10.16, a plugin for CraftCMS, contains an Server-side template injection (SSTI) vulnerability, resulting in arbitEPSS 0.6%CVE-2026-24887HIGHClaude Code has a Command Injection in find Command Bypasses User Approval PromptEPSS 0.6%CVE-2026-92127HIGHJenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier automatically approves the classpath entries in an item configuration when EPSS 0.6%CVE-2025-1615MEDIUMFiberHome AN5506-01A ONU GPON NAT Submenu cross site scriptingEPSS 0.6%CVE-2025-9517HIGHatec Debug <= 1.2.22 - Authenticated (Administrator+) Remote Code ExecutionEPSS 0.6%CVE-2024-45198HIGHinsightsoftware Spark JDBC 2.6.21 has a remote code execution vulnerability. Attackers can inject malicious parameters into the JDBC URL, trEPSS 0.6%CVE-2024-48962HIGHApache OFBiz: Bypass SameSite restrictions with target redirection using URL parameters (SSTI and CSRF leading to RCE)EPSS 0.6%CVE-2024-45199HIGHinsightsoftware Hive JDBC through 2.6.13 has a remote code execution vulnerability. Attackers can inject malicious parameters into the JDBC EPSS 0.6%CVE-2023-54345HIGHFrappe Framework ERPNext 13.4.0 Remote Code ExecutionEPSS 0.6%CVE-2024-10899HIGHWooCommerce Product Table Lite <= 3.8.6 - Unauthenticated Arbitrary Shortcode Execution & Reflected Cross-Site ScriptingEPSS 0.6%CVE-2025-66222CRITICALDeepChat Cross-Site Scripting(XSS) escalate to Remote Code Execution(RCE)EPSS 0.6%CVE-2026-21853HIGHAFFiNE: One-click Remote Code Execution through Custom URL HandlingEPSS 0.6%CVE-2024-6946MEDIUMFlute CMS list code injectionEPSS 0.6%CVE-2024-36679CRITICALIn the module "Module Live Chat Pro (All in One Messaging)" (livechatpro) <=8.4.0, a guest can perform PHP Code injection. Due to a predictaEPSS 0.6%CVE-2024-10262MEDIUMDrop Shadow Boxes <= 1.7.14 - Authenticated (Subscriber+) Arbitrary Shortcode ExecutionEPSS 0.6%CVE-2021-23154MEDIUMCommand injection in Lens causes arbitrary shell command execution when malicious custom helm chart configuration providedEPSS 0.6%CVE-2024-55529CRITICALZ-BlogPHP 1.7.3 is vulnerable to arbitrary code execution via \zb_users\theme\shell\template.EPSS 0.6%CVE-2026-64633CRITICALA vulnerability allowing remote unauthenticated code execution on the agent host.EPSS 0.6%