Weaknesses of type CWE-494

187 results

Escalação de Privilégio

É quando um atacante consegue elevar suas permissões no sistema além do que deveria ter acesso — por exemplo, passando de usuário comum para administrador. Acontece porque o software não valida adequadamente quem pode executar certas operações sensíveis, ou confia em dados que podem ser manipulados.

Example

Um aplicativo web que guarda o nível de acesso do usuário em um cookie do lado do cliente (tipo 'role=user') permite que o atacante edite o cookie para 'role=admin' e ganhe acesso a funcionalidades administrativas. Outro caso: um programa Linux que roda com setuid mas não valida argumentos antes de executar comandos do sistema.

How to mitigate

Sempre valide e controle privilégios no servidor/backend, nunca confie em dados do cliente. Use listas de controle de acesso (ACL) ou modelos RBAC bem implementados, e garanta que operações sensíveis exigem reauthenticação ou tokens seguros que não podem ser falsificados.

CVE-2026-42249HIGHRemote Code Execution in Ollama via Update MechanismEPSS 0.6%CVE-2023-39474HIGHInductive Automation Ignition downloadLaunchClientJar Remote Code Execution VulnerabilityEPSS 0.6%CVE-2020-7873HIGHDownload of code without integrity check vulnerability in ActiveX control of Younglimwon Co., Ltd allows the attacker to cause a arbitrary fEPSS 0.6%CVE-2019-3801HIGHJava Projects using HTTP to fetch dependenciesEPSS 0.6%CVE-2020-7874HIGHNEXACRO14 Runtime arbitrary file download and execution vulnerabilityEPSS 0.6%CVE-2023-23110HIGHAn exploitable firmware modification vulnerability was discovered in certain Netgear products. The data integrity of the uploaded firmware iEPSS 0.6%CVE-2018-14620MEDIUMThe OpenStack RabbitMQ container image insecurely retrieves the rabbitmq_clusterer component over HTTP during the build stage. This could poEPSS 0.6%CVE-2020-22658CRITICALIn Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, RuckusEPSS 0.5%CVE-2026-2999CRITICALChanging|IDExpert Windows Logon Agent - Remote Code ExecutionEPSS 0.5%CVE-2026-3000CRITICALChanging|IDExpert Windows Logon Agent - Remote Code ExecutionEPSS 0.5%CVE-2020-9751Naver Cloud Explorer before 2.2.2.11 allows the system to download an arbitrary file from the attacker's server and execute it during the upEPSS 0.5%CVE-2019-10248Eclipse Vorto versions prior to 0.11 resolved Maven build artifacts for the Xtext project over HTTP instead of HTTPS. Any of these dependentEPSS 0.5%CVE-2024-30205HIGHIn Emacs before 29.3, Org mode considers contents of remote files to be trusted. This affects Org Mode before 9.6.23.EPSS 0.5%CVE-2020-29032HIGHAdd integrity check of GateManager firmwareEPSS 0.5%CVE-2025-63215HIGHThe Sound4 IMPACT web-based management interface is vulnerable to Remote Code Execution (RCE) via a malicious firmware update package. The uEPSS 0.5%CVE-2025-63220HIGHThe Sound4 FIRST web-based management interface is vulnerable to Remote Code Execution (RCE) via a malicious firmware update package. The upEPSS 0.5%CVE-2021-26639HIGHWISA Smart Wing CMS File Download VulnerabilityEPSS 0.5%CVE-2026-25961HIGHSumatraPDF Update MITM -> Arbitrary Code ExecutionEPSS 0.5%CVE-2025-56513CRITICALNiceHash QuickMiner 6.12.0 perform software updates over HTTP without validating digital signatures or hash checks. An attacker capable of iEPSS 0.4%CVE-2025-11182HIGHFile Download in GTONE ChangeFlowEPSS 0.4%