Weaknesses of type CWE-494

187 results

Escalação de Privilégio

É quando um atacante consegue elevar suas permissões no sistema além do que deveria ter acesso — por exemplo, passando de usuário comum para administrador. Acontece porque o software não valida adequadamente quem pode executar certas operações sensíveis, ou confia em dados que podem ser manipulados.

Example

Um aplicativo web que guarda o nível de acesso do usuário em um cookie do lado do cliente (tipo 'role=user') permite que o atacante edite o cookie para 'role=admin' e ganhe acesso a funcionalidades administrativas. Outro caso: um programa Linux que roda com setuid mas não valida argumentos antes de executar comandos do sistema.

How to mitigate

Sempre valide e controle privilégios no servidor/backend, nunca confie em dados do cliente. Use listas de controle de acesso (ACL) ou modelos RBAC bem implementados, e garanta que operações sensíveis exigem reauthenticação ou tokens seguros que não podem ser falsificados.

CVE-2019-10240Eclipse hawkBit versions prior to 0.3.0M2 resolved Maven build artifacts for the Vaadin based UI over HTTP instead of HTTPS. Any of these deEPSS 0.4%CVE-2025-69263HIGHpnpm Lockfile Integrity Bypass Allows Remote Dynamic DependenciesEPSS 0.4%CVE-2023-37864HIGHPHOENIX CONTACT: WP 6xxx Web panels prone to download code without integrity checkEPSS 0.4%CVE-2026-85427CRITICALMOOS essential-moos through 10.0.1 pAntler Remote Code Execution via Unauthenticated MISSION_FILEEPSS 0.4%CVE-2025-27593CRITICALRCE due to Device DriverEPSS 0.4%CVE-2019-14845MEDIUMA vulnerability was found in OpenShift builds, versions 4.1 up to 4.3. Builds that extract source from a container image, bypass the TLS hosEPSS 0.4%CVE-2026-40066HIGHAnviz Products Download of Code Without Integrity CheckEPSS 0.4%CVE-2025-28236CRITICALNautel VX Series transmitters VX SW v6.4.0 and below was discovered to contain a remote code execution (RCE) vulnerability in the firmware uEPSS 0.4%CVE-2019-19166HIGHTobesoft XPlatform Arbitrary File Execution VulnerabilityEPSS 0.4%CVE-2022-46423HIGHAn exploitable firmware modification vulnerability was discovered on the Netgear WNR2000v1 router. An attacker can conduct a MITM (Man-in-thEPSS 0.4%CVE-2023-27574ShadowsocksX-NG 1.10.0 signs with com.apple.security.get-task-allow entitlements because of CODE_SIGNING_INJECT_BASE_ENTITLEMENTS.EPSS 0.4%CVE-2026-42248HIGHMissing Signature Verification for Updates in OllamaEPSS 0.4%CVE-2025-14265CRITICALImproper server-side validation in ScreenConnect extension frameworkEPSS 0.4%CVE-2022-24117CRITICALCertain General Electric Renewable Energy products download firmware without an integrity check. This affects iNET and iNET II before 8.3.0,EPSS 0.4%CVE-2025-57431HIGHThe Sound4 PULSE-ECO AES67 1.22 web-based management interface is vulnerable to Remote Code Execution (RCE) via a malicious firmware update EPSS 0.3%CVE-2026-48046CRITICALStreambert Vulnerable to Remote Code Execution (RCE) via Unvalidated Auto-Updater IPC HandlerEPSS 0.3%CVE-2020-22654CRITICALIn Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, RuckusEPSS 0.3%CVE-2022-46430MEDIUMTP-Link TL-WR740N V1 and V2 v3.12.4 and earlier allows authenticated attackers to execute arbitrary code or cause a Denial of Service (DoS) EPSS 0.3%CVE-2022-46428MEDIUMTP-Link TL-WR1043ND V1 3.13.15 and earlier allows authenticated attackers to execute arbitrary code or cause a Denial of Service (DoS) via uEPSS 0.3%CVE-2023-27025HIGHAn arbitrary file download vulnerability in the background management module of RuoYi v4.7.6 and below allows attackers to download arbitrarEPSS 0.3%