Weaknesses of type CWE-494

187 results

Escalação de Privilégio

É quando um atacante consegue elevar suas permissões no sistema além do que deveria ter acesso — por exemplo, passando de usuário comum para administrador. Acontece porque o software não valida adequadamente quem pode executar certas operações sensíveis, ou confia em dados que podem ser manipulados.

Example

Um aplicativo web que guarda o nível de acesso do usuário em um cookie do lado do cliente (tipo 'role=user') permite que o atacante edite o cookie para 'role=admin' e ganhe acesso a funcionalidades administrativas. Outro caso: um programa Linux que roda com setuid mas não valida argumentos antes de executar comandos do sistema.

How to mitigate

Sempre valide e controle privilégios no servidor/backend, nunca confie em dados do cliente. Use listas de controle de acesso (ACL) ou modelos RBAC bem implementados, e garanta que operações sensíveis exigem reauthenticação ou tokens seguros que não podem ser falsificados.

CVE-2023-5630MEDIUM A CWE-494: Download of Code Without Integrity Check vulnerability exists that could allow a privileged user to install an untrusted firmwEPSS 0.3%CVE-2020-7817MEDIUMMyBrowserPlus downloads the files needed to run the program through the setup file (Setup.inf). At this time, there is a vulnerability in doEPSS 0.3%CVE-2024-28878CRITICALIOSIX IO-1020 Micro ELD Download of Code Without Integrity CheckEPSS 0.3%CVE-2025-7620HIGHDSIC|Cross-browser Components for Official Document Creation - Remote Code ExecutionEPSS 0.3%CVE-2023-45799HIGHMLSoft TCO!stream Remote Code Execution VulnerabilityEPSS 0.3%CVE-2024-39348HIGHDownload of code without integrity check vulnerability in AirPrint functionality in Synology Router Manager (SRM) before 1.2.5-8227-11 and 1EPSS 0.3%CVE-2026-92128HIGHJenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier downloads a JAR file specified by URL twice, confirming the approval of theEPSS 0.3%CVE-2023-41921CRITICALDownload of Code Without Integrity Check in Kiloview P1/P2 devicesEPSS 0.3%CVE-2024-33118HIGHLuckyFrameWeb v3.5.2 was discovered to contain an arbitrary read vulnerability via the fileDownload method in class com.luckyframe.project.cEPSS 0.2%CVE-2026-59286HIGHSpring for GraphQL loads Untrusted Resources in GraphiQL supportEPSS 0.2%CVE-2026-9037CRITICALDownload of code without integrity check in XCharge C6EPSS 0.2%CVE-2022-37908MEDIUMAn authenticated attacker can impact the integrity of the ArubaOS bootloader on 7xxx series controllers. Successful exploitation can compromEPSS 0.2%CVE-2025-1058HIGHCWE-494: Download of Code Without Integrity Check vulnerability exists that could render the device inoperable when malicious firmware is doEPSS 0.2%CVE-2026-49241HIGHAngular: Multiple Remote Code Execution Vulnerabilities in Angular Language Service VS Code ExtensionEPSS 0.2%CVE-2025-55582MEDIUMD-Link DCS-825L firmware v1.08.01 contains a vulnerability in the watchdog script `mydlink-watch-dog.sh`, which blindly respawns binaries suEPSS 0.2%CVE-2025-35115CRITICALAgiloft insecure download of system packagesEPSS 0.2%CVE-2026-45058CRITICALelecterm: Import unsafe bookmark data could lead to unsafe operation when click local type bookmarkEPSS 0.2%CVE-2023-28317MEDIUMA vulnerability has been discovered in Rocket.Chat, where editing messages can change the original timestamp, causing the UI to display messEPSS 0.2%CVE-2026-34841CRITICALAxios npm Supply Chain Incident Impacting @usebruno/cliEPSS 0.2%CVE-2024-55459MEDIUMAn issue in keras 3.7.0 allows attackers to write arbitrary files to the user's machine via downloading a crafted tar file through the get_fEPSS 0.2%