Fallos del tipo CWE-120

3165 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2024-50838MEDIUMA Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/department.php in KASHIPARA E-learning Management System Project 1.0. EPSS 0.5%CVE-2022-40514CRITICALBuffer copy without checking size of input in WLAN FirmwareEPSS 0.5%CVE-2023-52729HIGHTCPServer.cpp in SimpleNetwork through 29bc615 has an off-by-one error that causes a buffer overflow when trying to add '\0' to the end of lEPSS 0.5%CVE-2020-10023MEDIUMShell Subsystem Contains a Buffer Overflow Vulnerability In shell_spaces_trimEPSS 0.5%CVE-2025-66287HIGHWebkitgtk: processing maliciously crafted web content may lead to an unexpected process crashEPSS 0.5%CVE-2023-33045CRITICALBuffer Copy Without Checking Size of Input in WLAN FirmwareEPSS 0.5%CVE-2024-46431HIGHTenda W18E V16.01.0.8(1625) is vulnerable to Buffer Overflow. An attacker with access to the web management portal can exploit this vulnerabEPSS 0.5%CVE-2024-23968HIGHChargePoint Home Flex SrvrToSmSetAutoChnlListMsg Stack-based Buffer OverflowEPSS 0.5%CVE-2023-27892LOWInsufficient length checks in the ShapeShift KeepKey hardware wallet firmware before 7.7.0 allow a global buffer overflow via crafted messagEPSS 0.5%CVE-2022-26527MEDIUMRealtek Linux/Android Bluetooth Mesh SDK - Buffer OverflowEPSS 0.5%CVE-2022-26529MEDIUMRealtek Linux/Android Bluetooth Mesh SDK - Buffer OverflowEPSS 0.5%CVE-2022-26528MEDIUMRealtek Linux/Android Bluetooth Mesh SDK - Buffer OverflowEPSS 0.5%CVE-2026-19999MEDIUMOpen Asset Import Library Assimp 3DGS MDL7 Bone Transformation Key MDLLoader.cpp ParseBoneTrafoKeys_3DGS_MDL7 buffer overflowEPSS 0.5%CVE-2026-64691CRITICALA buffer overflow was addressed with improved size validation. This issue is fixed in macOS Tahoe 26.6. An app may be able to cause unexpectEPSS 0.5%CVE-2022-48260HIGHThere is a buffer overflow vulnerability in BiSheng-WNM FW 3.0.0.325. Successful exploitation could lead to device service exceptions.EPSS 0.5%CVE-2025-50652HIGHAn issue in D-Link DI-8003 16.07.26A1 related to improper handling of the id parameter in the /saveparm_usb.asp endpoint.EPSS 0.5%CVE-2024-35400MEDIUMTOTOLINK CP900L v4.1.5cu.798_B20221228 was discovered to contain a stack overflow via the desc parameter in the function SetPortForwardRulesEPSS 0.5%CVE-2020-21428LOWBuffer Overflow vulnerability in function LoadRGB in PluginDDS.cpp in FreeImage 3.18.0 allows remote attackers to run arbitrary code and cauEPSS 0.5%CVE-2026-4729CRITICALMemory safety bugs fixed in Firefox 149 and Thunderbird 149EPSS 0.5%CVE-2024-25254CRITICALSuperScan v4.1 was discovered to contain a buffer overflow via the Hostname/IP parameter.EPSS 0.5%