Fallos del tipo CWE-120

3166 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2026-24110CRITICALAn issue was discovered in Tenda W20E V4.0br_V15.11.0.6. Attackers may send overly long `addDhcpRules` data. When these rules enter the `addEPSS 0.4%CVE-2019-10882MEDIUMNetskope client buffer overflow vulnerabilityEPSS 0.4%CVE-2024-50840MEDIUMA Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/class.php in KASHIPARA E-learning Management System Project 1.0. This EPSS 0.4%CVE-2024-25253HIGHDriver Booster v10.6 was discovered to contain a buffer overflow via the Host parameter under the Customize proxy module.EPSS 0.4%CVE-2024-46591HIGHDraytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sDnsPro parameter at v2x00.cgi. This vulnerability allows attEPSS 0.4%CVE-2024-46590HIGHDraytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the ssidencrypt%d parameter at v2x00.cgi. This vulnerability alloEPSS 0.4%CVE-2024-46568HIGHDraytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sPeerId parameter at vpn.cgi. This vulnerability allows attacEPSS 0.4%CVE-2024-36760HIGHA stack overflow vulnerability was found in version 1.18.0 of rhai. The flaw position is: (/ SRC/rhai/SRC/eval/STMT. Rs in rhai: : eval: : SEPSS 0.4%CVE-2024-46598HIGHDraytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the iprofileidx parameter at dialin.cgi. This vulnerability allowEPSS 0.4%CVE-2024-46592HIGHDraytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the ssidencrypt_5g%d parameter at v2x00.cgi. This vulnerability aEPSS 0.4%CVE-2024-46580HIGHDraytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the fid parameter at v2x00.cgi. This vulnerability allows attackeEPSS 0.4%CVE-2026-4720CRITICALMemory safety bugs fixed in Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149EPSS 0.4%CVE-2024-46571HIGHDraytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sPPPSrvNm parameter at fwuser.cgi. This vulnerability allows EPSS 0.4%CVE-2026-4721CRITICALMemory safety bugs fixed in Firefox ESR 115.34, Firefox ESR 140.9, Thunderbird ESR 140.9, Firefox 149 and Thunderbird 149EPSS 0.4%CVE-2020-37189MEDIUMTaskCanvas 1.4.0 - 'Registration' Denial Of ServiceEPSS 0.4%CVE-2024-56805MEDIUMQTS, QuTS heroEPSS 0.4%CVE-2024-25115HIGHRedisBloom heap buffer overflow in CF.LOADCHUNK commandEPSS 0.4%CVE-2025-50399CRITICALFAST FAC1200R F400_FAC1200R_Q is vulnerable to Buffer Overflow in the function sub_80435780 via the parameter password.EPSS 0.4%CVE-2026-7300HIGHBuffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Web Integration Service) allows Filter Failure through Buffer Overflow.EPSS 0.4%CVE-2025-50402CRITICALFAST FAC1200R F400_FAC1200R_Q is vulnerable to Buffer Overflow in the function sub_80435780 via the parameter string fac_password.EPSS 0.4%