Fallos del tipo CWE-120

3166 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2025-48386MEDIUMGit allows a buffer overflow in 'wincred' credential helperEPSS 0.4%CVE-2023-25664HIGHTensorFlow vulnerable to Heap Buffer Overflow in AvgPoolGrad EPSS 0.4%CVE-2023-40166MEDIUMNotepad++ heap buffer read overflow in FileManager::detectLanguageFromTextBegining EPSS 0.4%CVE-2023-1560LOWTinyTIFF File tinytiffreader.c buffer overflowEPSS 0.4%CVE-2025-52869LOWQsync CentralEPSS 0.4%CVE-2025-48725LOWQuTS heroEPSS 0.4%CVE-2025-55605CRITICALTenda AX3 V16.03.12.10_CN is vulnerable to Buffer Overflow in the saveParentControlInfo function via the deviceName parameter.EPSS 0.4%CVE-2025-50667HIGHA buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the iface parameter in the /wan_line_detectiEPSS 0.4%CVE-2024-48420HIGHEdimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 is vulnerable to Buffer Overflow via /goform/getWifiBasic.EPSS 0.4%CVE-2025-60548CRITICALD-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formLanSetupRouterSettingEPSS 0.4%CVE-2025-55603CRITICALTenda AX3 V16.03.12.10_CN is vulnerable to Buffer Overflow in the fromSetSysTime function via the ntpServer parameter.EPSS 0.4%CVE-2025-36557HIGHBIG-IP HTTP vulnerabilityEPSS 0.4%CVE-2025-60553CRITICALD-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetWAN_Wizard52.EPSS 0.4%CVE-2025-60554CRITICALD-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formSetEnableWizard.EPSS 0.4%CVE-2025-50669HIGHA buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 and DI-8003G 19.12.10A1 due to improper handling of the wan_ping parametEPSS 0.4%CVE-2025-55606CRITICALTenda AX3 V16.03.12.10_CN is vulnerable to Buffer Overflow in the fromAdvSetMacMtuWan function via the serverName parameter.EPSS 0.4%CVE-2025-50672HIGHA buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /yyxz_dlink.asp endpoint.EPSS 0.4%CVE-2020-37155MEDIUMCore FTP Lite 1.3 - Denial of Service (PoC)EPSS 0.4%CVE-2021-34778MEDIUMCisco Small Business 220 Series Smart Switches Link Layer Discovery Protocol VulnerabilitiesEPSS 0.4%CVE-2025-50608HIGHA buffer overflow vulnerability has been discovered in Netis WF2880 v2.1.40207 in the FUN_00471994 function of the cgitest.cgi file. AttackeEPSS 0.4%