Fallos del tipo CWE-120

3166 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2021-34776MEDIUMCisco Small Business 220 Series Smart Switches Link Layer Discovery Protocol VulnerabilitiesEPSS 0.4%CVE-2025-60337HIGHTenda AC6 V2.0 15.03.06.50 was discovered to contain a buffer overflow in the speed_dir parameter in the SetSpeedWan function. This vulnerabEPSS 0.4%CVE-2025-50608HIGHA buffer overflow vulnerability has been discovered in Netis WF2880 v2.1.40207 in the FUN_00471994 function of the cgitest.cgi file. AttackeEPSS 0.4%CVE-2021-34775MEDIUMCisco Small Business 220 Series Smart Switches Link Layer Discovery Protocol VulnerabilitiesEPSS 0.4%CVE-2021-34777MEDIUMCisco Small Business 220 Series Smart Switches Link Layer Discovery Protocol VulnerabilitiesEPSS 0.4%CVE-2024-48416HIGHEdimax AC1200 Wi-Fi 5 Dual-Band Router BR-6476AC 1.06 is vulnerable to Buffer Overflow via /goform/fromSetLanDhcpsClientbinding.EPSS 0.4%CVE-2020-37187MEDIUMSpotDialup 1.6.7 - 'Name' Denial of ServiceEPSS 0.4%CVE-2020-37188MEDIUMSpotOutlook 1.2.6 - 'Name' Denial of ServiceEPSS 0.4%CVE-2025-50673HIGHA buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the http_lanport parameter in the /webgl.aspEPSS 0.4%CVE-2025-50668HIGHA buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the s parameter in the /web_list_opt.asp endEPSS 0.4%CVE-2025-23412HIGHBIG-IP APM access profile vulnerabilityEPSS 0.4%CVE-2024-5463MEDIUMA vulnerability regarding buffer copy without checking the size of input ('Classic Buffer Overflow') has been found in the login component. EPSS 0.4%CVE-2024-53319HIGHA heap buffer overflow in the XML Text Escaping component of Qualisys C++ SDK commit a32a21a allows attackers to cause Denial of Service (DoEPSS 0.4%CVE-2025-60340HIGHMultiple buffer overflows in the SetClientState function of Tenda AC6 v.15.03.06.50 allows attackers to cause a Denial of Service (DoS) via EPSS 0.4%CVE-2024-52016MEDIUMNetgear R8500 v1.0.2.160, XR300 v1.0.3.78, R7000P v1.3.3.154, and R6400 v2 1.0.4.128 were discovered to multiple stack overflow vulnerabilitEPSS 0.4%CVE-2025-60343HIGHMultiple buffer overflows in the AdvSetMacMtuWan function of Tenda AC6 v.15.03.06.50 allows attackers to cause a Denial of Service (DoS) viaEPSS 0.4%CVE-2024-22526MEDIUMBuffer Overflow vulnerability in bandisoft bandiview v7.0, allows local attackers to cause a denial of service (DoS) via exr image file.EPSS 0.4%CVE-2025-65834CRITICALMeltytech Shotcut 25.10.31 is vulnerable to Buffer Overflow. A memory access violation occurs when processing MLT project files with manipulEPSS 0.4%CVE-2025-60339HIGHMultiple buffer overflow vulnerabilities in the openSchedWifi function of Tenda AC6 v.15.03.06.50 allows attackers to cause a Denial of ServEPSS 0.4%CVE-2021-47797MEDIUMLeawo Prof. Media 11.0.0.1 - Denial of Service (DoS) (PoC)EPSS 0.4%