Fallos del tipo CWE-120

3166 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2025-48724LOWQsync CentralEPSS 0.4%CVE-2025-28025HIGHTOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 werEPSS 0.4%CVE-2025-28020HIGHTOTOLINK A800R V4.1.2cu.5137_B20200730 was found to contain a buffer overflow vulnerability in downloadFile.cgi through the v25 parameter.EPSS 0.4%CVE-2025-28028HIGHTOTOLINK A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5185_B20201128, and A3100R V4.1.2cu.5247_B20211129 werEPSS 0.4%CVE-2025-14310CRITICALBuffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in rethinkdb.This issue affects rethinkdb: before 2.4.4EPSS 0.4%CVE-2025-52870LOWQsync CentralEPSS 0.4%CVE-2024-34727HIGHIn sdpu_compare_uuid_with_attr of sdp_utils.cc, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remEPSS 0.4%CVE-2024-37040MEDIUMCWE-120: Buffer Copy without Checking Size of Input (‘Classic Buffer Overflow’) vulnerability exists that could allow a user with access to EPSS 0.4%CVE-2024-4640HIGHOnCell G3470A-LTE Series: Authenticated Command Injection via sendTestEmailEPSS 0.4%CVE-2025-28021HIGHTOTOLINK A810R V4.1.2cu.5182_B20201026 was found to contain a buffer overflow vulnerability in the downloadFile.cgi through the v14 and v3 pEPSS 0.4%CVE-2025-48723LOWQsync CentralEPSS 0.4%CVE-2025-28022HIGHTOTOLINK A810R V4.1.2cu.5182_B20201026 was found to contain a buffer overflow vulnerability in downloadFile.cgi through the v25 parameter.EPSS 0.4%CVE-2025-26240HIGHIn JazzCore python-pdfkit 1.0.0, the from_string method enables the execution of JavaScript code within the context of the server applicatioEPSS 0.4%CVE-2025-34106HIGHPDF Shaper v3.5/3.6 Buffer Overflow via Convert to Image FeatureEPSS 0.4%CVE-2023-51367MEDIUMQTS, QuTS heroEPSS 0.4%CVE-2024-48712MEDIUMIn TP-Link TL-WDR7660 1.0, the rtRuleJsonToBin function handles the parameter string name without checking it, which can lead to stack overfEPSS 0.4%CVE-2024-50839MEDIUMA Stored Cross-Site Scripting (XSS) vulnerability was found in /admin/add_subject.php in KASHIPARA E-learning Management System Project 1.0.EPSS 0.4%CVE-2025-52221HIGHTenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetCfm function via the funcname, funcpara1, and funcpara2 parameterEPSS 0.4%CVE-2023-33025CRITICALBuffer Copy without Checking Size of Input in Data ModemEPSS 0.4%CVE-2024-10559MEDIUMSourceCodester Airport Booking Management System details buffer overflowEPSS 0.4%