Fallos del tipo CWE-120

3164 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2025-5905HIGHTOTOLINK T10 POST Request cstecgi.cgi setWiFiRepeaterCfg buffer overflowEPSS 11.3%CVE-2023-20189HIGHCisco Small Business Series Switches Buffer Overflow VulnerabilitiesEPSS 11.1%CVE-2025-5904HIGHTOTOLINK T10 POST Request cstecgi.cgi setWiFiMeshName buffer overflowEPSS 11.0%CVE-2025-5903HIGHTOTOLINK T10 POST Request cstecgi.cgi setWiFiAclRules buffer overflowEPSS 11.0%CVE-2024-7463HIGHTOTOLINK CP900 cstecgi.cgi UploadCustomModule buffer overflowEPSS 11.0%CVE-2019-5064HIGHAn exploitable heap buffer overflow vulnerability exists in the data structure persistence functionality of OpenCV, before version 4.2.0. A EPSS 10.7%CVE-2020-15069CRITICALSophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientlesEPSS 10.7%KEVCVE-2023-20160HIGHCisco Small Business Series Switches Buffer Overflow VulnerabilitiesEPSS 10.3%CVE-2023-20159HIGHCisco Small Business Series Switches Buffer Overflow VulnerabilitiesEPSS 10.3%CVE-2023-20161HIGHCisco Small Business Series Switches Buffer Overflow VulnerabilitiesEPSS 10.3%CVE-2022-23747—In Sony Xperia series 1, 5, and Pro, an out of bound memory access can occur due to lack of validation of the number of frames being passed EPSS 10.2%CVE-2023-29468CRITICALThe Texas Instruments (TI) WiLink WL18xx MCP driver does not limit the number of information elements (IEs) of type XCC_EXT_1_IE_ID or XCC_EEPSS 10.1%CVE-2025-9961HIGHAuthenticated RCE by CWMP binaryEPSS 9.8%CVE-2024-37357CRITICALA buffer overflow vulnerability exists in the adm.cgi set_TR069() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTEPSS 9.7%CVE-2022-45672HIGHTenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the formWx3AuthorizeSet function.EPSS 9.1%CVE-2023-50991HIGHBuffer Overflow vulnerability in Tenda i29 versions 1.0 V1.0.0.5 and 1.0 V1.0.0.2, allows remote attackers to cause a denial of service (DoSEPSS 8.8%CVE-2022-41966HIGHXStream Denial of Service via stack overflow EPSS 8.8%CVE-2021-3466—A flaw was found in libmicrohttpd. A missing bounds check in the post_process_urlencoded function leads to a buffer overflow, allowing a remEPSS 8.7%CVE-2020-7593—A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (V1.81.01 - V1.81.03), LOGO! 8 BM (incl. SIPLUS variants) (V1.82.0EPSS 8.7%CVE-2021-28580HIGHMedium by Adobe file parsing buffer overflow vulnerability could lead to arbitrary code executionEPSS 8.5%