Fallos del tipo CWE-120

3164 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2023-32674CRITICALCertain versions of HP PC Hardware Diagnostics Windows are potentially vulnerable to buffer overflow.EPSS 0.9%CVE-2025-6939HIGHTOTOLINK A3002RU HTTP POST Request formWlSiteSurvey buffer overflowEPSS 0.9%CVE-2023-4582HIGHBuffer Overflow in WebGL glGetProgramivEPSS 0.9%CVE-2021-21969LOWAn out-of-bounds write vulnerability exists in the HandleSeaCloudMessage functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. ThEPSS 0.9%CVE-2025-0960CRITICALAutomationDirect C-more EA9 HMI Classic Buffer OverflowEPSS 0.9%CVE-2026-30650HIGHA post-authentication remote buffer overflow vulnerability exists in the /cgi-bin/admin/eventtask.cgi endpoint of the admin interface of VivEPSS 0.9%CVE-2022-39343MEDIUMAzure RTOS FileX vulnerable to Buffer OfferflowEPSS 0.9%CVE-2021-21970LOWAn out-of-bounds write vulnerability exists in the HandleSeaCloudMessage functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. ThEPSS 0.9%CVE-2022-34886HIGHA remote code execution vulnerability was found in the firmware used in some Lenovo printers, which can be caused by a remote user pushing aEPSS 0.9%CVE-2026-2067HIGHUTT 进取 520W formTimeGroupConfig strcpy buffer overflowEPSS 0.9%CVE-2023-43010HIGHThe issue was addressed with improved memory handling. This issue is fixed in iOS 17.2 and iPadOS 17.2, macOS Sonoma 14.2, Safari 17.2, iOS EPSS 0.9%CVE-2026-93740CRITICALTotolink A3002MU formWlEncrypt buffer overflowEPSS 0.9%CVE-2025-20115HIGHCisco IOS XR Software Border Gateway Protocol Denial of Service VulnerabilityEPSS 0.9%CVE-2025-1895HIGHTenda TX3 setMacFilterCfg buffer overflowEPSS 0.9%CVE-2026-27459HIGHpyOpenSSL DTLS cookie callback buffer overflowEPSS 0.9%CVE-2023-49208CRITICALscheme/webauthn.c in Glewlwyd SSO server before 2.7.6 has a possible buffer overflow during FIDO2 credentials validation in webauthn registrEPSS 0.9%CVE-2023-22917HIGHA buffer overflow vulnerability in the “sdwan_iface_ipc” binary of Zyxel ATP series firmware versions 5.10 through 5.32, USG FLEX series firEPSS 0.9%CVE-2019-16536HIGHStack overflow leading to DoS can be triggered by a malicious authenticated client.EPSS 0.9%CVE-2025-13288HIGHTenda CH22 PPTPUserSetting fromPptpUserSetting buffer overflowEPSS 0.9%CVE-2024-48406CRITICALBuffer Overflow vulnerability in SunBK201 umicat through v.0.3.2 and fixed in v.0.3.3 allows an attacker to execute arbitrary code via the pEPSS 0.9%