Fallos del tipo CWE-120

3164 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2024-57471CRITICALH3C N12 V100R005 contains a buffer overflow vulnerability due to the lack of length verification in the 2.4G wireless network processing funEPSS 0.8%CVE-2025-14526HIGHTenda CH22 L7Im frmL7ImForm buffer overflowEPSS 0.8%CVE-2026-15314HIGHAuthenticated Denial-of-Service Vulnerability in TP-Link Tapo P110EPSS 0.8%CVE-2023-50361MEDIUMQTS, QuTS heroEPSS 0.8%CVE-2024-0762HIGHPotential buffer overflow when handling UEFI variablesEPSS 0.8%CVE-2025-6882HIGHD-Link DIR-513 formSetWanPPTP buffer overflowEPSS 0.8%CVE-2025-43213MEDIUMThe issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOEPSS 0.8%CVE-2023-38671HIGHHeap buffer overflow in paddle.traceEPSS 0.8%CVE-2025-13551HIGHD-Link DIR-822K/DWR-M920 formWanConfigSetup buffer overflowEPSS 0.8%CVE-2026-1140HIGHUTT 进取 520W ConfigExceptAli strcpy buffer overflowEPSS 0.8%CVE-2025-13552HIGHD-Link DIR-822K/DWR-M920 formWlEncrypt buffer overflowEPSS 0.8%CVE-2026-30652HIGHA remote buffer overflow vulnerability exists in the /cgi-bin/dido/setdo.cgi endpoint of the admin interface of Vivotek FD8136 cameras runniEPSS 0.8%CVE-2025-13550HIGHD-Link DIR-822K/DWR-M920 formVpnConfigSetup buffer overflowEPSS 0.8%CVE-2010-10016CRITICALBS.Player 2.57 Buffer Overflow via M3U Playlist ImportEPSS 0.8%CVE-2026-76691HIGHAuthenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in HPE Networking EdgeConnect SD-WAN Gateway API EndpointEPSS 0.8%CVE-2026-10126HIGHEdimax BR-6478AC POST Request formQoS buffer overflowEPSS 0.8%CVE-2026-44880HIGHLow-Privilege Authenticated Buffer Overflow Vulnerabilities lead to Remote Code Execution in AOS-CXEPSS 0.8%CVE-2024-20451HIGHMultiple vulnerabilities in the web-based management interface of Cisco Small Business SPA300 Series IP Phones and Cisco Small Business SPA5EPSS 0.8%CVE-2026-27820LOWzlib: Buffer Overflow in Zlib::GzipReader ungetc via large input leads to memory corruptionEPSS 0.8%CVE-2025-11323HIGHUTT 1250GW formUserStatusRemark strcpy buffer overflowEPSS 0.8%