Fallos del tipo CWE-120

3164 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2025-13553HIGHD-Link DWR-M920 formPinManageSetup sub_41C7FC buffer overflowEPSS 0.7%CVE-2025-15215HIGHTenda AC10U HTTP POST Request setPptpUserList formSetPPTPUserList buffer overflowEPSS 0.7%CVE-2026-51380CRITICALBuffer Overflow vulnerability in Tenda AC10 v3 (firmware V03.03.16.09) allows attackers to cause a permanent Denial of Service (DoS) or poteEPSS 0.7%CVE-2023-51771CRITICALIn MicroHttpServer (aka Micro HTTP Server) through a8ab029, _ParseHeader in lib/server.c allows a one-byte recv buffer overflow via a long UEPSS 0.7%CVE-2025-5357MEDIUMFreeFloat FTP Server PWD Command buffer overflowEPSS 0.7%CVE-2025-5052MEDIUMFreeFloat FTP Server LS Command buffer overflowEPSS 0.7%CVE-2025-5074MEDIUMFreeFloat FTP Server PROMPT Command buffer overflowEPSS 0.7%CVE-2025-4240MEDIUMPCMan FTP Server LCD Command buffer overflowEPSS 0.7%CVE-2025-5053MEDIUMFreeFloat FTP Server MDIR Command buffer overflowEPSS 0.7%CVE-2026-22861HIGHiccDEV has a heap-buffer-overflow in SIccCalcOp::Describe() at IccProfLib/IccMpeCalc.cppEPSS 0.7%CVE-2025-5217MEDIUMFreeFloat FTP Server RMDIR Command buffer overflowEPSS 0.7%CVE-2025-4254MEDIUMPCMan FTP Server LIST Command buffer overflowEPSS 0.7%CVE-2025-5051MEDIUMFreeFloat FTP Server BINARY Command buffer overflowEPSS 0.7%CVE-2025-5219MEDIUMFreeFloat FTP Server ASCII Command buffer overflowEPSS 0.7%CVE-2025-4290MEDIUMPCMan FTP Server SMNT Command buffer overflowEPSS 0.7%CVE-2025-4251MEDIUMPCMan FTP Server RMDIR Command buffer overflowEPSS 0.7%CVE-2025-4238MEDIUMPCMan FTP Server MGET Command buffer overflowEPSS 0.7%CVE-2025-4845MEDIUMFreeFloat FTP Server TRACE Command buffer overflowEPSS 0.7%CVE-2025-5356MEDIUMFreeFloat FTP Server BYE Command buffer overflowEPSS 0.7%CVE-2025-5221MEDIUMFreeFloat FTP Server QUOTE Command buffer overflowEPSS 0.7%