Fallos del tipo CWE-120

3164 resultados

Execução de código ou comandos não autorizados

Fraqueza em que a aplicação executa código ou comandos sem validar adequadamente a origem, permissões ou conteúdo fornecido por um atacante. O perigo está em permitir que um usuário sem privilégios execute operações restritas, como comandos do sistema, funções administrativas ou código arbitrário, comprometendo toda a segurança da aplicação.

Ejemplo

Um painel de controle que permite ao usuário executar scripts de manutenção sem autenticação apropriada, ou uma função que passa entrada do usuário diretamente para eval() em Python/JavaScript, permitindo injeção de código malicioso que roda com as permissões da aplicação.

Cómo mitigar

Implemente validação rigorosa de entrada, use allowlists (não blacklists), mantenha controle de acesso baseado em roles (RBAC) com verificação em cada operação sensível, e evite construtores dinâmicos como eval(). Quando precisar executar comandos do sistema, use APIs seguras e nunca passe entrada do usuário sem sanitização completa.

CVE-2024-42545CRITICALTOTOLINK A3700R v9.1.2u.5822_B20200513 has a buffer overflow vulnerability in the ssid parameter in setWizardCfg function.EPSS 0.7%CVE-2025-5665MEDIUMFreeFloat FTP Server XCWD Command buffer overflowEPSS 0.7%CVE-2024-34198CRITICALTOTOLINK AC1200 Wireless Router A3002RU V2.1.1-B20230720.1011 is vulnerable to Buffer Overflow. The formWlEncrypt CGI handler in the boa proEPSS 0.7%CVE-2025-5595MEDIUMFreeFloat FTP Server PROGRESS Command buffer overflowEPSS 0.7%CVE-2024-5412HIGHA buffer overflow vulnerability in the library "libclinkc" of the Zyxel VMG8825-T50K firmware version 5.50(ABOM.8)C0 could allow an unauthenEPSS 0.7%CVE-2025-5666MEDIUMFreeFloat FTP Server XMKD Command buffer overflowEPSS 0.7%CVE-2025-5664MEDIUMFreeFloat FTP Server RESTART Command buffer overflowEPSS 0.7%CVE-2025-9812HIGHTenda CH22 exeCommand formexeCommand buffer overflowEPSS 0.7%CVE-2026-2139HIGHTenda TX9 fast_setting_wifi_set sub_432580 buffer overflowEPSS 0.7%CVE-2026-30075HIGHOpenAirInterface Version 2.2.0 has a Buffer Overflow vulnerability in processing UplinkNASTransport containing Authentication Response contaEPSS 0.7%CVE-2022-4857MEDIUMModbus Tools Modbus Poll mbp File mbpoll.exe buffer overflowEPSS 0.7%CVE-2026-93741CRITICALTotolink A3002MU formWlWds buffer overflowEPSS 0.7%CVE-2023-26109HIGHAll versions of the package node-bluetooth-serial-port are vulnerable to Buffer Overflow via the findSerialPortChannel method due to impropeEPSS 0.7%CVE-2024-10964MEDIUMemqx neuron plugin_handle.c handle_add_plugin buffer overflowEPSS 0.7%CVE-2026-82772HIGHBuffer overflow vulnerability exists in Contec EC1000 series. If a remote attacker sends a specially crafted request to the product's web seEPSS 0.7%CVE-2026-82770HIGHBuffer overflow vulnerability exists in Contec RP-WAH-SR Series. If a remote attacker sends a specially crafted request to the product's webEPSS 0.7%CVE-2026-27942LOWfast-xml-parser has stack overflow in XMLBuilder with preserveOrderEPSS 0.7%CVE-2023-22416HIGHJunos OS: MX Series and SRX Series: The flow processing daemon (flowd) will crash if SIP ALG is enabled and a malformed SIP packet is receivedEPSS 0.7%CVE-2024-49778HIGHA heap-based buffer overflow in tsMuxer version nightly-2024-05-12-02-01-18 allows attackers to cause Denial of Service (DoS) and Code ExecuEPSS 0.7%CVE-2024-21274HIGHVulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions that are affected EPSS 0.7%