Weaknesses of type CWE-829

209 results

Inclusão de funcionalidade de esfera de controle não confiável

Ocorre quando o software importa, carrega ou executa código, bibliotecas ou componentes originários de uma fonte não confiável ou não verificada. O atacante consegue injetar funcionalidade maliciosa que rodará com os mesmos privilégios da aplicação, comprometendo a integridade e segurança do sistema.

Example

Uma aplicação web baixa dinamicamente um plugin ou módulo de um servidor externo sem validar assinatura criptográfica ou integridade. Um atacante intercepta ou compromete o servidor de origem e substitui o arquivo legítimo por uma versão maliciosa; a aplicação carrega e executa o código comprometido automaticamente.

How to mitigate

Valide sempre a origem, autenticidade e integridade de componentes antes de carregá-los: use assinatura digital criptográfica, checksums verificados, HTTPS com pinning de certificado e, quando possível, evite carregamento dinâmico. Mantenha inventário atualizado de dependências e aplique patches regularmente.

CVE-2018-1122HIGHprocps-ng before version 3.3.15 is vulnerable to a local privilege escalation in top. If a user runs top with HOME unset in an attacker-contEPSS 1.3%CVE-2026-59864CRITICALKiota: Path/URL injection into generated Copilot plugin manifest via x-ai-* extensionsEPSS 1.3%CVE-2019-11770In Eclipse Buildship versions prior to 3.1.1, the build files indicate that this project is resolving dependencies over HTTP instead of HTTPEPSS 1.3%CVE-2021-41256MEDIUMIntent URI permissions manipulation in nextcloud news-androidEPSS 1.1%CVE-2026-44359CRITICALMeshtastic GitHub repo vulnerable to Arbitrary Code Execution via pull_request_target Fork Checkout in CI WorkflowEPSS 1.0%CVE-2023-26053MEDIUMGradle usage of long IDs for PGP keys opens potential for collision attacksEPSS 1.0%CVE-2022-24824MEDIUMAnonymous user cache poisoning in discourseEPSS 1.0%CVE-2026-43999CRITICALvm2: NodeVM builtin allowlist bypass via `module` builtin's `Module._load` allows sandbox escapeEPSS 1.0%CVE-2025-20236HIGHCisco Webex App Client-Side Remote Code Execution VulnerabilityEPSS 0.9%CVE-2022-34468HIGHAn iframe that was not permitted to run scripts could do so if the user clicked on a <code>javascript:</code> link. This vulnerability affecEPSS 0.9%CVE-2026-22208CRITICALOpenS100 Portrayal Engine Unrestricted Lua Standard Library AccessEPSS 0.9%CVE-2021-41037CRITICALIn Eclipse p2, installable units are able to alter the Eclipse Platform installation and the local machine via touchpoints during installatiEPSS 0.8%CVE-2026-43003HIGHAn issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0. Ironic Python Agent (IPA) sometimes executes grub-install froEPSS 0.8%CVE-2026-57102HIGHVisual Studio Code Security Feature Bypass VulnerabilityEPSS 0.8%CVE-2025-62726HIGHn8n Vulnerable to Remote Code Execution via Git Node Pre-Commit HookEPSS 0.8%CVE-2023-0625HIGHDocker Desktop before 4.12.0 is vulnerable to RCE via a crafted extension description or changelogEPSS 0.7%CVE-2023-2453HIGHLocal file Inclusion (LFI) in Forum Infusion via Directory TraversalEPSS 0.7%CVE-2025-8714HIGHPostgreSQL pg_dump lets superuser of origin server execute arbitrary code in psql clientEPSS 0.7%CVE-2022-24119CRITICALCertain General Electric Renewable Energy products have a hidden feature for unauthenticated remote access to the device configuration shellEPSS 0.7%CVE-2023-36609HIGH The affected TBox RTUs run OpenVPN with root privileges and can run user defined configuration scripts. An attacker could set up a local OpEPSS 0.7%