Fallos del tipo CWE-20

5423 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2024-3029CRITICALImproper Input Validation in mintplex-labs/anything-llmEPSS 0.7%CVE-2023-27488MEDIUMEnvoy gRPC client produces invalid protobuf when an HTTP header with non-UTF8 value is received.EPSS 0.7%CVE-2026-22444HIGHApache Solr: Insufficient file-access checking in standalone core-creation requestsEPSS 0.7%CVE-2025-2622MEDIUMaizuda snail-job Workflow-Task Management Module check-node-expression getRuntime deserializationEPSS 0.7%CVE-2026-48769CRITICALIncus has an arbitrary file write on its client due to trusted image hashEPSS 0.7%CVE-2022-32236—When a user opens manipulated Windows Bitmap (.bmp, 2d.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the apEPSS 0.7%CVE-2024-26253MEDIUMWindows rndismp6.sys Remote Code Execution VulnerabilityEPSS 0.7%CVE-2024-3841HIGHInsufficient data validation in Browser Switcher in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to inject scripts or HTMLEPSS 0.7%CVE-2021-42117LOWUI Redressing in TopEaseEPSS 0.7%CVE-2019-15997MEDIUMCisco DNA Spaces: Connector Command Injection VulnerabilityEPSS 0.7%CVE-2025-4377HIGHPath traversal vulnerability in Sparx Pro Cloud Server WebEA webconfig in logview.phpEPSS 0.7%CVE-2022-29492MEDIUMA vulnerability exists in the handling of a malformed IEC 104 TCP packet. Upon receiving a malformed IEC 104 TCP packet, the malformed packet is dropped, however the TCP connection is left open. This may cause a denial-of-service if the affected conne ...EPSS 0.7%CVE-2022-22508MEDIUMCODESYS V3: Improper Input ValidationEPSS 0.7%CVE-2023-24493MEDIUMA formula injection vulnerability exists in Tenable.sc due to improper validation of user-supplied input before returning it to users. An auEPSS 0.7%CVE-2023-32305HIGHaiven-extras PostgreSQL Privilege Escalation Through Overloaded Search PathEPSS 0.7%CVE-2021-27760MEDIUMHCL Notes 11.0 - 11.0.1 FP4 Sametime Embedded chat clients are vulnerable to group chats loading script on restartEPSS 0.7%CVE-2022-27674HIGHInsufficient validation in the IOCTL input/output buffer in AMD μProf may allow an attacker to bypass bounds checks potentially leading to aEPSS 0.7%CVE-2024-22027MEDIUMImproper input validation vulnerability in WordPress Quiz Maker Plugin prior to 6.5.0.6 allows a remote authenticated attacker to perform a EPSS 0.7%CVE-2020-3429HIGHCisco IOS XE Wireless Controller Software for the Catalyst 9000 Family WPA Denial of Service VulnerabilityEPSS 0.7%CVE-2020-15197MEDIUMDenial of Service in TensorflowEPSS 0.7%