Fallos del tipo CWE-20

5425 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2025-1177MEDIUMdayrui XunRuiCMS Linkage.php import_add deserializationEPSS 0.7%CVE-2025-1701HIGHLocal Privilege Escalation in MIM Admin ServiceEPSS 0.7%CVE-2024-45258CRITICALThe req package before 3.43.4 for Go may send an unintended request when a malformed URL is provided, because cleanHost in http.go intentionEPSS 0.7%CVE-2020-7870MEDIUMA memory corruption vulnerability exists when ezPDF improperly handles the parameter. This vulnerability exists due to insufficient validatiEPSS 0.7%CVE-2022-45088CRITICALLocal File Inclusion in Smartpower WebEPSS 0.7%CVE-2026-42811CRITICALApache Polaris: could broaden vended GCS credentials through unescaped identifier content in access-boundary CEL conditionsEPSS 0.7%CVE-2023-27586CRITICALCairoSVG improperly processes SVG files loaded from external resourcesEPSS 0.7%CVE-2023-50709MEDIUMDenial of service attack on the cube-api endpointEPSS 0.7%CVE-2025-30213MEDIUMFrappe has Possibility of Remote Code Execution due to improper validationEPSS 0.7%CVE-2024-20721MEDIUMT5 Acrobat JS vulnerability - Exploitable crash via t5::javascript::get_page_num_wordsEPSS 0.7%CVE-2026-57985HIGHMicrosoft Edge (Chromium-based) Remote Code Execution VulnerabilityEPSS 0.7%CVE-2022-34851MEDIUMBIG-IP and BIG-IQ iControl SOAP vulnerability CVE-2022-34851EPSS 0.7%CVE-2024-21519MEDIUMThis affects versions of the package opencart/opencart from 4.0.0.0. An Arbitrary File Creation issue was identified via the database restorEPSS 0.7%CVE-2026-54632HIGHSIPSorcery: Malformed UDP packet on the RTP/ICE socket can remotely terminate a media session (DoS)EPSS 0.7%CVE-2021-22538MEDIUMPrivilege escalation in RBAC systemEPSS 0.7%CVE-2026-44522HIGHNote Mark: Arbitrary File Write via Path Traversal in Asset Names Leading to Remote Code ExecutionEPSS 0.7%CVE-2026-48436MEDIUMCAI Content Credentials | Improper Input Validation (CWE-20)EPSS 0.7%CVE-2024-25290HIGHAn issue in Casa Systems NL1901ACV R6B032 allows a remote attacker to execute arbitrary code via the userName parameter of the add function.EPSS 0.7%CVE-2026-73513HIGHEnvoy: oghttp2 upstream trailers incorrect handlingEPSS 0.7%CVE-2023-50256HIGHFroxlor username/surname AND company field BypassEPSS 0.7%