Fallos del tipo CWE-20

5427 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2019-13939HIGHA vulnerability has been identified in APOGEE MEC/MBC/PXC (P2) (All versions < V2.8.2), APOGEE PXC Compact (BACnet) (All versions < V3.5.3),EPSS 0.7%CVE-2022-4427MEDIUMSQL Injection via OTRS Search APIEPSS 0.7%CVE-2026-44180CRITICALJupyter Enterprise Gateway: ContainerProcessProxy._enforce_prohibited_ids can be BypassedEPSS 0.7%CVE-2023-41268MEDIUMPossible stack overflow due to insufficient input validationEPSS 0.7%CVE-2022-21696MEDIUMUsername spoofing in OnionShareEPSS 0.7%CVE-2022-41733MEDIUMIBM InfoSphere Information Server denial of serviceEPSS 0.7%CVE-2023-39529MEDIUMPrestaShop vulnerable to file deletion via attachment APIEPSS 0.7%CVE-2019-1750HIGHCisco IOS XE Software Catalyst 4500 Cisco Discovery Protocol Denial of Service VulnerabilityEPSS 0.7%CVE-2026-3288HIGHingress-nginx rewrite-target nginx configuration injectionEPSS 0.7%CVE-2021-44462HIGHHorner Automation Cscape EnvisionRV Improper Input ValidationEPSS 0.7%CVE-2023-32690MEDIUMResponder can Invoke Undefined Behavior in libspdm RequesterEPSS 0.7%CVE-2022-43908MEDIUMIBM Security Guardium denial of serviceEPSS 0.7%CVE-2023-22581CRITICALWhite Rabbit Switch - Unauthenticated remote code executionEPSS 0.7%CVE-2022-43903MEDIUMIBM Security Guardium denial of serviceEPSS 0.7%CVE-2025-47282CRITICALMalicious google credential in DNS secret can lead to privilege escalationEPSS 0.7%CVE-2023-38131MEDIUMImproper input validationation for some Intel Unison software may allow an authenticated user to potentially enable denial of service via neEPSS 0.7%CVE-2023-41917CRITICALImproper input validation in Kiloview P1/P2 devices allows for remote code executionEPSS 0.7%CVE-2023-32485CRITICAL Dell SmartFabric Storage Software version 1.3 and lower contain an improper input validation vulnerability. A remote unauthenticated attackEPSS 0.7%CVE-2014-125114HIGHi-Ftp 2.20 Schedule.xml Stack-Based Buffer OverflowEPSS 0.7%CVE-2023-22337HIGHImproper input validation for some Intel Unison software may allow an unauthenticated user to potentially enable denial of service via netwoEPSS 0.7%