Fallos del tipo CWE-20

5429 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2026-58186HIGHApache Traffic Server: webp_transform plugin decodes unsafely and mislabels degraded responsesEPSS 0.7%CVE-2023-35944HIGHEnvoy vulnerable to incorrect handling of HTTP requests and responses with mixed case schemesEPSS 0.7%CVE-2020-3257HIGHCisco IOx Application Environment for IOS Software for Cisco Industrial Routers VulnerabilitiesEPSS 0.7%CVE-2025-59032HIGHManageSieve AUTHENTICATE command crashes when using literal as SASL initial response. This can be used to crash ManageSieve service repeatedEPSS 0.7%CVE-2022-34844MEDIUMBIG-IP and BIG-IQ AWS vulnerability CVE-2022-34844EPSS 0.7%CVE-2026-82550MEDIUMLinux Foundation Magma NGSetupRequest input validationEPSS 0.7%CVE-2025-58173HIGHFreshRSS vulnerable to authenticated RCE via path traversal inside include()EPSS 0.7%CVE-2022-36082MEDIUMmangadex-downloader vulnerable to unauthorized file readingEPSS 0.7%CVE-2024-32371HIGHAn issue in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a regular user account to escalate their privileges and gain aEPSS 0.7%CVE-2020-3507HIGHCisco Video Surveillance 8000 Series IP Cameras Cisco Discovery Protocol Remote Code Execution and Denial of Service VulnerabilitiesEPSS 0.7%CVE-2022-34476CRITICALASN.1 parsing of an indefinite SEQUENCE inside an indefinite GROUP could have resulted in the parser accepting malformed ASN.1. This vulneraEPSS 0.7%CVE-2024-25590HIGHCrafted responses can lead to a denial of service due to cache inefficiencies in the RecursorEPSS 0.7%CVE-2026-43777HIGHThis issue was addressed with improved input validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.6.EPSS 0.7%CVE-2023-49568HIGHMaliciously crafted Git server replies can cause DoS on go-git clientsEPSS 0.7%CVE-2023-41303—Command injection vulnerability in the distributed file system module. Successful exploitation of this vulnerability may cause variables in EPSS 0.7%CVE-2020-16216—Philips Patient Monitoring Devices Improper Input ValidationEPSS 0.7%CVE-2023-46159LOWIBM Storage Ceph denial of serviceEPSS 0.7%CVE-2025-6563MEDIUMCross-site scripting via dst parameter in RouterOS WiFi hotspotEPSS 0.7%CVE-2022-23831HIGHInsufficient validation of the IOCTL input buffer in AMD μProf may allow an attacker to send an arbitrary buffer leading to a potential WindEPSS 0.7%CVE-2026-43692HIGHA validation issue was addressed with improved input sanitization. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS TaEPSS 0.7%