Fallos del tipo CWE-20

5429 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2024-38046HIGHPowerShell Elevation of Privilege VulnerabilityEPSS 0.7%CVE-2022-4428HIGHsupport_uri validation missing in WARP client for WindowsEPSS 0.7%CVE-2023-23375HIGHMicrosoft ODBC and OLE DB Remote Code Execution VulnerabilityEPSS 0.7%CVE-2023-2455MEDIUMRow security policies disregard user ID changes after inlining; PostgreSQL could permit incorrect policies to be applied in certain cases whEPSS 0.7%CVE-2024-23634MEDIUMGeoServer arbitrary file renaming vulnerability in REST Coverage/Data Store APIEPSS 0.7%CVE-2021-25748HIGHIngress-nginx `path` sanitization can be bypassed with newline characterEPSS 0.7%CVE-2023-22916HIGHThe configuration parser of Zyxel ATP series firmware versions 5.10 through 5.35, USG FLEX series firmware versions 5.00 through 5.35, USG FEPSS 0.7%CVE-2023-31010MEDIUMNVIDIA DGX H100 BMC contains a vulnerability in IPMI, where an attacker may cause improper input validation. A successful exploit of this vuEPSS 0.7%CVE-2025-1556MEDIUMwestboy CicadasCMS Template Management system deserializationEPSS 0.7%CVE-2025-7876MEDIUMMetasoft 美特软件 MetaCRM download.jsp AnalyzeParam deserializationEPSS 0.7%CVE-2026-33332MEDIUMNiceGUI's unvalidated chunk size parameter in media routes can cause memory exhaustionEPSS 0.7%CVE-2026-46587HIGHApache Camel: Couchbase: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted inputEPSS 0.7%CVE-2026-46588HIGHApache Camel: CouchDB: Non-Camel-prefixed Exchange headers bypass HeaderFilterStrategy allowing operation override from untrusted inputEPSS 0.7%CVE-2026-49042HIGHApache Camel: langchain4j-tools: filter tool argument headers against declared parametersEPSS 0.7%CVE-2026-57817HIGHApache CXF: The authorization code hash (c_hash) is not enforced for the hybrid OIDC flowEPSS 0.7%CVE-2024-23246HIGHThis issue was addressed by removing the vulnerable code. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macEPSS 0.7%CVE-2025-4563LOWNodes can bypass dynamic resource allocation authorization checksEPSS 0.7%CVE-2021-33115HIGHImproper input validation for some Intel(R) PROSet/Wireless WiFi in UEFI may allow an unauthenticated user to potentially enable escalation EPSS 0.7%CVE-2026-42810CRITICALApache Polaris: could broaden vended S3 credentials through wildcard-bearing namespace or table namesEPSS 0.7%CVE-2024-1019HIGHWAF bypass of the ModSecurity v3 release lineEPSS 0.7%