Fallos del tipo CWE-20

5429 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2026-43944CRITICALelecterm: dangerous code can be run through links or command lineEPSS 0.6%CVE-2020-29021LOWScripting tag chars < > not filtered in input fields could cause Cross-Site Scripting (XSS)EPSS 0.6%CVE-2026-54909MEDIUMPion STUN vulnerable to remote denial of service via panic while parsing a malformed XOR-MAPPED-ADDRESS attributeEPSS 0.6%CVE-2026-5329HIGHRapid7 Velociraptor Improper Input Validation in Client Message HandlerEPSS 0.6%CVE-2026-56340HIGHvLLM - Denial of Service via Unvalidated Multimodal EmbeddingsEPSS 0.6%CVE-2026-7803CRITICALFlow Validation Bypass via Empty Component Type FieldEPSS 0.6%CVE-2023-5571MEDIUMImproper Input Validation in vriteio/vriteEPSS 0.6%CVE-2019-1746HIGHCisco IOS and IOS XE Software Cluster Management Protocol Denial of Service VulnerabilityEPSS 0.6%CVE-2026-1315HIGHUnauthenticated Denial of Service via Firmware Update Endpoint on TP-Link Tapo C220 & C520WSEPSS 0.6%CVE-2019-1816MEDIUMCisco Web Security Appliance Privilege Escalation VulnerabilityEPSS 0.6%CVE-2025-53652HIGHJenkins Git Parameter Plugin 439.vb_0e46ca_14534 and earlier does not validate that the Git parameter value submitted to the build matches oEPSS 0.6%CVE-2026-90961CRITICALMISP LdapAuth and LinOTPAuth Authentication Bypass via Empty or Non-String CredentialsEPSS 0.6%CVE-2026-93295HIGHMISP Background Job Argument Injection via Console Path Switches Enables Remote Code ExecutionEPSS 0.6%CVE-2023-31013MEDIUMNVIDIA DGX H100 BMC contains a vulnerability in the REST service, where an attacker may cause improper input validation. A successful exploiEPSS 0.6%CVE-2023-31012MEDIUMNVIDIA DGX H100 BMC contains a vulnerability in the REST service where an attacker may cause improper input validation. A successful exploitEPSS 0.6%CVE-2022-3676MEDIUMIn Eclipse Openj9 before version 0.35.0, interface calls can be inlined without a runtime type check. Malicious bytecode could make use of tEPSS 0.6%CVE-2026-39386HIGHNeko has Self-service Privilege Escalation for Authenticated UsersEPSS 0.6%CVE-2024-21315HIGHMicrosoft Defender for Endpoint Protection Elevation of Privilege VulnerabilityEPSS 0.6%CVE-2020-3390HIGHCisco IOS XE Wireless Controller Software for the Catalyst 9000 Family SNMP Trap Denial of Service VulnerabilityEPSS 0.6%CVE-2023-48311HIGHAny image allowed by defaultEPSS 0.6%