Fallos del tipo CWE-20

5429 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2026-55994HIGHApache Camel Iggy: The inbound consumer maps externally-supplied Iggy message user-headers into the Exchange without a HeaderFilterStrategy, allowing injection of Camel control headers - enabling control over internal behaviourEPSS 0.6%CVE-2026-46592HIGHApache Camel: Camel-CXF: The SOAP operation-selection headers used non-Camel-prefixed names (operationName, operationNamespace) that bypass the HTTP header filter, allowing an HTTP client to redirect the invoked SOAP operationEPSS 0.6%CVE-2022-45113MEDIUMImproper validation of syntactic correctness of input vulnerability exist in Movable Type series. Having a user to access a specially crafteEPSS 0.6%CVE-2023-31203MEDIUMImproper input validation in some OpenVINO Model Server software before version 2022.3 for Intel Distribution of OpenVINO toolkit may allow EPSS 0.6%CVE-2021-1482MEDIUMCisco SD-WAN vManage Authorization Bypass VulnerabilityEPSS 0.6%CVE-2023-21503MEDIUMPotential buffer overflow vulnerability in mm_LteInterRatManagement.c in Shannon baseband prior to SMR May-2023 Release 1 allows remote attaEPSS 0.6%CVE-2023-21504MEDIUMPotential buffer overflow vulnerability in mm_Plmncoordination.c in Shannon baseband prior to SMR May-2023 Release 1 allows remote attackersEPSS 0.6%CVE-2025-5497MEDIUMslackero phpwcms Feedimport processing.inc.php deserializationEPSS 0.6%CVE-2023-39539HIGHFailure when uploading a Logo image fileEPSS 0.6%CVE-2026-74761HIGHApache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Spoofing of RemoveSubscription clientIdEPSS 0.6%CVE-2025-31132HIGHRaven allows Remote Code Execution due to improper validationEPSS 0.6%CVE-2026-3204CRITICALImproper input validation in the error message page in Devolutions Server 2025.3.16 and earlier allows remote attackers to spoof the displaEPSS 0.6%CVE-2026-5536MEDIUMFedML-AI FedML gRPC server grpc_server.py sendMessage deserializationEPSS 0.6%CVE-2023-22898MEDIUMworkers/extractor.py in Pandora (aka pandora-analysis/pandora) 1.3.0 allows a denial of service when an attacker submits a deeply nested ZIPEPSS 0.6%CVE-2022-20545HIGHIn bindArtworkAndColors of MediaControlPanel.java, there is a possible way to crash the phone due to improper input validation. This could lEPSS 0.6%CVE-2022-22247HIGHJunos OS Evolved: Kernel processing of unvalidated TCP segments could lead to a Denial of Service (DoS)EPSS 0.6%CVE-2023-36462MEDIUMMastodon's verified profile links can be formatted in a misleading wayEPSS 0.6%CVE-2023-51931HIGHAn issue in alanclarke URLite v.3.1.0 allows an attacker to cause a denial of service (DoS) via a crafted payload to the parsing function.EPSS 0.6%CVE-2026-7195HIGHCWE-20: Improper Input Validation in web services in Progress SitefinityEPSS 0.6%CVE-2026-25128HIGHfast-xml-parser has RangeError DoS Numeric Entities BugEPSS 0.6%