Fallos del tipo CWE-20

5430 resultados

Validação inadequada de entrada

A aplicação recebe dados de fontes externas (usuário, API, arquivo) sem verificar se estão no formato, tamanho ou tipo esperado antes de usá-los. Isso permite que um atacante envie dados malformados ou maliciosos que podem causar erros, corrupção de dados, execução de código ou acesso não autorizado.

Ejemplo

Um formulário que aceita um número de idade sem validar se é um inteiro positivo entre 0 e 150. Um atacante envia idade=-5 ou idade='DROP TABLE users;' via SQL, e o código processa isso diretamente no banco sem sanitização, causando dano.

Cómo mitigar

Valide TODA entrada externa: verificar tipo, tamanho, formato e intervalo permitido antes de usar. Use whitelists (aceitar apenas valores conhecidos como seguros) em vez de blacklists, e aplique sanitização ou prepared statements para dados que vão em queries. Testes de entrada fuzzing também ajudam a encontrar gaps.

CVE-2024-26151HIGHPotentially untrusted input is rendered as HTML in final outputEPSS 0.6%CVE-2023-29026MEDIUMRockwell Automation ArmorStart ST Vulnerable to Cross-Site Scripting AttackEPSS 0.6%CVE-2024-29008MEDIUMApache CloudStack: The extraconfig feature can be abused to load hypervisor resources on a VM instanceEPSS 0.6%CVE-2026-21258MEDIUMMicrosoft Excel Information Disclosure VulnerabilityEPSS 0.6%CVE-2025-27517CRITICALVolt Allows RCE Via User-Crafted RequestsEPSS 0.6%CVE-2024-55653MEDIUMpwndoc's UnhandledPromiseRejection on audits causes Denial of Service (DoS)EPSS 0.6%CVE-2023-28291HIGHRaw Image Extension Remote Code Execution VulnerabilityEPSS 0.6%CVE-2022-27897MEDIUMPalantir Gotham included an endpoint that would log arbitrary sized zip files. EPSS 0.6%CVE-2023-26095—ASQ in Stormshield Network Security (SNS) 4.3.15 before 4.3.16 and 4.6.x before 4.6.3 allows a crash when analysing a crafted SIP packet.EPSS 0.6%CVE-2023-20522HIGHInsufficient input validation in ASP may allow an attacker with a malicious BIOS to potentially cause a denial of service. EPSS 0.6%CVE-2025-2689MEDIUMyiisoft Yii2 SortableIterator.php getIterator deserializationEPSS 0.6%CVE-2023-20530HIGHInsufficient input validation of BIOS mailbox messages in SMU may result in out-of-bounds memory reads potentially resulting in a denial of EPSS 0.6%CVE-2026-54234HIGHvLLM: Remote DoS in vLLM via Invalid Recovered Token ReinjectionEPSS 0.6%CVE-2022-27892MEDIUMPalantir Gotham included an endpoint that would log arbitrary sized payloads. EPSS 0.6%CVE-2025-31240HIGHThis issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.5, macOS Sonoma 14.7.6, macOS Ventura 13.7.6. MountinEPSS 0.6%CVE-2021-1250MEDIUMCisco Data Center Network Manager VulnerabilitiesEPSS 0.6%CVE-2021-1249MEDIUMCisco Data Center Network Manager VulnerabilitiesEPSS 0.6%CVE-2026-44482CRITICALsoundcloud-rpc: Remote Code Execution via XSS in Track TitleEPSS 0.6%CVE-2021-1253MEDIUMCisco Data Center Network Manager VulnerabilitiesEPSS 0.6%CVE-2024-0031CRITICALIn attp_build_read_by_type_value_cmd of att_protocol.cc , there is a possible out of bounds write due to improper input validation. This couEPSS 0.6%